Global Director, Security Services

5 dni temu


Kraków, Lesser Poland GPC Global Technology Center Pełny etat 80 000 zł - 120 000 zł rocznie

Position Summary:

The Global Director, Security Services is responsible for leading and executing all security engineering efforts across GPC. This role focuses on comprehensive application security, covering both custom-developed and third-party SaaS/Packaged software, with oversight spanning over 1,000 applications and microservices globally. This position ensures that security standards and controls are embedded throughout the Software Development Lifecycle (SDLC) for every project within the company's global IT portfolio. Additionally, the role functions as a primary security liaison to IT leadership, providing visibility into security performance and supporting IT Vice Presidents and Business Unit CIOs in managing risk. This position reports to the CISO and oversees a cross-functional, globally distributed team of engineers and specialists across North America, Europe, and Australasia.

Key Responsibilities:

Security Architecture and Engineering:

  • Oversee and implement security requirements across all global IT portfolio items, including security requirements engineering, architecture reviews, penetration testing, software composition analysis, and code reviews.
  • Define, promote, and oversee the adoption of pre-approved security blueprints within IT teams to streamline secure application implementation.
  • Ensure application security through vulnerability reporting, secure coding practices, and collaboration with application development teams.
  • Leveraging global SMEs across GRC, Cyber Defense and IAM functions to drive secure by design technology implementation.
  • Support teams in securing infrastructure requirements as part of project security coordination.

Product/Application Security Ownership
:

  • Direct security practices for a global portfolio of over 1,000 applications and 500+ projects per year, including approximately 50% custom-developed solutions.
  • Own and manage security technology stack required to deliver secure software, including but not limited to Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Application Security Posture Management (ASPM), and other related tools.
  • Maintain and enforce security controls across the SDLC, conducting third-party security reviews, providing architectural guidance, and ensuring secure implementation practices.

Executive Communication and Risk Visibility:

  • Develop and present executive-level security reports, providing insights into project-level security postures and highlighting any critical vulnerabilities.
  • Assume full responsibility for all Cyber Executive Communication, up to C-Suire and Full Board Updates o Educate and inform IT Vice Presidents and Business Unit CIOs on security issues within their projects, driving the closure of identified vulnerabilities and assessment findings.

Global Team Leadership and Organizational Structure:

  • Lead a team structured into three primary functions: Product Security, Engineering & Software Security, and Security Coordination & Champions Management with resources spread across North America, Europe, India and Australasia
  • Manage a specialized team responsible for security technology enablement and governance, including SAST, DAST, ASPM, and GenAI security frameworks.

Budget and Resource Ownership:

  • Exercise full budgetary responsibility for project-based security resourcing and tool allocations, ensuring optimal use of security resources across the global portfolio.

Compliance and Standards Enforcement:

  • Assume full responsibility for Payments Security, incl. P2PE certification o Act as a conduit between project teams and the global GRC Team, ensuring alignment with PCI-DSS and privacy regulations.
  • Identify compliance controls required within projects, enforce standards, and oversee their integration during the build process to mitigate risk proactively.

Key Stakeholder and Project Coordination:

  • Serve as the single point of contact (SPOC) for project-level security support, overseeing security standards within projects to ensure alignment with enterprise security policies.
  • Collaborate globally with stakeholders across North America, Europe, and Australasia to address region-specific security challenges and ensure cohesive security practices.

Key Performance Indicators (KPIs):

Secure Configuration:
Zero vulnerabilities reach production environments, with a focus on proactive mitigation and ensuring all enterprise controls are properly implemented.

Security Efficiency
: Achieve a "first-time pass" rate on security reviews, minimizing unplanned security work and optimizing development cycles.

Compliance Adherence
: Ensure newly implemented technology maintains compliance with regulatory standards (PCI-DSS, privacy regulations) and internal policies, ensuring security controls meet audit requirements



  • Kraków, Lesser Poland HEINEKEN Global Shared Services Pełny etat 1 050 000 zł - 1 650 000 zł rocznie

    Digital & Technology Team (D&T)is an integral division of HEINEKEN Global Shared Services Center. We are committed to making Heineken the most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and...


  • Kraków, Lesser Poland HEINEKEN Global Shared Services Pełny etat 120 000 zł - 180 000 zł rocznie

    Digital & Technology Team (D&T)is an integral division of HEINEKEN Global Shared Services Center. We are committed to making Heineken the most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and...


  • Kraków, Lesser Poland HEINEKEN Global Shared Services Pełny etat 90 000 zł - 120 000 zł rocznie

    Digital & Technology Team (D&T)is an integral division ofHEINEKEN Global Shared Services Center. We are committed to makingHeinekenthe most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and innovative...


  • Kraków, Lesser Poland HEINEKEN Global Shared Services Pełny etat

    AtHEINEKEN Kraków (HEINEKEN Global Shared Services)our success comes directly from our great people. We are a growing team of business experts in finance, accounting, data and technology ready to "WOW" the world with our expertise, passion and pride to be GREEN.We act on our values of Passion for consumers & customers, Courage to dream & pioneer, Care for...

  • Technology Director

    3 dni temu


    Kraków, Lesser Poland Euroclear Pełny etat 120 000 zł - 240 000 zł rocznie

    Job DescriptionTechnology Director – Innovation Tribe (GDC)About The RoleWe are looking for an inspiring, technology delivery director to drive one of key stream related to Digital assets within our Group Digital Capabilities team and innovation Tribe.This role sits at the crossroads of technology, strategy, and leadership — ideal for someone who thrives...

  • Global Risk Director

    20 godzin temu


    Kraków, Lesser Poland Aon Corporation Pełny etat

    Aon is currently recruiting a Head of the Global Risk Centre of Excellence to join our team in Krakow.This is a hybrid role with the flexibility to work both virtually and from our Krakow office. Aon is in the business of better decisions  At Aon, we shape decisions for the better to protect and enrich the lives of people around the world   As an...


  • Kraków, Lesser Poland HEINEKEN Global Shared Services Pełny etat 25 000 zł - 40 000 zł rocznie

    At HEINEKEN Kraków (HEINEKEN Global Shared Services) our success comes directly from our great people. We are a growing team of business experts in finance, accounting, data and technology ready to "WOW" the world with our expertise, passion and pride to be GREEN.We act on our values of Passion for consumers & customers, Courage to dream & pioneer, Care for...


  • Kraków, Lesser Poland canpack Pełny etat 120 000 zł - 180 000 zł rocznie

    Global IT Security ExpertPosition of broad specialization. In this role employee will lead and advance the strategic security operations and engineering initiatives across GGH, ensuring robust protection of digital assets, infrastructure, and operational continuity. The Security Expert will drive innovation, influence global security posture, and serve as a...

  • Global IT Security Expert

    20 godzin temu


    Kraków, Lesser Poland CANPACK Pełny etat

    Global IT Security Expert - IAMPosition of broad specialization, with main area focusing on Identity and Access Management (IAM). In this role employee will lead and advance the strategic security operations and engineering initiatives across GGH related to Identity and Access Management, ensuring robust protection of digital assets, infrastructure, and...


  • Kraków, Lesser Poland CANPACK Group Pełny etat 80 000 zł - 120 000 zł rocznie

    Position of broad specialization. In this role employee will lead and advance the strategic security operations and engineering initiatives across GGH, ensuring robust protection of digital assets, infrastructure, and operational continuity. The Security Expert will drive innovation, influence global security posture, and serve as a key advisor on risk...