Job’s mission
Under the direct supervision and guidance of the Global Head of Information Security, the job holder is part of the Global Information Security (Digital & IT Division), responsible for leading the implementation & execution of Global Cyber Defense Strategy, implementation of technical solutions to defend Santen from cyberattacks, running risk assessments of all new global solutions, managing the risk and vulnerability management process (both Information Systems and Industrial Control Systems), developing and maintaining the organization's security architecture, while considering investor's expectation for company security measures such as security regulations, standards and best practice, working with SOC (Security Operations Center) partner in order to ensure that information assets are adequately protected and compliant as well as maximize the benefit of information systems for Santen’s global businesses.
Number of direct subordinates
There might be direct reports soon, and several Digital & IT members and external consultants whose activities need to be coordinated by this role within the framework of cybersecurity projects or processes.
Key Responsibilities & Accountabilities
Cybersecurity Defense & Management
- According to the company’s long-term vision, formulate and integrate cybersecurity strategies into a companywide strategic plan by collaborating with cross-functional teams to design and implement secure infrastructure and application solutions
- Understand expectations of the company regarding continuous growth, establish concrete goals, and create mid-term strategies to achieve goals
- Drive the Global Cyber Defense Strategy, maintain ready forces and capabilities to conduct cybersecurity operations
- Anticipate future internal and external trends and implications and create appropriate cybersecurity measures
- Build understanding of cyber threats in each level. Develop detection & protection measures continuously, lead the technical solution implementations to be prepared to defend Santen from disruptive or destructive cyberattacks
Security Incident Management
- Ensure the security incident management process are executed properly by all parties by tracking the resolution process and making sure the known issues are addressed according to risk management methodology
- Lead the monthly operational meetings between SOC team and Santen, improve the overall process and ensure the KPIs are achieved
- Verify and continuously improve the Recovery Process performed during or after a security incident to ensure that it meets business requirements and is effective and practical
- Manage the Major Security Incident Management process, under Global Head of Information Security, and guide/train different stakeholders, including SOC team, DIT leaders and technical managers
- Support the Disaster Recovery and Business Continuity framework, initiatives, and execution
Technical Risk Management
- Improve Santen’s cybersecurity maturity level by increasing overall awareness and providing security advice/insights on technical requirements to DIT and non-DIT leaders (both Information Systems and Industrial Control Systems global leaders)
- Lead global programs & project implementations, planning the delivery of risk mitigation solutions and answering technical questions, reviewing current security measures, recommending enhancements, and identifying areas of security weakness
- Perform technical risk assessments (IT & OT) of all new global solutions and third parties, identify potential gaps and make sound recommendations for mitigating the risks on a global scale
- Implement the Internal Cybersecurity Framework to support the state-of-art technologies and Santen regulatory and organizational requirements (ISO 27001, NIST, Data Privacy Laws)
Vulnerability Management
- Implement and improve the Global Vulnerability Management Program focused on reducing the risk presented by vulnerabilities in Santen environment by continuously performing three core steps: Discovery, Reporting and Remediation
- Guide the technical teams (Global IT Infra, Regional IT Infra and Application teams, critical third parties) to make sure vulnerabilities are mitigated on a timely manner, perform the escalations on time
- Manage the global vulnerability scan and penetration test exercises
- Manage the relationship and contracts with the external suppliers to obtain the best value for Santen
Threat Intelligence
- Determine the need for covering the risks on company’s threat landscape and continuously search for the most strategic product & services to deliver the needed capabilities
- Keep track of changes in Santen’s business, threat landscape, product innovations and rebalance according to the risk appetite
- Build and maintain robust partnerships with market leaders (e.g. Gartner, ISF) to deter shared threats in our industry
- Build close partnerships and implement efficient internal processes with business and technical teams to detect and mitigate threats before they can be exploited
Project Initiation and Execution
- Lead projects to implement new cybersecurity solutions or frameworks by developing business cases or conducting opportunity studies when needed
- Understand projects and services specificities in a multi locations environment with many remote management situations
- Ensure there are continuous PDCA (Plan, Do, Check and Action) cycles to improve services and solution in place in relations with KPIs/SLAs in place or to be developed
Stakeholder Relationship and Vendor Management
- Maintain good working relationships with internal stakeholders globally, especially with Digital & IT management
- Support his/her Digital & IT peers in charge of infrastructure, service operations and business applications to provide the right information security advice or solutions allowing them to provide the contributions to business domains
- Manage the suppliers by defining clear guidelines and objectives, relying on KPIs in coordination with the governance in place. Challenge organization and governance in place to verify the company is obtaining best value and that vendors are meeting our information security needs and requirements
Resources Management
- Develop and own the budget proposal for the cybersecurity domain in accordance with the company guidance on budget directions
- Ensure financial governance and efficient use of resources to meet business objectives.
- Execute the budget in respect of its objectives in terms of services to operate, solutions to deliver
- Perform ongoing security maturity level assessment to evaluate the effectiveness of security controls and explain the effectiveness to project teams, business stakeholders and senior management