Apply now »

Product Owner D&T Compliance & Reporting

This role is part of the D&T department of HEINEKEN International and is in Heineken Global Shared Service, Krakow, Poland. D&T is proud to bring cutting-edge innovation, strong technology, and advanced analytics to HEINEKEN. With speed and agility, we ensure HEINEKEN has the technological competitive advantages it needs to deliver on its ambition.

 

Digital & Technology Team (D&T) is an integral division of HEINEKEN Global Shared Services Center. We are committed to making Heineken the most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and innovative teams and have a direct impact on building the future of Heineken!  

 

Would you like to meet the Team, see our office and much more? Visit our website: Heineken (heineken-dt.pl).

 

 

Your responsibilities would include: 

 

  • executing, assessing and reporting Security Control Effectiveness Assessment (SCEA) compliance for Head Office and providing oversight for Regions, Hubs and OpCos
  • leading initiatives to automate control testing activities through the Security Control Effectiveness Assessment (SCEA) process
  • orchestrating activities with central Global D&T vendors and coordinating with OpCos and Regions for the collection of third-party assurance reports
  • evaluating reported findings, aligning follow-up actions and coordinating assurance evaluation memos with the Global D&T Leadership Team
  • implementing and operating a global risk reporting and issue management process to unify risk mitigation and risk visibility across D&T and all Lines of Defense
  • utilizing the SCEA process to identify and manage Global D&T operational risks beyond cybersecurity
  • implementing and operating a sustainable and standardized approach for compliance with external frameworks, including NIS2, DORA, SWIFT CSP, EU Data Act and PCI-DSS
  • defining the scope for external framework compliance and driving synergies across control executions and regulatory frameworks
  • preparing internal and external compliance and assurance reporting
  • supporting the D&T Leadership Team in regulatory compliance reporting.
 
 

You are a good match if you have:

 

  • Master’s Degree in Information Systems, Computer Science or equivalent
  • qualification in at least one of the following qualifications or their equivalent: CISA, CRISC, CISSP, CISM, CIA
  • has worked with relevant market standards such as NIST, ISO 27001, COBIT, and relevant laws and regulations such as privacy laws
  • 15+ years’ working experience in the areas of Cyber Security and Risk Management
  • has extensive experience in a 2nd Line of Defense role and an Internal Audit capacity
  • ability to balance security risk and business objectives in a practical, business-enabling way
  • has an innate ability to translate complex technical terms into business language that is easily understood by all levels of the organisation
  • extensive working experience of Agile methodology
  • ability to work and team up with a multitude of different people and different cultures 
  • displays professionalism, customer service attitude, attention to detail and quality
  • possesses strong interpersonal, relationship management and negotiation skills, as well as strong verbal and written communication skills
  • develops self and others through continuous learning, sharing best practices, knowledge and expertise
  • keeps current with trends in Cyber Security, Risk Management and related developments in regulatory requirements
  • demonstrates excellent management and leadership skills
  • working experience with Governance, Risk & Compliance (GRC) tooling, such as OneTrust and ServiceNow Issue & Risk Management
  • proficient in Audit and Risk Management methodologies
  • advanced certification as Product Owner and/or Scrum Master
  • utilises Agile methodology experience in leading and empowering Product Teams through facilitative leadership
  • plays a key role in delivering complex cross-product, tribe and portfolio initiatives
  • demonstrates strong analytical skills
  • demonstrates strong negotiation and conflict resolution skills across all levels of the organisation
  • proficient in Business English (written and verbal)
  • takes the lead in establishing cross-functional and cross-OpCo engagement.

 

 

#LI-HYBRID 

At HEINEKEN Kraków, we take integrity and ethical conduct seriously. If someone has concerns about a possible violation of legal regulations indicated in Polish Whistleblowing Act or our Code of Business Conduct, we encourage them to speak up. Cases can be reported to global team or locally (in line with the local HGSS Whistleblowing procedure) by selecting proper option in this tool or by communicating it on hotline. 


Job Segment: Compliance, Risk Management, Internal Audit, Law, Relationship Manager, Legal, Finance, Customer Service

Apply now »