CHEP helps move more goods to more people, in more places than any other organization on earth via our 300 million pallets, crates and containers. We employ 11,000 people and operate in more than 55 countries. Through our pioneering and sustainable share-and-reuse business model, the world’s biggest brands trust us to help them transport their goods more efficiently, safely and with less environmental impact.
What does that mean for you? You’ll join an international organization big enough to take you anywhere, and small enough to get you there sooner. You’ll help change how goods get to market and contribute to global sustainability. You’ll be empowered to bring your authentic self to work and be surrounded by diverse and driven professionals. And you can maximize your work-life balance and flexibility through our .
Job Description
Position Purpose
The Security Services Delivery Lead will establish, lead, and deliver the overall Security program portfolio for the company, including program updates, metrics management, PMO oversight, Training and Awareness, Data Protection, GRC, and general security evangelism across the enterprise. This is an exciting role to define and drive total employee involvement in corporate security initiatives, while delivering transformational security improvement across multiple areas of scope as a true change agent for the enterprise.
Major / Key Accountabilities
1. Deliver excellence in Security program delivery, data protection, and training & awareness across the Brambles enterprise.
2. Maintain strong partner relationships, evangelize information security, advise senior leadership and key partners on cyber risks.
3. Operationalize and improve security governance structure and reporting, both operational and for security committees and management teams, partnering across functions, regions, and various external teams involved.
4. Coordinate project assurance of key initiatives, and perform risk management, in strict alignment and collaboration with other teams in TS and beyond (e.g. Risk & Assurance, Supplier and Customer security audits, Cybersecurity assessments, etc), with the biggest purpose to enable the Business via cyber strategy deployment.
5. Support the design and the implementation of a Cyber Risk Program, with technology, process, and organizational components, by taking into account e.g. insights from project assurance (e.g. in terms of recurrent security gaps and deficiencies), key business strategy elements, Cyber Threat Intelligence insights, etc., in order to increase cybersecurity maturity and business resilience; correlate CRP implementation progress to Cyber Maturity Index increase (NIST, etc).
6. Support Information Security Assessments across locations, applications and security processes, in order to identify security gaps, perform risk management, and define risk-reduction actions to be implemented by teams within and beyond TS.
7. Work with global teams to ensure policies, standards, and control frameworks consider regional/market nuances responding to local laws, regulations, and other local requirements.
8. Strengthen ownership and awareness of Information Security through continuous trainings and awareness campaigns globally.
9. Lead and drive the overall Cyber data protection program including data classification, data loss prevention, and data residency.
10. Lead internal scorecard and metrics management program indicating health and success of the overall cyber program.
11. Develop security training and awareness content.
12. Identify new partners to help deliver content in an engaging way.
13. Appropriate reporting including security knowledge assessments, training completion rates.
14. Champion new security tooling, and effective change management.
15. Create and maintain strong relationships throughout the business to foster a “change champions” support pool.
16. Maintain a good understanding of security techniques and terminology to be able to fluently articulate security concepts in a simple to understand way.
17. Provide recommendations for additional security solutions or enhancements to existing controls, based on feedback from wider business contacts.
18. Ad-Hoc Support in Security Incident Response Team (SIRT) in the identification, containment, eradication, and resolution of security issues.
19. Ad-Hoc support for requests from business contacts in local time zones to provide a global support framework.
Qualifications
20. Bachelor's or advanced degree in a relevant field (e.g., Information Security, Risk Management, Business Administration).
21. Proven experience in change management and risk governance.
22. Strong knowledge of relevant regulations and industry standards.
23. Effective as a change agent and influencing across organizations and regions.
24. Experience in interacting, presenting and working with top management in both domestic and international corporate environments to engage team members, drive decisions and communicate effectively.
25. Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate strategic information security topics, policies, and standards as well as risk-related concepts to technical and nontechnical audiences at various hierarchical levels.
26. Strong influencing and negotiation skills and diplomacy.
27. Strong leadership skills and ability to lead and empower multi-functional, interdisciplinary and multi-geographical teams to achieve tactical and strategic goals.
28. Experience implementing information security programs in a global environment.
29. Relevant certifications, such as CISSP, CISM, or GIAC are preferred, or willingness to pursue.
30. Experience working in a manufacturing environment, preferred.
31. Experience with global security and privacy standards and regulations such as GDPR and CCPA is a plus.
32. Global company experience.
Experience
33. Excellent program management, prioritization, and organizational skills.
34. Progressive leadership roles and relevant experience as a team lead in various Information and Cyber security disciplines supporting company information security departments.
Skills and Knowledge
35. Change agent for transformational programs.
36. Security evangelist at heart.
37. Experience in delivering transformational programs across a global enterprise.
38. Ability to pick up new concepts and domain experience quickly.
39. Data protection and data classification experience.
40. Ability to manage multiple projects and overall service delivery for an organization.
Essential Languages
41. English
Preferred Education
Bachelors
Preferred Level of Work Experience
7 - 10 years
Remote Type
Hybrid Remote
We are an Equal Opportunity Employer, and we are committed to developing a diverse workforce in which everyone is treated fairly, with respect, and has the opportunity to contribute to business success while realizing his or her potential. This means harnessing the unique skills and experience that each individual brings and we do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity, status as a veteran, and basis of disability or any other federal, state, or local protected class.