Information Security Supply Chain, Governance and Compliance Manager
vor 2 Wochen
Employment Type: Permanent
Contract Duration
Why you will love working here
At IATA, we represent over 350 airlines worldwide, striving to make aviation safer, smarter, more sustainable, and inclusive.
- Our Values are not just words on a page - they are the energy behind everything we do: ONE IATA - We collaborate across teams, TRUSTED - We do the right thing, INNOVATIVE - We make tomorrow better, INCLUSIVE - We embrace diverse perspectives.
- With over 30,000 courses available, we believe in continuous learning and support your growth in an ever-changing industry.
- Diversity, equity, and inclusion are our priorities. We are certified by the Equal Salary Foundation, offering equal pay and family-friendly policies.
- We encourage community involvement through volunteering and strive to make tomorrow better for aviation and our communities. We offer time off so you can support causes important to you.
- We promote work-life balance with flexible work options, including remote and hybrid work, a generous 'work from abroad' policy, and you get your birthday off
About The Team You Are Joining
You will be joining the Information and Data Division, reporting to Head of Information Security Governance, Risk & Compliance and Aviation Advocacy under the Chief Information Security Officer (CISO).
You will be responsible for managing and maintaining IATA's supply chain security program, work within multiple time zones, conduct security assessments in allocated time, complete supply chain questionnaires from vendors, collaborate with international vendors, internal business, procurement, engineering, technology, and legal divisions. Provide recommendations, scores, and risks for vendors. Manage and maintain a database of vendors, write minutes, procedures, enhancement requests, policies, and standard operating procedures. Work with the security team to identify and remediate any vulnerabilities, end of life components, and other security control requirements for vendors of IATA current and future business.
You will be responsible for safeguarding the IATA's supply chain ecosystem against cybersecurity risks. This role will be establishing and maintaining IATA's supply chain security program, designing, implementing, and monitoring security controls and assurance programs across third-party vendors, providers, and strategic partners. The position plays a critical role in ensuring that all suppliers meet the IATA's information security standards and regulatory requirements
What Your Day Would Be Like
Establishing and maintaining IATA's supply chain security program aligned with organizational risk posture and business objectives
Develop and maintain internal processes and policies for supply chain and vendor management
Serve as the primary point of contact for supply chain security of critical vendor matters across the organization
Provide complete security assessments for RFPs, RFQs, RFIs, and any other required business objective software for products and services
Maintain a register of critical suppliers and their risk profiles; coordinate periodic reviews and audits
Maintain, manage, and configure with the help of a customer relations manager a risk platform for vendor assessments, analysis, and reporting
Collaborate with Legal, Procurement, and other business functions to define and enforce supplier security requirements
Develop metrics and dashboards to measure supply chain security posture and maturity as well as produce executive level summaries for management committee and C Suites
Produce summaries, after action reports, and minutes of meetings, discussions, and events
Support due diligence and contractual security clauses during procurement and onboarding
Support developing incident response plans for supply chain-related security events
Coordinate investigations and remediation activities when third-party incidents occur
Drive continuous process improvements and automation for supplier risk management
Stay current on emerging threats, technologies, and regulatory changes impacting supply chain cybersecurity
We would love to hear from you if
Minimum of 7 years of experience with international exposure in cybersecurity/ information security with at least 3 years in third-party risk, supply chain security management or security governance risk and controls
Strong knowledge of risk assessment methodologies, vendor due diligence, security assurance practices and experience in managing security assessments, audits, and corrective action plans with suppliers
Familiarity with regulatory and standards frameworks such as ISO 27001, NIST , NIST CSF, SOC 2, GDPR, CMM and best cybersecurity practices
Excellent written and verbal communication skills, with the ability to present technical findings to non-technical stakeholders as well as negotiation and stakeholder management skills
Proficiency in English is required; additional language skills are a plus
Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CISA, or equivalent is an advantage.
Travel Required: 10
*Learn more about IATA's role in the industry, our benefits, and the team at iata/careers/ . We are looking forward to hearing from you*
-
Information Security and Compliance Officer
vor 2 Wochen
Genf, Genf, Schweiz Alohi SA Vollzeit CHF 90'000 - CHF 120'000 pro JahrDescriptionAlohi SA brings together a team of highly competent engineers that focus on merging state-of-the-art technologies with compelling user experience in order to simplify and enhance life for companies and people around the world. The company provides Sign.Plus (a legally binding electronic signature), Fax.Plus (online faxing), Dial.Plus (AI-voice...
