Head of Information Security and GRC for Hilti Corporation, leading security programs and compliance in Construction Software. Strategic role with significant influence across a growing business unit based in Austria.
Responsibilities
Develop and implement Hilti’s Construction SW security program.
Lead and oversee the Construction SW security team and the Product BISOs.
On top, act as Product BISO for On!Track.
Identify and assess product security risks and threats.
Implement security policies and procedures.
Ensure compliance with legal and regulatory requirements.
Collaborate with other executives to integrate security measures into business processes.
Report to management on security incidents and measures.
Work closely with other Information Security Officers within Hilti, the Product BISO community and the Group CISO.
Shape the further development of the ISMS and implement regulatory, organizational, and technical security requirements.
Analyze regulatory and legal developments (e.g., CRA, NIS2, EU AI data act), translate these into actionable requirements, and oversee their implementation.
Independently manage business projects related to information and product security, from requirements to implementation.
Take responsibility for specific security topics such as Cloud & AI Security or technical risk analyses within the BU.
Contribute to the continuous improvement of the security architecture, the ICS, and the ICT & cyber risk management for Construction SW.
Own and maintain BU CSW SOC2 certification and support Group ISO27001 certification
Coordinate internal and external audits in the field of information security and support the implementation of the resulting measures.
Requirements
Master’s degree in computer science, Information Technology, Information Security, Cybersecurity, or a related field. PhD degree preferred.
Several years of experience in a leadership position in SW/IT security.
Multiple years of experience in information security, including being in decision-taking roles.
In-depth knowledge of security protocols, technologies, and standards (e.g., ISO 27001, SOC2, NIST).
Experience in developing and implementing security programs.
Certifications such as CISSP, CISM, CISA, or equivalent are advantageous.
Proficiency in security frameworks, risk management, incident response, and security architecture.
Excellent analytical and problem-solving skills. Ability to assess risks and develop mitigation strategies.
Strong written and verbal communication skills. Ability to convey complex security concepts to non-technical stakeholders.
Capacity to adapt to a fast-paced and evolving environment. Commitment to staying updated on the latest security trends and technologies.
High level of integrity and ethical standards. Commitment to protecting the Construction SW’s information assets.
Technical understanding in areas such as Cloud & AI Security, IAM, Endpoint Security, Data Security, SDLC, DevSecOps, Application Security.
Benefits
A strategic seat at the table with senior leaders, board exposure, and influence across a rapidly growing business unit.
The opportunity to work from our global headquarters, surrounded by mountain views, modern workspaces, healthy food options, and in-house fitness facilities.
Relocation support for candidates across Europe, or flexible commuting options for those based in Switzerland or Austria.
Access to Hilti's global talent development programs, career mobility, and the chance to make an impact far beyond one BU.
Flexible work arrangements, e-bikes, parking, and on-site daycare to support your full life-not just your work life.
Working Student in Information Security at Allianz Direct supporting security monitoring and managing vulnerability assessments. Collaborating with cross - functional teams to enhance cybersecurity posture and awareness.
Enterprise Security Implementation Specialist at Vodafone supporting customers in implementing security solutions. Responsibilities include onboarding, incident management, and ensuring service quality with Fortinet and Zscaler products.
Cyber Security Specialist at Vodafone responsible for shaping and deploying security measures. Collaborating with business, IT, and Network teams as a trusted security partner.
Manager at PwC contributing to digital transformation in Utilities through technology consulting and stakeholder management. Focused on creating strategies and providing technology solutions in a data - driven world.
Research Associate conducting advanced research in iOS security within a leading institute for applied cybersecurity. Emphasis on secure application development and vulnerability analysis.
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.