About this role
<p> </p> <p> </p> <p>At JTI we celebrate differences, and everyone truly belongs. <strong>46,000 people from all over the world</strong> are continuously building their unique success story with us.<strong> 83% of employees feel happy </strong> working at JTI.</p> <p> </p> <p>To make a difference with us, all you need to do is bring your <strong> human best.</strong></p> <p><strong> </strong></p> <p>What will your story be? Apply now! </p> <p><strong>Learn more: <a href="https://www.jti.com/" target="_blank" rel="noopener">jti.com</a></strong></p> <p><strong> </strong></p> <p><strong> </strong></p><p style="margin:0.0in;line-height:normal;background-color:white;font-size:11.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in;text-align:center;line-height:normal;background-color:white;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:18.0pt;color:black">Information Security Risk Manager<br><br></span></strong></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;line-height:107%">About the Role:</span></strong></p> <p style="margin:0.0in;line-height:normal;background-color:white;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;color:black">The <strong>Information Security Risk Manager</strong> plays a pivotal role in JTI’s efforts to identify, assess, and manage information security and IT risks. This position ensures that information security risks are clearly understood, effectively managed, and aligned with JTI’s strategic objectives.</span></p> <p style="margin:0.0in;line-height:normal;background-color:white;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;color:black">You will be responsible for implementing robust risk management practices, strengthening IT & Security risk governance, ensuring compliance with international standards and regulations, and collaborating closely with stakeholders across Digital & IT, Security, Legal, Compliance, and Enterprise Risk Management (ERM). You will also support the implementation and enhancement of automated risk management processes and tools, such as <strong>ServiceNow GRC</strong>.</span></p> <p style="margin:0.0in;line-height:normal;background-color:white;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;color:black"> </span></strong></p> <p style="margin:0.0in;line-height:normal;background-color:white;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;color:black">What will you do - Responsibilities:</span></strong><span style="font-size:12.0pt;color:black"><br><br></span></p> <p style="text-align:justify;margin:0.0in 0.0in 8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;line-height:107%">Risk Identification & Assessment</span></strong></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Conduct regular IT and information security risk assessments across systems, applications, networks, and third‑party vendors</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Identify cybersecurity threats, vulnerabilities, and areas of non‑compliance</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Monitor emerging IT and cyber risks based on evolving technologies and threat intelligence</span></li> </ul> <p style="text-align:justify;margin:0.0in 0.0in 8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;line-height:107%">Risk Mitigation & Control Development</span></strong></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Develop and implement effective risk mitigation strategies</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Design and recommend security controls to protect IT infrastructure and sensitive information</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Partner with Digital & IT, Security, and business teams to embed controls into processes</span></li> </ul> <p style="text-align:justify;margin:0.0in 0.0in 8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;line-height:107%">Monitoring & Reporting</span></strong></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Define and maintain Key Risk Indicators (KRIs) and KPIs for IT and cyber risks</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Prepare clear risk reports and dashboards for senior leadership and key stakeholders</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Escalate critical risks and incidents in a timely manner</span></li> </ul> <p style="text-align:justify;margin:0.0in 0.0in 8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;line-height:107%">Governance & Compliance</span></strong></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Maintain and enhance the IT & Security Risk Management governance framework (policies, risk appetite, playbooks, operating cycle)</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Ensure compliance with industry standards (e.g. ISO 27001, NIST) and regulatory requirements (e.g. GDPR)</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Support internal and external audits and security assessments</span></li> </ul> <p style="text-align:justify;margin:0.0in 0.0in 8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;line-height:107%">Collaboration, Awareness & Resilience</span></strong></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Act as a key liaison between IT, Security, Legal, Compliance, ERM, and business teams</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Promote a risk‑aware culture through training and awareness initiatives</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt;line-height:107%">Contribute to incident response planning, resilience initiatives, and post‑incident investigations</span></li> </ul> <p style="margin:0.0in;line-height:normal;background-color:white;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;color:black">Who are we looking for - Requirements:</span></strong></p> <ul style="margin-bottom:0.0in;margin-top:0.0px" type="disc"> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Bachelor’s degree in Cybersecurity, Information Technology, or a related field</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Master’s degree is an advantage</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Professional certifications such as <strong>CISSP, CISM, or CRISC</strong> are highly desirable</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">5+ years of experience in information security, IT risk management, cybersecurity, or a related field</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Hands‑on experience with risk assessments, risk reporting, and security governance</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Experience working with security frameworks (e.g. NIST, COBIT)</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Knowledge of cloud security and modern IT environments</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Experience with risk automation platforms (e.g. ServiceNow GRC) is a strong plus</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Strong understanding of information security principles, technologies, and risk management methodologies</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Analytical mindset with excellent problem‑solving skills</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Ability to communicate complex security concepts to non‑technical stakeholders</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Strong collaboration and stakeholder management skills</span></li> <li style="line-height:15.0pt;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-size:12.0pt">Fluent spoken and written English</span><span style="font-size:10.5pt;color:black"> </span></li> </ul> <p style="margin:0.0in;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:12.0pt;line-height:107%">What are the next steps – Recruitment process: </span></strong></p> <p><span style="font-size:12.0pt;line-height:107%;font-family:Aptos, sans-serif">Thank you very much for your interest in the role. You are welcome to <u>apply</u>. </span></p><p> </p> <p>Are you ready to join us? Build your success story at JTI. Apply now!</p> <p>Next Steps:</p> <p> </p> <p>After applying, if selected, please anticipate the following within 1-3 weeks of the job posting closure: Phone screening with Talent Advisor > Assessment tests > Interviews > Offer. Each step is eliminatory and may vary by role type.</p> <p> </p> <p>At JTI, we strive to create a diverse and inclusive work environment. As an equal-opportunity employer, we welcome applicants from all backgrounds. If you need any specific support, alternative formats, or have other access requirements, please let us know.</p> <p> </p>