To deliver the optimal outcomes for the HoIS will partner with internal
and external providers including executives and managers across different business
and departments, third-party vendors, and thought leaders in the wider industry.
Core responsibility areas.
Governance, Risk and Compliance
Supply Chain risk.
Business Cyber Security awareness
Security Operations
Incident Management
Policy and Standards
Policies: Develop and maintain security policies, procedures, and standards that
govern all aspects of information security at HellermannTyton.
Compliance: Ensure compliance with the relevant security regulations and
industry standards (e.g., PCI DSS, GDPR, TISAX, NIS2).
Policy Implementation: Oversee the implementation and enforcement of
security policies across all global businesses and locations.
Training: Ensure employees are trained on security policies and procedures to
raise awareness and encourage responsible data handling.
Risk management
Risk program: Develop, implement, and monitor a strategic, comprehensive
enterprise information security risk management program.
Risk management: Work directly with the business units to facilitate risk
assessment and risk management processes.
Awareness: Partner with business stakeholders across the company to raise
awareness of risk management concerns.
Supply Chain: Develop, implement, and maintain a supply chain cyber security
risk management framework for the enterprise.
Data Governance and Compliance
Data Security: Partner with legal and compliance teams to understand data
privacy regulations and translate them into actionable data security practices.
Head of Information Security Role Profile
Internal
- Data Governance: Develop and maintain data governance policies and
procedures for data ownership, access, usage, and retention.
Other responsibilities
Framework: Develop and enhance an information security management
framework and maintain an effective ISMS.
Collaborative working: Understand and interact with related disciplines through
design authorities and direct working relationships to ensure the consistent
application of policies and standards across all technology projects, systems, and
services.
Awareness: Foster a culture of security awareness and responsibility within the
business.