INFORMATION SECURITY RISK MANAGER

JTI 2025-10-24 21:02:05

Описание

At JTI we celebrate differences, and everyone truly belongs. 46,000 people from all over the world are continuously building their unique success story with us. 83% of employees feel happy working at JTI.

To make a difference with us, all you need to do is bring your human best.

What will your story be? Apply now!  

Learn more: jti.com


Information Security Risk Manager

We are seeking an experienced Information Security Risk Manager to play a key role in our ongoing efforts to protect our organization from cyber threats, Digital and IT risks. The role will involve identifying, assessing, and managing security risks, ensuring compliance with industry regulations, and working closely with key stakeholders to strengthen our security posture. By implementing effective risk management practices, you will help safeguard our digital assets and align security initiatives with business objectives. 


What will you do – responsibilities:


Risk Identification and Assessment

Conduct regular risk assessments for D&IT systems, applications, networks, and third-party vendors.Identify potential cybersecurity threats, vulnerabilities, and areas of non-compliance.Evaluate emerging IT and cyber risks based on technological advancements and threat intelligence.

Risk Mitigation and Control Development:

Develop and implement risk mitigation strategies to address identified risks.Recommend and design controls to safeguard IT infrastructure and sensitive information.Collaborate with Digital &IT, security, and business teams to ensure controls are integrated into processes.

Monitoring and Reporting:

Establish key risk indicators (KRIs) and key performance indicators (KPIs) to monitor IT and cyber risks.Prepare detailed risk reports and dashboards for senior leadership and relevant stakeholders.Escalate critical risks and incidents promptly to appropriate parties.

Governance and Compliance:

Ensure compliance with industry standards (e.g., ISO 27001, NIST,) and regulatory requirements (e.g., GDPR).Maintain and improve the D&IT and cybersecurity risk management framework.Conduct audits and facilitate external assessments to verify compliance with risk and security standards.

Incident Response and Resilience:

Contribute to the development and testing of incident response plans and business continuity strategies.Support investigations and root-cause analysis of security incidents and breaches.

Who are we looking for – requirements:


Educational background:

Bachelor's or Master's degree in Cybersecurity, Information Technology, or a related field.Relevant certifications such as CISSP, CISM, or CRISC.Knowledge of relevant compliance standards and regulations.

Professional experience:

8+ years of experience in IT risk management, cybersecurity, or a related role.Hands-on work experience in information security, and risk management including risk reporting.Proficiency in IT security tools and software, understanding of network protocols, experience with security frameworks (e.g., NIST, COBIT), Knowledge of cloud security and cloud computing.In-depth knowledge of information security principles, practices, and technologies.Strong understanding of risk management methodologies and frameworks.Experience with security assessments, vulnerability management, and risk analysis.

Interpersonal, non-technical skills:

Strong analytical and problem-solving skills.Excellent communication and interpersonal skills for effectively collaborating with cross-functional teams and communicating security concepts to non-technical stakeholders.

Are you ready to join us? Build your success story at JTI. Apply now!

Next Steps:

After applying, if selected, please anticipate the following within 1-3 weeks of the job posting closure: Phone screening with Talent Advisor > Assessment tests > Interviews > Offer. Each step is eliminatory and may vary by role type.

At JTI, we strive to create a diverse and inclusive work environment. As an equal-opportunity employer, we welcome applicants from all backgrounds. If you need any specific support, alternative formats, or have other access requirements, please let us know.

