Stellen View

ID 5604
Sparte Qualitiy /Auditing / Security / Governance / Risk / Testing
Titel Business Information Security Officer (BISO) – Construction Software
Arbeitsort Schaan Lie
Aufgaben Define, implement, and continuously evolve the Construction Software security program in alignment with Hilti’s overall information security strategy. Lead and develop the Construction Software security team, acting as a trusted advisor to senior business and technology stakeholders. Identify, assess, and manage information and product security risks, translating threats into pragmatic mitigation measures. Ensure compliance with relevant legal, regulatory, and industry requirements (e.g. ISO 27001, SOC 2, CRA, NIS2, EU AI regulations). Own and maintain the BU Construction Software SOC 2 certification and actively support Group ISO 27001 certification. Drive the development and implementation of ISMS, security architecture, internal controls, and cyber risk management for Construction Software. Independently manage security related initiatives and projects from requirements definition through implementation. Act as a key interface to the Group CISO and other Information Security Officers, ensuring alignment and knowledge sharing. Coordinate internal and external audits and ensure timely implementation of resulting improvement measures.
Anforderungen To help you succeed, we’ll provide a strong network, clear mandate, and the opportunity to make a visible impact. You bring the expertise, leadership, and mindset to make it happen: Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field, combined with deep knowledge of security standards and frameworks (e.g. ISO 27001, SOC 2, NIST). Several years in senior or decision making information or software security roles, with demonstrated ability to design and implement enterprise level security programs. Strong experience translating regulatory and legal requirements into pragmatic, business ready security controls and risk mitigation measures. Ability to take ownership, make decisions, and clearly convey complex security topics to senior, non technical stakeholders in a global matrix environment. Solid understanding of cloud based software environments, including areas such as Cloud & AI Security, DevSecOps, and application security.
Sprachen Englisch C1, Deutsch