Group Head Of Information Security
CurrentWithin ERG Group (a leading diversified natural resources group), I’m providing leadership to the information security function, teams and specialist (+50 FTE in total) in different regions over the world. In this role I'm setting direction of the Information, Cyber, Operational Technology (OT) security strategy, keeping and maintain oversight of the sustainable improvements in this area. Furthermore, the operational security activities are in scope in, including but not limited to: penetration testing, vulnerability management, security assessment, Security Operations Center and Threat Intel unit. A summary of the (ongoing) activities and achievements: - Define risk appetite for Information Security - Develop and execute Information Security roadmap and required projects;- implementation of top tier security solutions (e.g. EDR, DLP, SIEM, NDR)- Steer on network security and access control improvement programs; - Continues penetration tests, application security reviews and network scans; - Red Teaming - Setup and maintain cyber security dashboards for different stakeholders- Established membership with ISF including the transfer of knowledge - Setup of Red and Blue teams, SOC, Group penetration test service and group threat intel - Setup Policy house based on (ISF) standards of good practice - Group security awareness programs - Stakeholder management with group leadership and ensuring effective governance (IT&IS C’tee, Group Risk C’tee) - Daily management of teams (coaching, setting targets/objectives)