Governance, Risk & Compliance (GRC):
• Support the implementation and operation of the local ISMS (ISO 27001 aligned) under guidance from Corporate InfoSec
• Contribute to information security governance, risk, and compliance activities at the site level
• Assist in maintaining the risk register, performing risk assessments, and tracking mitigation actions
• Support selection and adaptation of security control frameworks in alignment with corporate standards
• Ensure compliance with applicable regulations, policies, and standards
• Contribute to reporting for local management and the CISO
OT / Industrial Security (Factory Environment):
• Support the protection of confidentiality, integrity, and availability (CIA) of IT and OT systems
• Work with engineering and operations to implement security controls for industrial environments (MES, production networks)
• Ensure security principles are considered in system design and implementation
• Assist in identifying and mitigating risks specific to factory and OT environments
Security Operations & Incident Management:
• Support incident response activities, including investigation and documentation of security events
• Participate in major incident investigations and contribute to root cause analysis and corrective actions
• Assist in vulnerability management, including tracking remediation and validating closure
• Work with SOC/CSIRT and service providers to ensure effective operational security
Third-Party / Supplier Security:
• Support vendor security assessments and onboarding activities
• Ensure security requirements are understood and applied in supplier engagements
• Assist in monitoring third-party compliance and risk mitigation actions
Security Architecture & Projects Enablement:
• Contribute to the implementation of security and safety strategies defined at corporate or site level
• Provide practical security guidance to IT, OT, and project teams
• Support integration of security requirements into projects, systems, and solutions
• Align local implementations with global security standards and architecture
Awareness, Culture & Training:
• Support the rollout and adaptation of global information security strategy at the site level
• Deliver and coordinate security awareness and training initiatives
• Promote a security-conscious culture across IT, OT, and business teams
Metrics & Reporting:
• Prepare regular reports on risks, incidents, and compliance status for local leadership
• Support communication and alignment with corporate security and CISO organization
• Take ownership of assigned security domains or controls, ensuring effective implementation and maintenance
• Contribute to audit preparation and remediation tracking