Head of Security leading the information security function for diverse portfolios in a global holding organization. Collaborating with leaders and enhancing security maturity across subsidiaries.
Responsibilities
Translate headquarters' baseline standards into a tailored security roadmap
Develop and maintain a security maturity model appropriate to the size and complexity of subsidiaries
Define subsidiary tiers by risk, industry and data sensitivity to develop differentiated strategies
Create and maintain a group-level library of policies, templates and standards (e.g., incident response plan, password policy)
Facilitate policy adoption across subsidiaries with appropriate localization
Establish and manage a policy update schedule with version control
Provide or recommend shared tools across the group
Negotiate contracts with preferred security vendors and manage licensing agreements
Build a lean security engineering support function, whether in-house or outsourced
Participate in M&A due diligence to assess the cybersecurity posture of targets
Advise investment teams on cyber risk exposure and hidden liabilities
Conduct annual or semi-annual security self-assessments across subsidiaries
Consolidate results into quarterly dashboards for group leadership and HQ
Publish and maintain a group-level incident response playbook
Serve as the initial escalation point for subsidiary-level incidents
Coordinate post-incident reviews and group-level communications
Help subsidiaries achieve and maintain compliance (e.g., SOC 2, ISO 27001, GDPR, HIPAA)
Maintain a centralized view of compliance status across the group
Assist with customer/supplier security questionnaires and audits
Triage critical vulnerabilities and incidents across subsidiaries
Escalate major risks to HQ or group executives as needed
Maintain a group-level risk register and coordinate prioritization
Requirements
Over 10 years of experience in cybersecurity, with leadership roles across multiple business units or portfolio companies
Proven experience working cross-functionally with engineering, operations, legal and executive stakeholders
Deep knowledge of security standards and certifications (e.g., SOC 2, ISO 27001)
Demonstrated experience in multi-entity environments such as holding companies, private equity, or decentralized organizations
Excellent communication, negotiation and influencing skills
Security Principal at Optiv designing AI security solutions for clients, leveraging advanced security services and technologies. Driving pipeline generation and maintaining strong client relationships as a trusted advisor.
Technical Leader overseeing security for Product and Cloud at Tempo. Leading team, engaging with partners, ensuring compliance, fostering innovations in security practices.
Senior Cybersecurity Advisor providing support to threat and vulnerability analysts at Exposant 3 in a hybrid work model. Collaborating on incident responses and vulnerability management in a dynamic team.
Financial Security Advisor at RBC Insurance connecting clients with comprehensive insurance solutions. Building client relationships and leveraging RBC’s brand to grow the market.
Senior IAM Systems Support Analyst responsible for deploying and improving IAM services at RBC. Supporting MFA systems and ensuring platform reliability while collaborating with various teams.
Senior Manager overseeing IAM initiatives and strategic roadmap execution at RBC. Partnering with stakeholders to enhance organizational capabilities in Identity and Access Management.
Senior Internal Controller in information security defining security strategies and conducting risk analysis. Participating in audits and controls for a multidisciplinary firm in Canada.
Product Manager responsible for managing Microsoft Security Services portfolio at Softchoice. Engaging with customers, Microsoft and stakeholders to drive market success and growth.