Group Chief Information Security

Il y a 2 jours

Brussel, Brussel-Hoofdstad, Belgique Forvis Mazars Group Temps plein 180 000 € - 260 000 € Contrat

Group Chief Information Security & Technology Risk Officer (Group CISTRO)

This is a hybrid position and candidates must be based in one of our offices across Europe.

Company Description

Forvis Mazars is a leader in audit, tax and advisory services, operating worldwide across 100+ countries and territories. Join our 40,000+ strong team to grow your career through global opportunities, diverse projects and continuous learning. Belong to a supportive environment where your unique perspective is valued and success comes from working together. Impact with your bold ideas and help drive us forward.

Purpose of the Role

The Group Chief Information Security & Technology Risk Officer (Group CISTRO) is the Group’s senior second-line executive responsible for oversight of cyber security, AI and technology risk across member firms, shared services (Group) and strategic providers. The role provides independent oversight of the Group’s cyber, AI and technology risk framework, including risk appetite, policy, resilience and governance.

The role exists to provide the Group Governance bodies with independent, decision-ready insight on the effectiveness of cyber and technology risk management, the adequacy of controls, emerging threats, resilience readiness and material risk exposures. Through a scalable Group-wide independent assurance and oversight model, the role supports consistent standards, greater reliance on shared assurance evidence and stronger confidence in the management of increasingly concentrated cyber and technology risks.

The role operates independently within the Second Line of Defence and is responsible for oversight, challenge, reporting and escalation of cyber, AI and technology risks across the Group.

The Group CISTRO does not own or operate first-line technology controls. Responsibility for technology operations, security tooling, incident response, remediation delivery, supplier management and control execution remains with member firms, Group T&DS and other service owners. The Group CISTRO provides independent oversight, challenge and reporting over the effectiveness of those arrangements.

Reporting Line and Key Stakeholders

  • Reports to the Group Chief Quality & Risk Officer.
  • Leads on updates to Governance bodies on principal cyber, AI and technology risks
  • Chairs the Group Information Security Committee as the principal Group cyber, AI and technology risk governance forum, working closely with the Group CIO and other first-line technology leaders.
  • Works closely with Group Transformation, the Group CIO, Regional CIOs, Country CIOs, member firm CISOs, T&DS leadership, Internal Audit, Legal, Independence, Data Protection, AI and Data governance and regional leadership to support consistent risk oversight across the Group's federated operating model.
  • Material risk issues, control weaknesses, remediation delays or disagreements relating to risk acceptance shall be escalated through the Group Information Security Committee (GISC), QRMC and other relevant governance forums as appropriate.

Key Accountabilities

1. Lead the Group Cyber, AI and Technology Risk Management Transformation plan

  • Deliver the cyber, AI and technology risk roadmap and establish and mature Group's independent 2LoD cyber, AI and technology risk oversight capability.
  • Develop the future operating model, capability and resourcing (including use of offshore Delivery Platforms) required to support long-term sustainability.
  • Establish an "Assure Once" model, working with Group Internal Audit and other assurance providers to reduce duplication, enable reliance on common evidence and strengthen the Three Lines of Defence

2. Establish Policy, Risk Appetite and Oversight Framework

  • Own the Group's cyber, AI and technology risk policy framework including risk appetite, minimum control expectations, oversight and assurance requirements and governance standards.
  • Oversee the Group AI governance framework, including principles for responsible AI, model lifecycle, governance, accountability, transparency and risk management.
  • Ensure policies remain aligned to regulatory obligations, client expectations, business priorities and emerging risks.
  • Set expectations and oversee the effectiveness of Group cyber awareness, executive education and behavioural risk programmes, ensuring they reflect current threat, regulatory and client expectations.

3. Provide Independent Oversight of Cyber, AI and Technology Risk

  • Design and operate a proportionate Group-wide oversight framework covering member firms, shared services, strategic providers and critical third parties, enabling reliance on common activities, consistent risk reporting and proportionate local implementation.
  • Provide independent oversight and