Похожие вакансии

  • Senior Security Officer

    UNOPS , Kyiv, 2 дня назад
    ... and provide analysis of security related information obtained.  Ensure that appropriate and ... in producing Standing Operating Procedures Security Risk Assessments Security Plans per United Nations Security Management System. Language Requirements: Fluency ...
    ua.talent.com
  • Cyber Security DevOps Manager

    JTI 15 часов назад
    ...  Learn more: jti.com    Cyber Security DevOps Manager  What this position is about – ...
    jobs.jti.com
  • System Security Engineer

    Playtech , Kyiv, 10 дней назад
    ... in and support security risk assessments, audits, and compliance activities.Collaborate closely with business owners, product managers, DevOps, IT operations, and development teams, providing subject matter expertise on information security.Respond to and ...
    ua.talent.com
  • Senior Security Engineer

    Softjourn 15 часов назад
    ... information security, information technology, and information security assurance;Working knowledge and understanding of Cloud security (Salesforce Cloud etc.), data security, network security, identity, and access management, policy management, and risk ...
    softjourn.com
  • System Security Engineer

    Playtech , Kyiv, 10 дней назад
    ... in and support security risk assessments, audits, and compliance activities.Collaborate closely with business owners, product managers, DevOps, IT operations, and development teams, providing subject matter expertise on information security.Respond to and ...
    ua.talent.com
  • Cybersecurity and Digital Resilience Strategist

    CRDF Global , Kyiv, 9 дней назад
    ... progressively responsible work experience in information security cybersecurity or a related field ...
    ua.talent.com
  • Intermediate Security Engineer - OP01910

    Dev.Pro , , 10 дней назад
    ... skillsExcellent communication skills, including explaining security concepts to technical teamsIntermediate+ English levelDesirable:Technical degree (Information Security, Cybersecurity, Computer Science, etc.)Completed ...
    ua.talent.com
  • Intermediate Security Engineer - OP01910

    Dev.Pro , Lviv, 11 дней назад
    ... skillsExcellent communication skills, including explaining security concepts to technical teamsIntermediate+ English levelDesirable:Technical degree (Information Security, Cybersecurity, Computer Science, etc.) Completed ...
    ua.talent.com
  • Intermediate Security Engineer - OP01910

    Dev.Pro , Kyiv, 11 дней назад
    ... skillsExcellent communication skills, including explaining security concepts to technical teamsIntermediate+ English levelDesirable:Technical degree (Information Security, Cybersecurity, Computer Science, etc.) Completed ...
    ua.talent.com
  • DevSecOps Engineer

    Doctify , , месяц назад
    ... will be responsible for embedding security into every stage of our ... latest development in the internet security domain, thrives in a fast- ... passionate about helping shape the security culture and practices of a ...
    ua.talent.com
  • Information security consultant / IT audit manager

    TechMagic , Lviv, месяц назад
    ... seeking a Senior Information Security Consultant IT Audit Manager to join our TechMagic team. You will work on a diverse portfolio of clients, providing expert guidance on their security and compliance journeys. ... and risk analysis to coaching clients on ...
    ua.talent.com
  • Information security consultant / IT audit manager

    TechMagic , , месяц назад
    ... seeking a Senior Information Security Consultant IT Audit Manager to join our TechMagic team. You will work on a diverse portfolio of clients, providing expert guidance on their security and compliance journeys. ... and risk analysis to coaching clients on ...
    ua.talent.com
  • Head of Risk (Ukraine)

    ZEN.COM , Ukrainka, 5 дней назад
    ... are seeking a Head of Risk - Ukraine to establish and lead the risk management framework for ZEN.COM’s ... capable of building a robust risk culture, implementing effective controls, and ... 10+ years of experience in risk management within banking, fintech, or ...
    ua.talent.com
  • InfoSec (DevSecOps) Engineer

    LoopMe , Lviv, месяц назад
    ... a strong background in information security, familiarity with cloud environments like ... .Responsibilities: Develop and implement information security policies and protection procedures. Perform risk assessments, security audits, and threat analysis. Monitor ...
    ua.talent.com
  • InfoSec (DevSecOps) Engineer

    LoopMe , Dnipro, месяц назад
    ... a strong background in information security, familiarity with cloud environments like ... .Responsibilities: Develop and implement information security policies and protection procedures. Perform risk assessments, security audits, and threat analysis. Monitor ...
    ua.talent.com
  • Junior InfoSec (DevSecOps) Engineer

