Information Security Director leading the strategic vision in cybersecurity for Bragg. Managing risk and compliance in a fast-paced international environment from Ljubljana.
Responsibilities
Develop, implement, and maintain the company-wide information security strategy, vision, and roadmap.
Lead the identification, analysis, and evaluation of security risks, approving risk treatment plans and mitigation strategies.
Report on the organization's security posture and risk assessment findings to executive management.
Establish, manage, and optimize the information security budget, allocating resources effectively for key security initiatives.
Ensure and maintain compliance with major legal (e.g., GDPR) and regulatory frameworks (e.g., ISO 27001, SOC2).
Oversee the execution of security awareness programs, fostering and promoting a "security-first" culture throughout the organization.
Lead the strategic response to major security incidents and breaches, focusing on effective crisis communication and minimizing business impact.
Govern the security approval process for new tools and vendors, and provide strategic input into the change management policy.
Lead and coordinate internal and external security audits, ensuring all requirements are met and non-conformities are addressed.
Stay up to date with the latest security threats, evaluate emerging security strategies, and maintain industry leadership.
Requirements
8+ years of experience in information security, with at least 3-5 years in a security leadership or strategic role.
Deep knowledge and practical experience in developing strategies and governing frameworks like ISO 27001 and SOC.
Proven experience in developing security strategy, managing enterprise risk, and security budget management.
Hands-on experience in leading complex security incident response and crisis management.
Exceptional communication and presentation skills, with the ability to articulate complex security risks to non-technical executive stakeholders.
A proactive and strategic mindset and the ability to lead a team or work independently as needed.
Self-driven, energetic, and hands-on, with a "can do, get it done" mindset.
Strong ability to prioritize and manage several strategic initiatives simultaneously.
Bonus points if you hold security certifications (e.g., CISSP, CISM, CISA).
You have experience working in big enterprise environments and software development industry.
Benefits
Competitive compensation (based on your experience).
Hybrid work model.
30 days annual leave.
Educational learning opportunities to support each employee's professional growth journey.
Sports activities, team building, and informal gatherings.
Senior Identity Security Engineer optimizing identity verification and access management solutions at S&P Global. Collaborating with cross - functional teams to enhance security infrastructure and automate identity processes.
Senior Security Researcher at CrowdStrike conducting cloud and Linux security research. Analyzing threats and developing advanced security models to protect cloud environments.
Cyber Security Analyst Senior at GDIT focusing on 24/7 monitoring and threat intelligence analysis. Integral in safeguarding government systems and anticipating future threats.
Senior Information Security Analyst responsible for protecting Omni's technology environment. Focus areas: Monitoring, Defense, Operations across on - premises, cloud, and endpoints.
Alternate Information System Security Officer overseeing security compliance for classified information systems. Evaluating security solutions and assisting in system security documentation and procedures.
IT - Systemadministrator managing physical security systems and multimedia solutions. Administration, support, and project involvement in multimedia and surveillance technologies in Roding.
Security Officer performing patrols, emergency response, and customer service at Climax Molybdenum. Managing site security and assisting with emergency situations at various locations.
Security Officer leading safety inspections and facility patrols at Crown Equipment Corporation. Assigning duties and responding to security incidents efficiently.
Security Officer overseeing safety inspections and personnel training for Crown Equipment Corporation. Responsible for monitoring facilities and responding to security incidents.
Manager of Security Risk at Grainger overseeing Information Security Risk team and managing security risk programs. Focused on regulatory compliance, leadership, and risk assessment integration.