Jobs and Careers
AM

Corporate Information Security Officer

Amadeus
San Jose, United StatesRemotefull_timeVerifiedPosted 5 Mar 2024

About the role

Job Title

Corporate Information Security Officer

Summary of the role:

Part of the Hospitality Information Security Office, the Corporate Information Security Officer’s mission is to achieve and maintain compliance and certification for leading security standards and legislation based on business needs and a risk-based approach for the Hospitality product line. They have the responsibility of working with business functions and other organizations concerning Risk Management, Vulnerability Management, Security Operations, Incident Response, and Audit as well as Legal, Compliance, and HR to address specific Information Security requirements.

As an integral part of the Corporate Information Security Office, the team is an enabler and partners with business functions to satisfy security requirements and allow the business to move forward. The goal is to comply with the Amadeus Security Policies and Standards by supporting Amadeus ISMS (Information Security Management System) while staying in close partnership/relationship with the Incident Response Lead on IT Security events. The Corporate Information Security Officer do their utmost to ensure that remediations are executed and timelines respected.

The Corporate Information Security Officer is the staff member of the team (Hospitality InfoSec Program Management) in charge of achieving and maintaining compliance and certification for leading security standards and legislation based on business needs and a risk-based approach for the Hospitality product line.

The Corporate Information Security Officer reports to the director of Security Program Management of the Amadeus Hospitality Information Security Office and is supportive to the Hospitality CISO and the director of the Governance Risk and Compliance team with respect to the interface with Legal, Security and Data Privacy Authorities.

In this role you’ll:

  • Ensure alignment with Amadeus Hospitality Missions & Objectives, the HOS CISO vision, and the guidance provided by Amadeus central. This is then delivered as process implementation guidelines, policies and procedures

  • Ensure that the designed implementation guidelines, policies and procedures are communicated, understood and applied appropriately within Amadeus Hospitality Business Unit.

  • Be proficient in technical knowledge to ensure team performs at a high level.

  • Understand how main business drivers may impact on own area and assess complex problems with broad impact on the activity, improve processes, recommend solutions and risk mitigation plans and be able to communicate complex information.​
    Work with a high level of autonomy, based on management directions.

  • Leads projects and contribute to broad cross-functional projects. This role may contribute to planning of resources and budget.

  • Develop, implement, maintain the Information Security Framework for Internal Services (policies, standards, guidelines, architecture models, etc.)

  • Derivate & translate of Corporate Security Policies into local/specific ones and with the corresponding standards, baselines, guidelines & architectural model

  • Develop and embed security processes into global framework and methodologies
    Develop strong communication processes (position papers, policies, procedures, standards, etc.) & awareness

  • Ensure that the security risk posture for internal services is aligned with the business appetite & strategy

  • Manage and Coordinate of Security-centric Proof of Concepts & Pilots
    Provide security consulting/expertise and support in programs / projects to other Business Units:

  • Perform security assessment on Programs/projects ((confidentiality, integrity, availability, traceability) with compliance to applicable regulations)

  • Identify possible mitigation measures

  • Translate security risk into business terms which are understandable by the business to reach residual risk acceptance

  • Validate design & accreditation of the security with Programs & projects (architecture, design, processes, regulatory compliance)

  • Supervise implementation of security in Programs and Projects

  • Collect & report metrics supporting the business value of the security program’s activities
    Conduct, coordinate or support IT Risk Assessment analysis and Audit Plans

  • Drive the day-to-day security process:

  • Monitor Security operational process effectiveness and propose improvements

  • Frame vulnerabilities detection and mitigation proposal.

  • This is an individual contributor role.

About the ideal candidate:

  • Bachelor’s degree in computer sciences (IT, Cyber Security, Ri

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Amadeus

View company profile →