Head of Security Operations
hace 16 horas
Barcelona
Reporting to: Business Information Security Officer Direct Reports: 3 Position Type: Full time permanent Location : Barcelona, Spain Standing still is not an option in the current world of Insurance. TMHCC is one of the world’s leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients. We are the foundation for TMHCC’s success - enabling the business to grow, compete, and innovate through technology, security, and solution design. From shaping strategy to delivering resilient operations, we ensure every capability is aligned to business value. Our inclusive and collaborative culture empowers everyone to explore ideas, solve meaningful challenges, and build fulfilling careers that make a real impact. This role is a senior hire in the Business Information Security Office for TMHCC International who are looking to expand their team into Barcelona. You will act as the senior divisional lead for security operations, representing requirements, risk priorities and ensuring that centrally delivered security services effectively protect people, assets, and operations. You will maintain resilience against evolving security threats and align security detection and response priorities with divisional risk, regulatory and business requirements. • Provide oversight and performance management of security operations services delivered to the International division of TMHCC, • Ensure centrally provided security services (e.g. monitoring, incident response, crisis management) meet needs and service expectations of the international business, • Serve as the primary divisional escalation point for security incidents, issues, and operational risks, • Conduct divisional security risk assessments and ensure appropriate mitigation plans are agreed and implemented, • Provide input into security strategy, policies, and investment decisions to ensure divisional risks are appropriately addressed, • Support crisis management, business continuity, and resilience activities from an advisional security perspective, • Proven experience in a senior security operations role within a complex, matrixed, or federated organisation, • Strong knowledge of security operations, incident management, and threat response frameworks, • Demonstrated leadership experience managing teams and third-party providers, • Experience overseeing or assuring services delivered by a central or shared services security function, • Ability to operate at both strategic and operational levels, • Strong stakeholder management and communication skills, including engagement with senior leaders, • Experience translating business and divisional risk into clear security service, • Demonstrated hands‑on leadership of security incident response, including major or high‑impact incidents, • Proven experience developing, testing, and executing incident response plans and playbooks, • Strong understanding of incident lifecycle management, including detection, containment, eradication, recovery, and lessons learned, • Experience leading post‑incident reviews and driving continuous improvement, • Ability to coordinate incident response across multiple stakeholders, including IT, Legal, Risk, Compliance, and external agencies, • Experience in financial services, insurance, or other highly regulated industries, • Professional security certifications (e.g. CISSP or similar), • Experience with security monitoring tools, SOC operations, or integrated security technologies, • Experience leading crisis management or business continuity responses, • Experience operating in a divisional or business‑aligned security leadership role, • Background in regulated industries such as insurance, financial services, or critical infrastructure, • Experience with crisis management, business continuity, and resilience oversight #J-18808-Ljbffr