Hiring.Camp

Regional Cybersecurity Officer

Richemont

·

Today

Location
Office RIC - SEOUL 100 Toegye-ro 15-16-21F (KRSE0088), Korea, Republic of
Workplace
Onsite
Type
Full-time
Department
IT
Experience
10+ years
Source
Workday

Description

Richemont, one of the world leaders in the luxury sector, has various Houses specializing in jewelry, watches and high-end accessories. Each Maison proudly embodies a tradition of style, quality and craftsmanship and Richemont strives to preserve the heritage and identity specific to each of them. At the same time, we are committed to innovating and designing new products in line with the values ​​of our Houses, through a process of permanent creativity.

You, as a local Cybersecurity Officer, will be a member of the Richemont Group Cyber Resilience department, a highly motivated and dynamic global team. You will work with our Richemont Group including all worldwide Maisons. You will also be leading cybersecurity activities in South Korea and report jointly to the country CEO and the Group Cyber Resilience Associate Director. Sitting in the 2nd line of defense, you will provide guidance and advisory to business and technical functions within the Group, and especially within South Korea, to enable security by design and cyber risk management.

As a local Cybersecurity Officer, you will provide overall direction, oversight and definition of cyber-Security concepts and models along with cyber security best practices and control objectives to enable the Group to achieve its business strategy and objectives in a secure and resilient manner. 

You will be leading and supporting various initiatives aimed at defining and deploying processes, awareness and technologies related to cyber risk management.

You will also actively participate to other risk assessments activities, such as, amongst others, the definition and update of cyber security policies and baselines, control objectives or security best practices/guidance, security architecture review, awareness campaigns, third party security due diligence, etc … 

Your role will involve a prominent level of collaboration with regional key stakeholders from business as well as other security specialists, technology communities, control owners and external vendors. 

Additionally, you will be responsible to ensure compliance of the Group activities in South Korea, and lead the related streams, with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and any other relevant decrees, legislation, regulations, and guidelines issued by the South Korean Communications Commission in the context of information protection in Korea (“Korea Data Protection Law”).

HOW WILL YOU MAKE AN IMPACT?

Your key responsibilities will be the following:

  • Enable cyber risk & control management and implementation

    • Contribute to the cyber risk & control strategy for the Group

    • Steer the assessment and monitoring of cyber risk & controls

    • Empower risk & control owners to understand their responsibilities and to take ownership

  • Engage with various Richemont entities’ executives and drive or participate in cyber risk assessments at strategical level

  • Act as the principal point of contact for any cybersecurity activities within South Korea

  • Oversee and support the scaling of the quantitative cyber risk management framework toward the Group

  • Advise South Korean business units, operational teams, and IT teams on cyber risk expertise, to ensure only acceptable risks are introduced to the Group, and to make sure Richemont keep compliant with local legislations and regulatory requirements.

  • Track and monitor cyber risk remediation/mitigation measures

  • Serve as cyber risk subject matter expert to business and technical functions locally in South Korea, but also in the Group

  • Collaborate with cyber risk architects to ensure that cyber security best practices are properly and systematically embedded within business and enterprise applications, services, platforms, and processes (enforce security by design)

  • Assist in local deployment of the Group cyber awareness program and adapt it to local culture and ways of business when and where required.

HOW WILL YOU EXPERIENCE SUCCESS WITH US?

For this role you will need to demonstrate of a certain maturity in the below skills:

  • More than 10 years of experience in various cybersecurity domains with a focus on cyber risk and control management

  • Proven knowledge and hands-on expertise on information security principles and practices, and also on South Korean security and privacy regulations such as PIPA and ISMS.

  • Excellent communication skills including the ability to adapt and communicate toward several types of audiences, at various hierarchical levels (up to C-Level) but also with local regulators and governmental agencies (such as KISA)

  • SME (Subject Matter Experts) in control management frameworks, such as NIST CSF, CIS top 20, ISO 27002, NIST 300-53 etc…

  • Master one of the industries recognized common risk management frameworks (FAIR, NIST RMF, ISO 27005, ISO 31000, COSO, others). Knowledge of the other frameworks is a plus

  • Industry recognised Security Certifications are a plus (e.g., CISSP, CISM, CRISC, NIST CSF, etc.)

  • Business oriented

  • Experience in project management

  • Good analytical and problem-solving skills

  • Strong collaborative mindset is necessary

  • Experience working in large, multi-tiers and international environments

  • Fluent in Korean and English, additional languages are a plus

HOW DO WE KEEP YOU SMILING?

  • You will be working in an international and multicultural team, with a forward-looking mindset

  • Trust, integrity, collaboration, exchange, support, and development are important values for the team, along with autonomy and work-life balance

  • You will interact with highly talented people across many businesses area, disciplines, cultures, regions

  • You will find in our offices a modern and high-quality work environment

#Richemont #WeCraftTheFuture

Skills

CybersecurityRisk ManagementComplianceProject ManagementCISSP