Cyber Security Manager
Business Context and Main Purpose of the Role
Unilever is one of the world’s leading suppliers of Food, Home, and Personal Care products with sales in over 190 countries and reaching 3.4 billion consumers a day. Unilever has more than 400 brands found in homes around the world including Dove, Lux, Ponds, Magnum, Vaseline, and Hazeline. Faced with the challenge of climate change and the need for human development, we want to move towards a world where everyone can live well and within the natural limits of the planet. That’s why our purpose as Unilever is ‘to make sustainable living commonplace’.
At Unilever, we’re determined to achieve a culture where everyone can thrive, a culture where all individuals are treated fairly and respectfully, and where their uniqueness is celebrated. We’re taking a holistic approach that focuses on how we can use the scale and reach of our business to have the greatest impact in our own workplace and beyond. We’ve set clear goals to eliminate any bias and discrimination in our policies and practices, accelerate diverse representation in our leadership, and remove barriers for people with disabilities. At the same time, we’re setting out to spend more with diverse businesses and increasing representation of diverse groups in our advertising. Find out more about our commitment to equity, diversity, and inclusion on our website.
Unilever’s Cyber Security organization is a multi-disciplinary team responsible for protecting the Confidentiality, Integrity and Availability of our Information and Operations. Our Cyber Security organization runs a 24x7 Security Operations Centre (SOC), oversees a robust Security Architecture and associated technology landscape, provides Cyber Security Solution Engineering and Risk Advisory to our business, and assesses the security of our vast technology estate, including factories, to name but a few areas. Cyber Security sits as part of the Business Operations organisations, as a peer to Unilever’s Technology and Data functions and the broad Supply Chain agenda. Cyber Security is tasked with elevating, reporting on and influencing enterprise cyber security risk mitigation across Unilever. The Cyber Security function is made up of the Governance, Risk, Assurance, and Compliance (GRAC) team, the Tech & Ops team, the BISO teams, and the Office of the CISO.
This Cyber Security Manager role supports the Information Security Lead (ISL) in securing Unilever’s business in China. This includes cyber risk assessment across the region, including for third parties, representing to the regional businesses our central security services, applying those services to determine gaps in the regional security posture, consulting on appropriate risk mitigation approaches, advising on the regional security exceptions, cyber incident response in the region, and elevating and reporting into the central Cyber Security function. These activities will be conducted with a ‘Risk Based’ approach to help individual businesses manage cyber risk in their area.
A vacancy exists for the Cyber Security Manager for China within Unilever’s cyber function. The successful candidate will support the regional Information Security Lead for China in achieving and maintaining Cyber Security objectives, standards, awareness, and compliance, defined using a ‘Risk Based’ approach. This manager position will report to the regional Information Security Lead.
Key areas under this role delivered by the ISL team include:
· Cyber security solution engineering and risk advisory across Unilever businesses, assuring appropriate risk identification, assessment, mitigation, and reporting.
· Using security tooling for reporting purposes in China, in conjunction with the Tech & Ops team.
· Ensuring the Security Operations Centers (SOC) have full visibility across the ecosystem and actively participate in incident response at the direction of the Head of Incident Response.
· Developing and delivering risk reports for China.
· Tailoring cyber training and awareness in China in alignment and partnership with the Cyber Training and Awareness Lead.
· Participating in cyber cultural transformation across China in line with our Security Strategy and Transformation program.
· Maintaining and effectively directing the timely closure of security exceptions in businesses while reporting status to the Governance, Risk, Assurance and Compliance (GRAC) team.
· Providing standards and controls feedback, based on local implementation requirements to the GRAC team to help shape global policies and standards.
· Partner with the BISO for Supply Chain, R&D, and AB to ensure appropriate cyber risk mitigation for those functional areas within their region of responsibility.
· Testing business continuity planning (BCP) and disaster recovery (DR) in the region.
This role will work with various areas of our organisation in the China region in order to support the ISL in securing all aspects of our businesses.
• Responsible for supporting the ISL with cyber security solution design and advisory across Unilever businesses in China.
• Responsible for supporting the ISL in ensuring SOC visibility across China.
• Responsible for supporting the ISL in cyber risk reporting within China to the CISO and to the business leaders.
• Responsible for supporting the ISL in tailoring and delivering cyber training and awareness across China.
• Responsible for supporting the ISL in encouraging and leading the cyber champions network participation across China.
• Responsible for supporting the ISL in leading cyber cultural transformation efforts across China.
• Responsible for supporting the ISL in maintaining and effectively directing timely closure of security exceptions in businesses across China.
• Responsible for supporting the ISL in providing standards and controls feedback based on local implementation requirements/restrictions in order to refine global policies, standards and controls requirements.
• Responsible for supporting the ISL in identifying, categorizing and risk assessing third parties for cyber security implications across their region of responsibility.
Key Skills and Relevant Experience
• Excellent written and verbal communication skills and able to be understood by both technical and non-technical personnel.
• Proven ability to lead and motivate a team.
• The ability to lead through accountability with delegated responsibilities.
• Ability to manage conflicting priorities and multiple tasks.
• Stakeholder management and interpersonal skills at both a technical and non-technical level.
• Outstanding influencing ability.
• Ability to work in a collaborative environment.
• Outstanding critical reasoning and problem-solving skills – sticking to the problem until it is resolved.
• Customer-orientated, whether responding to queries or delivering new services.
• Skills in Programme and Project Management.
• While the business language of Unilever is English, business level proficiency in local languages is a plus.
• The role holder will have ideally have previously held a role in Cyber Security or a passion to learn more in the area.
• Experience in providing thought leadership, and driving a complex change agenda, and an ability to challenge the “status quo”.
• Strong strategic and operational business awareness, with an understanding of the key drivers, levers, issues and constraints of digital businesses.
• Experience within a customer focused environment.
Candidates would be required to demonstrate the Unilever Standards of Leadership & live the Values through showing the following behaviors:
● Agility – Flexes leadership style and plans to meet changing situations with urgency. Learns from the past, envisions the future, has a healthy dissatisfaction with the status quo.
● Personal Mastery – Actively builds wellbeing and resilience in themselves and their team. Has emotional intelligence to take feedback, manage mood and motivations, and build empathy for others. Sets high standards for themselves and always brings their best self.
● Passion for High Performance – Inspires the energy needed to win, generating intensity and focus to motivate people to deliver results at speed.
Unilever is an organisation committed to equity, inclusion and diversity to drive our business results and create a better future, every day, for our diverse employees, global consumers, partners, and communities. We believe a diverse workforce allows us to match our growth ambitions and drive inclusion across the business. At Unilever we are interested in every individual bringing their ‘Whole Self’ to work and this includes you! Thus if you require any support or access requirements, we encourage you to advise us at the time of your application so that we can support you through your recruitment journey.