Global Security Policy Lead
Job Description
Job Description:
The role of the Global Security Policy Lead is to safeguard the security document repository, lead the policy lifecycle, and execute targeted policy attestations. The role will focus on the accessibility, development, and maintenance of security policies and standards, and the environment in which they are stored.
What are we looking for?
Strong understanding of document lifecycle and policy attestations
Strong understanding of the relationship between policies, standards, and procedures as they relate to information security
Strong interpersonal, organizational, and documentation skills
Have exposure and good comprehension of digital culture
Excellent communication skills and ability to work across several teams within the organization to get security behaviors embedded across the entire business landscape
Ability to plan and execute projects independently
Excellent priority-setting capability
Strong project management skills
Excellent writing skills
What will be your key responsibilities?
Lead and own the Global Information Security policy and standards lifecycle, including initiation, maintenance, and revision.
Govern the organizational policy structure, ensuring alignment with key partners in legal, privacy, and other compliance functions.
Identify and analyze functional policy requirements.
Develop and implement processes to ensure organizational compliance by monitoring changes to external regulations and standards, performing periodic gap assessments, and integrating necessary updates into the policy lifecycle.
Partner with the security awareness program & privacy teams to communicate new policies, procedures, and programs as well as any supporting regulations, guidelines, procedures, and programs.
Operate the Policy Exception Management Process, aligning with key technical and business teams to evaluate and decide on exception requests using a formal, risk-based approach.
Execute the policy attestation process and investigate non-compliance.
Develop and maintain KPIs and metrics and report trends.
Qualifications
Bachelor’s degree in information security, IT, or a similar field or equivalent work experience
Minimum of 10+ years in Information Security GRC or IT Risk role, with a primary focus on policy and standards lifecycle management.
Expertise in leading the full lifecycle of security policies and standards, from creation and stakeholder review to publication and ongoing maintenance.
Familiarity with common security frameworks (NIST, ISO) and experience translating their requirements into organizational policy.
Excellent writing skills (prior experience as a technical editor or communications specialist is a plus).
CGEIT, CRISC, or similar governance-focused certification is a plus.
#TBdigital
Other jobs you might like
Global Information Risk Lead
Sao Paulo | Guararema (Brazil)
Working at Mars UK

Hybrid

Core hours 11–3





