The Role
We are seeking a strategic and experienced Chief Information Security Officer (CISO) to lead and oversee the organisation’s information security program. Reporting directly to the Chief Legal & HR Officer, the CISO will be responsible for developing, implementing, and maintaining a comprehensive information security strategy that aligns with industry and with ARX corporate objectives, regulatory requirements, and risk management practices.
The ideal candidate will be a collaborative leader with deep technical knowledge, proven strategic insight, and a strong understanding of relevant standards (e.g. ISO/IEC 27001), legal and regulatory compliance, and corporate governance frameworks in the defence and security sectors.
Key Responsibilities:
Information Security Strategy
The ideal candidate will be a collaborative leader with deep technical knowledge, proven strategic insight, and a strong understanding of relevant standards (e.g. ISO/IEC 27001), legal and regulatory compliance, and corporate governance frameworks in the defence and security sectors.
Key Responsibilities:
Information Security Strategy
- Develop, implement, and maintain an enterprise wide information security strategy aligned with the corporate strategy and evolving risk landscape.
- Champion information security as a business and management issue across all levels of the organisation.
- Define clear roles, responsibilities, and accountabilities for all aspects of information security within the organisation.
- Lead security governance initiatives and drive awareness and engagement at the executive and operational levels.
- Establish, implement, and continuously enhance the Information Security Management System (ISMS) in accordance with ISO/IEC 27001 standards.
- Guide risk assessments, internal audits, and corrective action processes to maintain and improve ISMS effectiveness.
- Develop, approve, and maintain security policies, standards, and procedures that support business operations while managing information security risks.
- Ensure consistent application and monitoring of security policies across the organization.
- Ensure compliance with all relevant legal, regulatory, and contractual requirements related to information security and data protection.
- Liaise with cross functional teams to monitor and respond to evolving regulatory landscapes.
- Introduce and manage appropriate security controls as defined in Annex A of ISO/IEC 27001, ensuring effectiveness and continual improvement.
- Oversee security technologies, incident response, threat detection, and mitigation strategies.