StellenbeschreibungppIn this role, you hold boverall responsibility for information security /b across the organization. You continuously develop the information‑security strategy, the bInformation Security Management System (ISMS) /b, and the binternal control system (ICS) /b. You lead IT risk management, ensure the effective implementation of policies, standards, and processes, and act as the central authority for audits, assurance, and regulatory security topics. You represent the organization with confidence in customer interactions, RfPs, and audits, and report in a stakeholder‑appropriate manner to senior management. /p h3Key Responsibilities /h3 h3Information Security Strategy Governance /h3 ul liDefine information‑security requirements and develop, maintain, and update security strategies, policies, and concepts /li liContinuously evolve the ISMS in line with business needs and regulatory requirements /li liMaintain and enhance information‑security governance structures across the organization /li liEnsure alignment with group‑level security principles and reporting structures /li /ul h3Risk Management Internal Control System (ICS) /h3 ul liLead IT and information‑security risk management activities /li liDevelop, operate, and continuously improve the internal control system (ICS) for information security /li liCarry out security controls within your area of responsibility and derive improvement measures /li liDefine security metrics and provide regular, structured reporting on the organization’s security posture /li /ul h3Audit, Assurance Compliance /h3 ul liTake full ownership of audit and assurance topics, with a strong focus on ISAE3402 /li liEnsure high quality, completeness, and traceability of evidence management and proof‑of‑compliance activities /li liCoordinate and support internal and external audits on information‑security topics /li liEnsure compliance with applicable regulatory frameworks and legal requirements (e.g. FINMA Circular2023/1) /li /ul h3Security Operations Architecture /h3 ul liSteer security operations and security testing activities /li liAccompany and advise on security‑related architecture, transformation, and digitalization projects /li liSupport the handling of information‑security incidents and related data‑protection breaches /li liEnsure pragmatic, risk‑based security solutions that support business continuity /li /ul h3Stakeholder Vendor Management /h3 ul liAct as the central contact person for customers, RfPs, audits, and security inquiries /li liAdvise the Head of IT and IT teams on the implementation and execution of security processes /li liCounsel and support responsible parties in fulfilling their information‑security obligations /li liOwn vendor and third‑party security management /li /ul h3Training, Awareness Group Collaboration /h3 ul liPlan and conduct training sessions to raise information‑security awareness among employees /li liSupport continuous improvement of security culture across the organization /li liActively contribute to selected initiatives and projects within the CISO Office of Swiss Life Switzerland /li /ul h3Must‑Have Qualifications /h3 ul liHigher professional education (HF, FH, or university degree), preferably in: ul liComputer Science /li liBusiness Informatics /li lior a comparable field /li /ul /li liSeveral years of professional experience (minimum 3 years) in: ul liA comparable information‑security role in a regulated environment, or /li liInformation‑security consulting /li /ul /li liIn‑depth knowledge of common information‑security standards and frameworks, such as: ul liISO2700x series /li liBSI IT‑Grundschutz /li liNIST /li /ul /li liStrong understanding of applicable regulatory and legal requirements, including FINMA Circular2023/1 /li liClear, audience‑appropriate communication skills and a high level of personal responsibility /li liStructured, analytical decision‑making and strong time‑management skills /li liPragmatic, solution‑oriented mindset /li liExcellent German language skills (ideally native speaker) and good English skills /li /ul h3Nice‑to‑Have /h3 ul liAdvanced certifications in information security, such as: ul liCISSP /li liCISM /li liCISA /li liMAS in Information Security or Risk Management /li /ul /li liExperience working in complex, group‑wide governance structures /li liExposure to financial services or highly regulated industries beyond banking /li /ul h3Personality Mindset /h3 ul liHighly responsible and reliable with a strong sense of ownership /li liStructured, analytical, and risk‑aware /li liConfident communicator across technical, business, and executive audiences /li liPragmatic problem solver with a continuous‑improvement mindset /li liCollaborative and comfortable working across organizational boundaries /li /ul h3What We Offer /h3 ul liA key leadership role with end‑to‑end ownership of information security /li liHigh visibility within senior management and group‑level security functions /li liInfluence on strategy, architecture, and regulatory positioning /li liOpportunities to shape security culture and governance in a regulated environment /li liLong‑term development opportunities within a stable and reputable organization /li /ul /p #J-18808-Ljbffr