Head Of Risk and Cyber Security
Indexed description
The Job in a Nutshell💡
The Head of Risk and Cyber Security is responsible for establishing, leading, and maturing the organization's enterprise risk management (ERM) and information/cyber security functions. This role ensures the business identifies, assesses, and mitigates operational, financial, regulatory, and technology-related risks, while safeguarding company and customer data against cyber threats. The role acts as the primary advisor to senior leadership and the board on risk posture and security strategy.
What Will You Do❓
Key Responsibilities Enterprise Risk Management
- Design and maintain the organization's ERM framework, risk appetite statement, and risk registers
- Lead periodic risk assessments across business units and consolidate findings into board/ERM committee reporting (including KRIs/KPIs)
- Identify emerging risks (operational, strategic, financial, regulatory, reputational) and drive mitigation planning with process owners
- Own business continuity and disaster recovery planning
- Support internal audit and compliance functions with risk-based input
- Develop and execute the information security strategy, policies, and controls
- Oversee security operations: threat detection, vulnerability management, incident response, and penetration testing programs
- Lead cyber incident response planning and act as incident commander during security events
- Ensure compliance with data protection regulations and industry certifications
- Manage security awareness training programs across the organization
- Build, lead, and develop the risk and security team
- Present regular risk and security posture updates to executive leadership and the board/risk committee
- Manage relationships with regulators, auditors, and external security partners
- Own the risk and security budget, tooling, and roadmap
- Bachelor's degree in information security, Risk Management, Computer Science, or related field (Master's preferred)
- 10+ years of experience in risk management and/or cybersecurity, with 5+ years in a leadership role
- Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent
- Strong knowledge of regulatory frameworks relevant to the industry/region
- Proven experience building risk frameworks and security programs from the ground up or scaling existing ones
- Excellent stakeholder management and board-level communication skills
- Fluent in English, with strong written and verbal communication skills
- Strategic thinking with hands on execution ability
- Strong analytical and problem-solving skills
- Crisis management and decision making under pressure
- Cross functional influence without direct authority
- We offer highly competitive compensation packages, including bonuses and the potential for shares
- We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment
- Join a talented team of over 30 nationalities working in 14 countries, and gain valuable experience in an exciting industry
- We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search