Head of Security leading information security function across diverse subsidiaries in a global holding organization. Ensuring security maturity evolves with business goals and collaboration with executives.
Responsibilities
Translate HQ’s baseline standards into a tailored security roadmap
Develop and maintain a security maturity model scaled to the subsidiaries’ size and complexity
Define tiers of subsidiaries by risk, industry, and data sensitivity to drive differentiated strategies
Create and maintain a library of group-level policies, templates, and standards (e.g., IR plan, password policy)
Facilitate adoption of policies across subsidiaries with appropriate localization
Establish and manage a policy update cadence with version control
Provide or recommend shared tooling across the group
Negotiate contracts with preferred security vendors and manage licensing agreements
Build lightweight security engineering support, whether internal or outsourced
Participate in M&A evaluations to assess the cybersecurity posture of targets
Advise investment teams on cyber risk exposure and hidden liabilities
Conduct annual or biannual security self-assessments across subsidiaries.
Consolidate results into quarterly dashboards for group leadership and HQ.
Publish and maintain a group-wide incident response playbook.
Serve as the first escalation point for incidents at the subsidiary level.
Coordinate post-incident reviews and group-level communication.
Help subsidiaries pursue and maintain compliance (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
Maintain a centralized view of compliance status across the group.
Assist with customer/vendor security questionnaires and audits.
Triage critical vulnerabilities and incidents across subsidiaries.
Escalate material risks to HQ or Group X executives as needed.
Maintain a group-wide risk register and coordinate prioritization.
Requirements
10+ years of experience in cybersecurity, with leadership roles across multiple business units or portfolio companies.
Proven ability to work cross-functionally with engineering, operations, legal, and executive stakeholders.
Deep familiarity with security standards and certifications (e.g., SOC 2, ISO 27001)
Demonstrated experience in multi-entity environments such as holding companies, private equity, or decentralized organizations.
Strong communication, negotiation, and influencing skills.
Empathy for the business: Understands startup vs. mature subsidiary dynamics.
Influence without authority: Excels at driving outcomes through relationships, not mandates.
Operational fluency: Balances strategic vision with hands-on delivery.
Program management: Leads repeatable assessments, tooling, and remediation efforts.
Adaptability: Able to flex approaches across subsidiaries with varying maturity.
IT/OT Cybersecurity Manager overseeing cybersecurity strategy and operational readiness at SkyNRG. Leading IT/OT cybersecurity initiatives for Europe’s first dedicated SAF plant in Delfzijl.
Business Owner for Enterprise Networking & Security leading strategic business growth and full P&L responsibility. Collaborating with teams to deliver high - quality solutions and maintain vendor partnerships.
Cybersecurity Senior Manager leading the delivery of managed cybersecurity services at a global accounting firm. Overseeing operations, mentoring teams, and ensuring high service quality.
Senior Application Security Specialist leading the security orchestration vision at Vanguard. Engaging in proactive security measures and collaborating with the development team for security best practices.
Cybersecurity Engineer specializing in ICS/OT environments at Vantage Data Centers. Assisting in security measures and system assessments for global enterprise technology.
Partner Manager driving Cyber Security and Data Protection strategy at CDW. Collaborating with partners and sales teams to ensure revenue growth and market awareness.
Cyber Security Specialist at CAE designing and implementing security controls for ICT systems. Leading Defence Cyber Security Assessment & Authorisation processes with opportunities across various programs.
Vérificateur des études et essais en sécurité ferroviaire à RATP Infrastructures. Assurant la sécurité ferroviaire par la validation des schémas de signalisation et les essais techniques.
Data Center Security Officer overseeing security at data center, conducting patrols and monitoring. Responsible for access control, incident investigations, and safety documentation.