    LoopMe , Dnipro, месяц назад
    ... development and maintenance of information security policies and procedures. Assist in performing risk assessments, security audits, and threat monitoring. Help ... to grow in information security. Benefits: Competitive compensation package Flexible ...
    ua.talent.com
  • Country Compliance & Risk Officer

    ZEN.COM , Lviv, 12 дней назад
    ... understanding of GRC frameworks, risk management principles, and second line ... regulatory exposure and proactively mitigate risk. Professional fluency in English (spoken ... and align with ZEN’s risk appetite. Risk Management & Leadership Serve as the ...
    ua.talent.com
  • CRM Manager (Middle+)

    RISK , Kyiv, 15 дней назад
    ... looking for a CRM Manager to join our team.Job ... experience as a CRM Manager in the iGaming industry (casino ... opportunity to take a RISK and come out on top. ... solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • Project Manager

    Miratech 15 часов назад
    ... position requires a seasoned Project Manager who can leverage traditional methods to enhance results, accelerate goal achievement, reduce costs, and maximize project benefits. With a focus on Information Security and Risk Management, this role will serve ...
    www.smartrecruiters.com
  • Project Manager

    Miratech 15 часов назад
    ... position requires a seasoned Project Manager who can leverage traditional methods to enhance results, accelerate goal achievement, reduce costs, and maximize project benefits. With a focus on Information Security and Risk Management, this role will serve ...
    www.smartrecruiters.com
  • Training Material Developer

    iMMAP , Lviv, 3 дня назад
    ... staff technical capacity inGIS and information management.SUPPORT TO PROJECT MANAGEMENT, MONITORING AND LEARNING AND PROGRAM DEVELOPMENT:Support the Project Manager to develop the project work- ...
    ua.talent.com
  • Research Manager – Resilience and Spatial Planning Unit for Ukraine, based in Dnipro (Link For External Applicants)

    IMPACT , Dnipro, 22 дня назад
    ... CoPs).The Research Manager will maintain the strictest confidentiality on all data collected and related processes. He she will actively take measures to prevent the unauthorized sharing of any information and data ... security and or isolation adjustment is ...
    ua.talent.com
  • Research Manager – Resilience and Spatial Planning Unit for Ukraine, based in Dnipro (Internal Applicants Only)

    IMPACT , Dnipro, месяц назад
    ... CoPs).The Research Manager will maintain the strictest confidentiality on all data collected and related processes. He she will actively take measures to prevent the unauthorized sharing of any information and data ... security and or isolation adjustment is ...
    ua.talent.com
  • Static Security Officer

    GardaWorld , Kiev, 28 дней назад
    ... years full time service; Security experience: a minimum of 3 years in the security sector, and preferably with diplomatic ... ensure the safety and security of all client staff and ... are as follows: Ensuring the security of client buildings and staff ...
    ua.talent.com
  • Application Security Engineer

    Andersen Ukraine 15 часов назад
    ... management practices; Strong understanding of information security and data protection requirements across ... on-prem); Experience with vendor risk assessments, security audits and developing internal controls ...
    people.andersenlab.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Kyiv, 19 дней назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Odesa, 19 дней назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Dnipro, 19 дней назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Sokil'nyky, 19 дней назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Kharkiv, 19 дней назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Kharkiv, 23 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Kyiv, 24 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Odesa, 24 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Dnipro, 24 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Kyiv, 23 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Sokil'nyky, 24 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Kharkiv, 24 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Dnipro, 23 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Sokil'nyky, 23 дня назад
    ... troubleshooting across the network and security stack.- Automate routine tasks using infrastructure-as-code and security-as-code best practices.- Partner with governance, risk, and compliance teams to maintain ...
    ua.talent.com

Карточка вакансии:

  • Должность INFORMATION SECURITY RISK MANAGER
  • Размещено: 2025-10-24 21:02:05
  • Город
  • Зарплата:
  • Компания: JTI