Jobs and Careers
AM

Associate Director, Business Information Security Officer

Amadeus
United Statesfull_timeVerifiedPosted 11 Jun 2024

About the role

Job Title

Associate Director, Business Information Security Officer

The Business Security Officer for Hospitality (HOS BISO) consists of 4 main objectives:

  • Standardize security practices in line with CISO governance

  • Address security risks and issues identified in line with business priorities

  • Improve security posture

  • Leverage new technologies aligned with CISO governance or as needed by the business unit (BU)

The HOS BISO is a key leading role of the Hospitality Business Unit and ensures that Hospitality business targets are met with appropriate organizational and security measures to safeguard the business and the information entrusted by our customers. This role ensures that the Amadeus Corporate Security Strategy, Policies, Standards, Guidelines, and Processes are communicated, understood, and applied appropriately within the Amadeus Hospitality Business Unit.

The HOS BISO serves as the interface with Security and Data Privacy groups as needed and guided by the Deputy CISO and HOS Legal department and it is

a pivotal support function to the Amadeus Deputy CISO, providing regular updates to the CISO, the Amadeus Executive Committee (Excom) and Board of Directors, as well as supporting internal audit committee needs.

The HOS BISO reports to the Amadeus Deputy CISO and supports the Hospitality Business Unit in 4 domains:

  • Compliance (Risk management, Certification, Data Privacy)

  • Security Operations (Security Architecture reviews, Incident Monitoring and Management, Security Engineering)

  • Certification management (ISO 27001, SOC 1, SOC 2, PCI DSS)

  • Internal and external interactions (RFIs, RFPs, Security Questionnaires, Customer questions)

In this role, you will:

  • Review and refine the information security strategy for HOS in line with CISO objectives, including managing the HOS security organization and identifying optimization opportunities with the Central CISO Teams (Compliance, Security Operations GSOC, Awareness campaigns, Data Privacy), and plan and manage the HOS CISO security budget.

  • Ensure the asset inventory is completed and assess the risks, threats, and impacts to build the quarterly HOS risk maps. Coordinate with the Deputy CISO, the CISO, and the HOS BU heads to ensure the risks are understood and recommend risk reduction roadmaps in line with business objectives.

  • Ensure that the security compliance programs (PCI DSS / ISO 27001 / SOC 1 / SOC 2 / GDPR…) committed to our customers are properly scoped, planned, and budgeted, and report on any issues that require escalation and reprioritization of HOS activities.

  • Work closely with the head of HOS SDL to ensure the vulnerabilities identified by the HOS CISO Teams and the HOS SDL Teams are consolidated, communicated to the product owners, and tracked and reported on the risk reduction initiatives. This will be presented quarterly to HOS SLT as well as the CISO and Deputy CISO.

  • Maintain HOS SOC team posture to ensure it is properly staffed to support HOS security incidents. Ensure opportunities of convergence with the CISO GSOC (tooling, services) and ensure the Amadeus SIRP is adopted and followed during security incidents.

  • Manage the HOS CISO Project Management Office, which is responsible for all internal and external queries (RFIs, RFPs, etc.), participate in contract negotiations, manage the PCI certification program, and oversee all risk reduction projects approved by HOS SLT and Deputy CISO.

About the ideal candidate:

  • Bachelor’s Degree in Computer Science and/or equivalent work experience.

  • 5-8 years prior experience as a Manager, Business Information Security Officer, or similar position.

  • Minimum of 5 years experience in team management.

  • Strong analytical and problem-solving skills combined with strong business judgment and the ability to present analysis clearly and compellingly. Excellent writing and presentation skills.

  • Good understanding of Amadeus business and the different business units.

  • Knowledge of Cybersecurity, ISO27K implementation and auditing, Project Management.

  • Cybersecurity, Audit & Quality, Project Management.

  • Information Systems Security, ISO27K LA, CISSP, PMP, or equivalent knowledge/experience/interest.

  • Travel required to Europe, USA, & India.

  • The position will be located in either Miami or Orlando.

What we can offer you:

  • Get rewarded with competitive remuneration, individual and company annual bonus, vacation and holiday paid time off, health insurances and other competitive benefits.

  • Professional development

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Amadeus

View company profile →