Information & Product Security Specialist
Tokyo - Shinagawa Shibaura
Philips
Sie sind Konsument oder Geschäftskunde und möchten sich über die Innovationen und Lösungen von Philips informieren? ➜ Wir freuen uns auf Sie!Job Title
Information & Product Security SpecialistJob Description
Position Summary:
As Information & Product Security Officer, you are the leading responsible expert in your designated business, market and functions for all activities related to information and products & services security, both internally within the Enterprise, and for the products and services we deliver to our customers.
The Information & Product Security Officer works across various environments, markets and business teams to maintain and expand a world-class capability and culture around information & product security and ensures that formal regulations and certifications are kept up to date and adhered to.
Duties and Responsibilities:
General
- Support/localize information & product security awareness, training and education programs.
- Supports, creation, approval and embedding of information/product security policies, adaptions, standards.
- Establish & deliver centralized reporting within Philips and to the business markets on the effectiveness of the information & product security function and its performance against strategic objectives.
- Aligns with the supplier security team on information & product security issues related to Philips suppliers/partners/3rd party ecosystems.
Product & Services Security
- Creating products & services security strategies, both short-term and long-range, in support of the business goals.
- Identify product/services security requirements throughout the Idea-to-market (I2M)/ Product Development Lifecycle Management and work with other teams as necessary to provide mitigation and cost/benefit analysis.
- Directing an ongoing, proactive product & services security risk assessment program so effective controls can be put in place for those areas presenting the greatest information security risk. Communicating risks and recommendations to mitigate risks to the senior management
- Supporting businesses in maintaining external business certifications and compliance with other (international) guidelines for information security.
- Assisting with business internal audits and overseeing and guiding external audits related to its products and services in the markets.
- Creating products & services security strategies, both short-term and long-range, in support of the business goals.
Information Security
- Be an authority on the Philips Security Management Framework: policies (tactical level), processes and risk management designs. Drive and support compliance/policy/risk reviews for your assigned market areas/business units.
- Engage with business, markets and functions to identify improvement opportunities across secure foundation, information protection, secure access to business information/assets , threat/ incidents response capabilities and vulnerabilities mitigation.
- Help Philips businesses and markets in making their own information (application) security assessments and sample assessments in order to audit compliance and report on compliance.
- Drive local business on the implementation of ISMS (High level controls and Technical Baselines), gather information and assess risk together with the risk management team.
- Support the embedding of Information Security (e.g. ISMS, client requirements, Technical Baselines) within business/markets/ functions operations and various environments.
- Support the Market Japan ISO27001 certification and improvement
Education/Skills and Experience Requirements:
Minimum
- A Master’s degree or equivalent combination of education and work experience
- Minimum of 10 years in product/information security or risk management and/or related functions (such as IT audit, IT Risk Management and IT Compliance)
- Excellent knowledge of ISO27001/2 and NIST Cybersecurity frameworks
- Information security management or audit qualifications such as CISM/ CISSP/ CISA/ CRISC
- Experience in the creation and enforcement of information security (including the sensitivity to establish a risk based view on compliance), including compliance reporting
- Experience in Health information security and risk management (ISO 27799, ISO/IEC 80001, DIACAP)
- Familiar with Laws and regulations on privacy, data protection, and breach notification, such as HIPAA, FDA, GDPR, ISO/TS 14265, 21CFR820 and equivalent Japanese laws
- Domain specific standards and approaches on privacy and product security (DICOM, IHE)
- Experience working in a large global organization with practical experience in a highly regulated environment
- Strong interpersonal skills – communication, presentation, ability to influence and lead
- Self-motivated, positive attitude, and results-oriented
- English fluency
- Willingness to travel as needed
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CISA CISM CISSP Compliance CRISC DIACAP GDPR HIPAA ISMS ISO 27001 NIST Privacy Product security Risk assessment Risk management Security assessment Vulnerabilities
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs