| Role requirements |
Details |
| Leadership |
- Provide the security leadership across Japan by deploying the global information security program and influencing IT and business executives whilst ensuring the local regulatory and business requirements are met.
- Represent the Group CISO function as the Japan country Information Security leader.
- Operate as the local subject matter expert & Leader
|
| Technical / Assessment |
- Regularly assess and evaluate local country risk & control position against the KPI’s and information security risk management framework.
- Support Japan regulatory assessment activities in relation to RISO & GIS domains, ensure partnership, visibility, and engagement to regional CRA, and global security GRC leadership.
- Provide guidance and technical security advisory on local projects, become the local subject matter expert for Chubb group security expectations to local stakeholders. Ensure security issues are appropriately escalated to relevant Regional and Global stakeholder where they relate to delivery priorities for Chubb Japan.
|
| RISO Transformation & Change |
- Lead the security uplift of Japan's legacy application estate. Drive local adoption of Chubb security processes, policy, and standards.
- Support GIS and RISO portfolio delivery into Japan with local oversight and escalation to ensure that GIS objectives, transformation targets are effectively (and consistently) rolled out locally.
- Ability to build plans and oversee local improvement and transformation aligning to Chubb’s GIS program and RISO functional objectives.
- Able to influence local Chubb Japan Technology, Operations, and business units to support, execute and prioritize RISO and GIS priorities.
|
| Reporting and Governance |
- Provide regular country reporting on information security Key Performance Indicators (KPI) to the Japan, Regional, and Security leadership.
- Support Local Board and senior management reporting and awareness on Cyber.
- Build accurate inventory / registry of Japan security issues and exceptions, ensuring local disclosure and identification of security derogations.
- Track and regularly review Japan security issues, and exceptions with owners and local management, as well as regional and group security management.
- Monitor Third-Party Cyber Risk Management risks and support local management escalation discussions where necessary.
|
| Communication & Stakeholders |
- Build an effective relationship, partnering and supporting the Japan CIO, and other local Japan Leaders on Information Security matters.
- Identify and engage with key business contacts and stakeholders to raise awareness of the security threats to CHUBB and to ensure adequate coverage for business’ information security program.
- Attend Regional InfoSec Leadership and Global Team meetings providing local insight on Japan specific issues, challenges, and status.
- Regularly partner and collaborate with Regional Technical Security team, Cyber Risk & Assurance and Security Architectural teams on security issues, assessments, and reporting matters.
- Managing and supporting Japan local stakeholders through strong in office presence, face to face stakeholder engagement and presence.
- Engagement with GIS functional towers and teams based in US, and APAC RISO organization to support alignment and maturing GIS processes in Japan, as well as Security service coverage.
|
| Cyber Incident response oversight |
- Oversee, support and report on Far East (Japan) information security incidents in collaboration with Global Security Operations and the Privacy function, and the regional Information Security Incident Management team.
|
| Security training & Awareness |
- Plan, support security awareness and training activities within Japan driving risk culture changes, improvement of security behaviours.
|