- Company Name
- CHEP
- Job Title
- Director of Digital Business Cyber Security
- Job Description
-
**Job title**
Director of Digital Business Cyber Security
**Role Summary**
Lead the cyber‑security strategy and compliance for the Digital organization. Partner with Digital, Technology, Compliance, Legal and Data teams to embed secure design, risk‑based prioritisation, data protection, and third‑party risk controls across all digital platforms and services. Drive continuous improvement of cyber maturity and Data Loss Prevention (DLP) across the enterprise.
**Expectations**
- Deliver cyber‑security governance aligned with the Board‑approved Cyber Strategy and NIST CSF.
- Ensure digital solutions are secure by design, meeting regulatory and industry best practices.
- Balance risk and investment, providing clear cyber‑security requirements to Digital leadership.
- Manage a high‑performance cyber‑risk improvement program, meeting defined data protection targets.
**Key Responsibilities**
- Act as primary security liaison for Digital business units, assessing, prioritising and remediating cyber risks.
- Develop, implement and monitor cyber‑control policies, exception management and compliance metrics.
- Lead Governance, Risk & Compliance (GRC) toolset implementation and third‑party security assessments for Digital.
- Define and execute global Data Protection & DLP program, integrating with application development and risk teams.
- Coordinate with Privacy Office, Data Management, Legal, IT and Compliance teams on cross‑functional security initiatives.
- Oversee vendor security assessments, POCs, and technology research to support Data & Cyber initiatives.
- Engage Data Owners/Custodians to enforce data protection governance and empower data‑centric security decisions.
- Report on cyber posture, risk reductions, and improvement metrics to senior leadership and Board stakeholders.
**Required Skills**
- Strategic cyber‑security leadership with the ability to translate risk into actionable programs.
- Deep understanding of NIST CSF, ISO/IEC 27001, GDPR, and other relevant standards.
- Expertise in Digital platforms, IoT, SaaS, cloud security, and third‑party risk management.
- Experience with GRC platforms, IAM, DLP solutions, threat intelligence and incident response.
- Strong stakeholder management, influencing business units to adopt security controls.
- Project and portfolio management, with data‑driven performance reporting.
- Excellent written and verbal communication skills.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, Risk Management or related field (Master’s preferred).
- Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent.
- Additional certifications in cloud security (e.g., CCSP, AWS Certified Security – Specialty) or data protection (e.g., CIPP/E, CIPP/US) are advantageous.