
Head of Security Strategy (all humans)
- Vienna, Austria
- Cyber Defense Center / Cyber Security
- Security
Job description
Make a difference in the financial life of millions of people: At Erste Digital you are co-creating the digital future, in which better financial health is possible. #believeinyourself
We are part of Erste Group – the largest banking group in Central and Eastern Europe with more than 2,500 branches and over 45,000 employees. Our more than 2,000 IT experts and enthusiasts are the bank's Digital Muscle.
Help shape the next generation of Cyber & Information Security at Erste Digital
We are evolving our security organization around clear missions, accountable services and stronger collaboration across domains. As Head of Department, you will shape the capability together with your teams and peers rather than inherit a fixed organizational blueprint. You will be accountable for outcomes, people leadership, service maturity and cross-Group value.
Your Mission
Shape the translation of Group security direction into a coherent Erste Digital security strategy, effective Information Security Management System (ISMS), standards, architecture and assurance model. The role creates clarity on what good security means, demonstrates that mandatory expectations are met and uses control effectiveness and compliance as practical enablers of resilience, sustainable delivery and continuous improvement.
What you will shape and be accountable for
Own and continuously improve the ISMS as the non-negotiable foundation for security governance, control effectiveness, regulatory compliance and management assurance.
Translate Group-wide security direction and mandatory expectations into actionable standards, architecture guidance and capability priorities for Erste Digital.
Establish a coherent compliance and assurance model across controls, evidence, audits, findings, maturity and management reporting - focused on effectiveness and improvement rather than bureaucracy.
Develop reusable security principles, architecture patterns and guidance that help teams understand expectations early and apply them consistently.
Strengthen strategic security involvement in significant technology change and emerging topics, ensuring material security implications are understood early and reflected in the security-management system.
Group first - Built to scale beyond one entity
Think Group First: design every capability so it can be consumed across the Group where feasible, or at minimum produce reusable blueprints, patterns, standards and lessons that create value beyond Erste Digital.
Seek alignment with Group Security and relevant entities before creating local-only solutions where a shared approach is realistic.
Balance local delivery responsibility with the ambition to simplify, standardize and scale security capabilities across the Group.
What success looks like
A mature and trusted ISMS that gives management transparent evidence of control effectiveness, compliance and improvement priorities.
Compliance and assurance processes that strengthen resilience and delivery instead of operating as parallel bureaucracy.
Clear, practical security standards and architecture patterns that teams can apply without repeated interpretation.
Earlier security involvement in strategic initiatives and reusable blueprints that create value across Erste Digital and the wider Group.
Who benefits from your work
Management, product teams, architects, technology leaders, assurance and audit functions, Group Security and Group entities benefit from clear direction, reliable assurance and a security-management system that turns expectations into measurable, actionable improvement.
Job requirements
What you bring
Leadership experience in security strategy, ISMS, compliance and assurance, security architecture or a comparable security or technology leadership role.
Strong understanding of information security management systems, security control frameworks, audit and assurance, regulatory expectations and enterprise security architecture.
Ability to distinguish effective assurance from evidence production alone and to turn findings, control gaps and regulatory expectations into practical improvement.
Ability to turn strategic intent into pragmatic, implementable outcomes while creating clarity for others.
Credibility with technical experts, assurance functions and senior stakeholders, paired with curiosity for emerging technologies and new ways of working.
Leadership approach we value
We are looking for leaders who combine high standards with trust, candour and genuine interest in helping others succeed.
Servant leader: create clarity, remove obstacles and give people the space and trust to do their best work.
High standards, genuine support: set clear expectations, follow through on commitments and help people reach them.
Honest and elevating: give direct, respectful feedback, make achievements visible and create opportunities for others to grow and be recognized.
Expert without micromanaging: bring enough subject-matter depth to ask the right questions, coach and exercise sound judgement, while trusting specialists to own the technical detail.
Delivery oriented and willing to address difficult topics: turn concepts into measurable outcomes, exercise sound judgement when needed, address difficult topics early and question established approaches when they no longer serve the mission.
Click here to learn more about our Leadership Dimensions.
Why this role
Few security leadership roles combine direction, architecture and proof of effectiveness so directly.
You will shape not only where Security is going, but also the management system that demonstrates whether it works - turning Group direction and regulatory expectations into practical standards, resilient capabilities and reliable assurance, and making the department a strong link between strategy, delivery and evidence.
Employee benefits – Benefit from special conditions for financial services and insurances, supermarkets, clothing stores and many more.
Employee Referral Program – Become a talent scout for career opportunities in IT. We are rewarding every successful referral for Erste Digital
A competitive and performance-related salary dependent on your professional and personal qualifications is granted - the minimum wage for this position in accordance with the respective collective agreement is EUR 85.000,-- gross per year. But this is just a formality, we are more than happy to discuss your actual expectations.
In your motivational letter, please include the following two perspectives:
Briefly describe one concrete example of how you would make a local security capability valuable for the wider Group - as a shared service, blueprint, pattern or standard.
Reflect on one aspect of this role description you would deliberately challenge or refine, including why.
We look forward to receiving your application by 16. October. First-round interviews are planned for early November.
You do not need to match every point perfectly to be a strong candidate. If the mission resonates with you and you believe you can grow into parts of the scope, we encourage you to apply.
The way we are
Erste Group considers the diversity of its employees as key to innovation and success. As employer we are proud to offer everyone equal chances, irrespective of age, skin colour, religious belief, gender, sexual orientation or origin.
or
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.
