Make Your Resume Now

Head of Security Strategy (all humans)

Posted September 15, 2026
fulltime_permanent manager 85000-90000 EUR/year

Job Overview

Make a difference in the financial life of millions of people: At Erste Digital you are co-creating the digital future, in which better financial health is possible. #believeinyourself


We are part of Erste Group – the largest banking group in Central and Eastern Europe with more than 2,500 branches and over 45,000 employees. Our more than 2,000 IT experts and enthusiasts are the bank's Digital Muscle.


Help shape the next generation of Cyber & Information Security at Erste Digital

We are evolving our security organization around clear missions, accountable services and stronger collaboration across domains. As Head of Department, you will shape the capability together with your teams and peers rather than inherit a fixed organizational blueprint. You will be accountable for outcomes, people leadership, service maturity and cross-Group value.

Your Mission

Shape the translation of Group security direction into a coherent Erste Digital security strategy, effective Information Security Management System (ISMS), standards, architecture and assurance model. The role creates clarity on what good security means, demonstrates that mandatory expectations are met and uses control effectiveness and compliance as practical enablers of resilience, sustainable delivery and continuous improvement.

What you will shape and be accountable for

  • Own and continuously improve the ISMS as the non-negotiable foundation for security governance, control effectiveness, regulatory compliance and management assurance.

  • Translate Group-wide security direction and mandatory expectations into actionable standards, architecture guidance and capability priorities for Erste Digital.

  • Establish a coherent compliance and assurance model across controls, evidence, audits, findings, maturity and management reporting - focused on effectiveness and improvement rather than bureaucracy.

  • Develop reusable security principles, architecture patterns and guidance that help teams understand expectations early and apply them consistently.

  • Strengthen strategic security involvement in significant technology change and emerging topics, ensuring material security implications are understood early and reflected in the security-management system.

Group first - Built to scale beyond one entity

  • Think Group First: design every capability so it can be consumed across the Group where feasible, or at minimum produce reusable blueprints, patterns, standards and lessons that create value beyond Erste Digital.

  • Seek alignment with Group Security and relevant entities before creating local-only solutions where a shared approach is realistic.

  • Balance local delivery responsibility with the ambition to simplify, standardize and scale security capabilities across the Group.

What success looks like

  • A mature and trusted ISMS that gives management transparent evidence of control effectiveness, compliance and improvement priorities.

  • Compliance and assurance processes that strengthen resilience and delivery instead of operating as parallel bureaucracy.

  • Clear, practical security standards and architecture patterns that teams can apply without repeated interpretation.

  • Earlier security involvement in strategic initiatives and reusable blueprints that create value across Erste Digital and the wider Group.

Who benefits from your work

Management, product teams, architects, technology leaders, assurance and audit functions, Group Security and Group entities benefit from clear direction, reliable assurance and a security-management system that turns expectations into measurable, actionable improvement.

Ready to Apply?

Take the next step in your career journey

Stand out with a professional resume tailored for this role

Build Your Resume – It’s Free!