-
Genf, Genf, Schweiz Actalent VollzeitWe are currently looking for aJuniorProject Manager – SCMto support a strategic initiative focused on harmonizing processes and systems across two distinct business units at both global and country levels. This is atemporary positionstartingASAP until June 30, 2026, offering a unique opportunity to lead a high-impact integration project within a dynamic...
-
Project Manager Supply Chain Management
Vor 3 Tagen
Genf, Genf, Schweiz nemensis ag Vollzeit CHF 60'000 - CHF 72'000 pro JahrReady to Drive Global Integration in Life Sciences?Duration: ASAP until Location: Geneva, SwitzerlandWork arrangement: 3 days on-site, 2 days home officeSalary: CHF 54,- - 60,-/hID: 03615About our clientFor our client, a leading global pharmaceutical company headquartered in Basel, we are seeking an experienced Project Manager Supply Chain Management...
-
Senior Consultant
vor 2 Wochen
Genf, Genf, Schweiz UNICEF Supply Vollzeit CHF 80'000 - CHF 120'000 pro JahrPurpose of Activity/Assignment:Under the supervision of a Contracts Specialist from the Digital Supply Unit, the Senior Consultant will lead and advise on large-scale procurement initiatives for Internet connectivity and associated services for schools and healthcare centres, primarily for the African continent, in compliance with Giga's technical...
-
Information Security Specialist 100
vor 2 Wochen
Genf, Genf, Schweiz ODDO BHF Vollzeit CHF 90'000 - CHF 120'000 pro JahrABOUT USODDO BHF is a Franco-German-Swiss financial group with French and German roots dating back to over 150 years and Swiss roots originating in 1780. It is owned by Philippe Oddo and his family, by employees and by long term partners.With 3,200 employees and more than EUR150 billion in client assets, ODDO BHF has three main business lines, based on a...
-
Lead, Grant Governance and Donor Relations
Vor 7 Tagen
Genf, Genf, Schweiz World Economic Forum VollzeitThis position is a maternity cover with a defined duration from 1 January 2025 to 30 September 2026.The World Economic Forum, committed to improving the state of the world, is the International Organization for Public-Private Cooperation.The Forum engages the foremost political, business, and other leaders of society to shape global, regional, and industry...
-
Genf, Genf, Schweiz Nembrini Consulting SA VollzeitWe are looking for aCisco Network Architect & Project Managerwith strong project governance, stakeholder management, and coordination capabilities. The role requiresfull-time on-site presence in Genevawithin a highly structured and secure public-sector environment.Key ResponsibilitiesLead and coordinate Cisco network transformation and infrastructure...
-
Lead, Grant Governance and Donor Relations
vor 1 Woche
Genf, Genf, Schweiz World Economic Forum VollzeitThis position is a maternity cover with a defined duration from 1 January 2025 to 30 September 2026.The World Economic Forum, committed to improving the state of the world, is the International Organization for Public-Private Cooperation.The Forum engages the foremost political, business, and other leaders of society to shape global, regional, and industry...
-
Head of Legal and Compliance
vor 2 Wochen
Genf, Genf, Schweiz Page Executive Vollzeit CHF 120'000 - CHF 240'000 pro JahrGreat career opportunityJoin a dynamic and ambitious, international companyAbout Our ClientOur client is an international, publicly traded FinTech with multiple, global locations.Job DescriptionLead the Legal and Compliance functionAdvise Senior Management on legal and regulatory requirementsImplement and execute the corporate risk and compliance...
-
Head of Legal and Compliance
vor 1 Woche
Genf, Genf, Schweiz Michael Page - Switzerland VollzeitAbout Our Client Our client is an international, publicly traded FinTech with multiple, global locations. Job Description Lead the Legal and Compliance function Advise Senior Management on legal and regulatory requirements Implement and execute the corporate risk and compliance strategy Ensure policies meet the Swiss regulator requirements and...