Head of Information Security and GRC
Core
Define and implement a Construction Software security program, ensuring compliance with legal/regulatory requirements and leading the security team and Product BISOs.
Role type
Head of Information Security and GRC (Line of Defense 1)
Builds
Construction Software security program, ISMS, and regulatory compliance frameworks
Domain
Construction industry + Information Security & Governance, Risk, and Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Strategic thinking, leadership, security protocol knowledge, risk assessment, policy implementation, regulatory analysis, project management, security architecture design, audit coordination
Preferred skills
CISSP, CISM, CISA certifications, Cloud & AI Security expertise, technical risk analysis
Technologies
ISO 27001, SOC2, NIST, CRA, NIS2, EU AI data act, ICS, ICT, cyber risk management
Responsibilities
Develop and implement Hilti's Construction SW security program; Lead and oversee the Construction SW security team and Product BISOs; Act as Product BISO for On!Track; Identify and assess product security risks and threats; Implement security policies and procedures; Ensure compliance with legal and regulatory requirements; Collaborate with executives to integrate security measures into business processes; Report on security incidents and measures; Shape ISMS development and implement security requirements; Analyze regulatory developments and translate into actionable requirements; Manage business projects related to information and product security; Take responsibility for Cloud & AI Security or technical risk analyses; Contribute to security architecture and cyber risk management improvement; Own and maintain BU CSW SOC2 certification; Coordinate internal and external audits
Seniority
Senior, hands-on IC with strategic leadership
