About this role
<p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif"> </span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="background-color:#ffffff"><span style="color:#000000"><img src="https://rmkcdn.successfactors.com/c53088e5/2b7a0e54-4d2d-4ff0-b700-b.jpg"></span> </span></span></p> <p><br><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Job ID: 525936</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"> </span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">CRH is a leading global diversified building materials group, employing over 75,800 people at more than 3,160 locations in 29 countries. CRH is the leading building materials company in North America and the world. We manufacture and distribute a diverse range of superior building materials, products, and solutions, which are used extensively in construction projects of all sizes. </span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif"> </span></p><p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif"><strong><u>Job Summary</u></strong></span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif">As part of the Group Information Security team and reporting to the Governance, Risk and Frameworks Manager, the successful candidate will contribute to driving strategy and multi‑year program plans aimed at reducing overall cyber risk, while also supporting related Group reporting and governance requirements.</span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Given the increasing need for global alignment and continuous improvement across CRH, the role will work closely with Group, Divisional, and OpCo teams to ensure adherence to policy and best practices. The candidate will help drive standardization, tracking, and measurement of information security metrics and management across 150+ CRH entities, covering cyber governance, risk, best practice, and framework activities.</span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif">The role will involve extensive engagement across divisions, regions, and OpCo management on key work areas, contributing to programs that will be reported to the Global Information Security (Cyber) Council—chaired by the Group Finance Director and part of the Global Leadership Team (GLT). The outputs and progress tracking will form key components of the biannual Audit Committee updates and regular GLT updates.</span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif"><strong><u>Job Location</u></strong></span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif">This role is based at our corporate office in the Perimeter area of Atlanta, GA – hybrid work schedule</span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif"><strong><u>Job Responsibilities</u></strong></span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Develop, implement, and continuously enhance global cyber risk assessment processes covering 150+ CRH entities, ensuring consistent reporting, oversight, and governance across the Group.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Develop, roll out, and support the adoption of information security standards and best practices across the Group, enabling local IT teams and functions to meet minimum security requirements.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Design and deploy the Group’s third-party due diligence assessment process.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Collaborate with Group, Divisional, and OpCo teams to identify, assess, mitigate, and monitor supplier related risks.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Maintain, enhance, and support Group alignment with IEC/ISO 27001 accreditation requirements.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Provide advisory and consultancy support to OpCos and business units to strengthen their information security controls and practices.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">In alignment with Financial Regulatory Controls (FRC) and Sarbanes Oxley (SOX) reporting requirements, develop and support the execution of key entity level cyber controls, including incident reporting and security awareness.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Partner closely with Group and Divisional teams—including Legal, Compliance, Finance, Risk, IT, and Internal Audit—to support the planning, execution, and remediation of internal and external audit findings across all cyber and IT audit areas.</span></li> <li style="margin:0.0in 0.0in 8.0pt 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Ensure timely follow up and drive sustained improvements based on audit outcomes.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif"><strong><u>Job Requirements</u></strong></span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Experience working or consulting within large, diverse global organizations, navigating differing needs, priorities, and maturity levels.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Strong team player with a track record of breaking down silos, fostering collaboration, and building shared visions across complex environments.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Exceptional interpersonal skills, with the ability to build trusted relationships at all levels of the organization.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Outcome driven, with the ability to navigate challenges, resolve issues, and maintain momentum in multi stakeholder initiatives.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Excellent written and verbal communication skills, able to clearly articulate technical concepts and processes to non-technical audiences.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Highly effective stakeholder engagement skills, capable of driving change within a matrixed organization and promoting governance, IT security standards, and framework adoption.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Strong analytical, reporting, and problem-solving abilities, with the capability to assess issues from multiple perspectives and develop “win-win” solutions.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Comfortable operating in environments of uncertainty, ambiguity, and change, exercising good judgement to make informed decisions and recommendations.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">3 or more years’ experience in cybersecurity governance and risk management, compliance/assurance, or IT security operations within large global organizations with diverse needs and priorities.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Third level qualification (or equivalent) in Information Technology, Information Security, Engineering, or a related discipline.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Preferred: Professional security certifications such as CISSP, CISM, GCIH, GIAC (SANS), or equivalent. (Candidates actively working toward these certifications are also encouraged.)</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Experience in developing, implementing, and supporting risk management and assurance frameworks (e.g., NIST CSF, IEC/ISO 27001).</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Experience with GRC platforms—administration skills in tools such as RSA Archer are a strong plus.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Experience with eDiscovery tooling is an advantage.</span></li> <li style="margin:0.0in 0.0in 8.0pt 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Proficiency in an additional language is a plus, reflecting CRH’s global footprint.</span></li> </ul><p> </p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif"><strong><u>What CRH Offers You</u></strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Highly competitive base pay</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Comprehensive medical, dental and disability benefits programs</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Group retirement savings program</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Health and wellness programs</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">An inclusive culture that values opportunity for growth, development, and internal promotion </span></li> </ul> <p style="margin:0.0in 0.0in 0.0pt 0.0in"> </p> <p style="margin:0.0in 0.0in 0.0pt 0.0in"> </p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif"><strong><u>About CRH</u></strong></span></p> <p> </p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">CRH has a long and proud heritage. We are a collection of hundreds of family businesses, regional companies and large enterprises that together form the CRH family. CRH operates in a decentralized, diversified structure that allows you to work in a small company environment while having the career opportunities of a large international organization.</span></p> <p> </p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">If you’re up for a rewarding challenge, we invite you to take the first step and apply today! Once you click apply now, you will be brought to our official employment application. Please complete your online profile and it will be sent to the hiring manager. Our system allows you to view and track your status 24 hours a day. Thank you for your interest! </span></p> <p align="center"> </p> <p align="center"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">CRH is an Affirmative Action and Equal Opportunity Employer.</span></p> <p align="center"> </p> <p align="center"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">EOE/Vet/Disability</span></p> <p style="text-align:center"> </p> <div> <p style="text-align:center"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">CRH is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or any other characteristic protected under applicable federal, state, or local law. </span></p> <p style="text-align:center"> </p> </div> <p style="text-align:center"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">AI tools may be used in certain stages of the employment lifecycle, such as candidate review; however, all final employment decisions will be made by a person.</span></p>