Implement and maintain the information security framework within the local insurance entity in alignment with group security policies.
Act as local point of contact for all cybersecurity matters, coordinating with Group CISO and central security teams.
Enforce and adapt group-level security policies to the local context and ensure compliance with internal standards and external regulations (e.g., GDPR, Solvency II, DORA).
Identify, assess, and report local information security risks and support mitigation initiatives.
Oversee local incident response and coordinate with group-level SOC; monitor systems for vulnerabilities and ensure timely patching and remediation.
Manage access controls and identity management according to group standards.
Conduct security awareness training for local staff and promote a security culture.
Provide regular reports on security posture, incidents, and compliance to local management and the Group CISO.
Requirements
Bachelor’s degree in Information Security, Computer Science, or related field.
1-2 years of experience in IT or cybersecurity roles.
Familiarity with ISO 27001, NIST, or similar frameworks.
Strong understanding of regulatory requirements in the insurance/financial sector.
Excellent communication and coordination skills.
Certifications such as CISSP, CISM, or CompTIA Security+ are a plus.