← Back to jobs

Group Chief Information Security & Technology Risk Officer

  • Remote
  • Sweden
  • English
  • Posted 18.09.26 16:19

Group Chief Information Security & Technology Risk Officer (Group CISTRO) This is a hybrid position and candidates must be based in one of our offices across Europe. Company DescriptionForvis Mazars is a leader in audit, tax and advisory services, operating worldwide across 100+ countries and territories. Join our 40,000+ strong team to grow your career through global opportunities, diverse projects and continuous learning. Belong to a supportive environment where your unique perspective is valued and success comes from working together. Impact with your bold ideas and help drive us forward.

Purpose of the Role The Group Chief Information Security & Technology Risk Officer (Group CISTRO) is the Group’s senior second-line executive responsible for oversight of cyber security, AI and technology risk across member firms, shared services (Group) and strategic providers. The role provides independent oversight of the Group’s cyber, AI and technology risk framework, including risk appetite, policy, , resilience and governance. The role exists to provide the Group Governance bodies with independent, decision-ready insight on the effectiveness of cyber and technology risk management, the adequacy of controls, emerging threats, resilience readiness and material risk exposures. Through a scalable Group-wide independent assurance and oversight model, the role supports consistent standards, greater reliance on shared assurance evidence and stronger confidence in the management of increasingly concentrated cyber and technology risks. The role operates independently within the Second Line of Defence and is responsible for oversight, challenge, reporting and escalation of cyber, AI and technology risks across the Group. The Group CISTRO does not own or operate first-line technology controls. Responsibility for technology operations, security tooling, incident response, remediation delivery, supplier management and control execution remains with member firms, Group T&DS and other service owners. The Group CISTRO provides independent oversight, challenge and reporting over the effectiveness of those arrangements. Reporting Line and Key StakeholdersReports to the Group Chief Quality & Risk Officer.Leads on updates to Governance bodes on principal cyber, AI and technology risksChairs the Group Information Security Committee as the principal Group cyber, AI and technology risk governance forum, working closely with the Group CIO and other first-line technology leaders.Works closely with Group Transformation, the Group CIO, Regional CIOs, Country CIOs, member firm CISOs, T&DS leadership, Internal Audit, Legal, Independence, Data Protection, AI and Data governance and regional leadership to support consistent risk oversight across the Group's federated operating model.Material risk issues, control weaknesses, remediation delays or disagreements relating to risk acceptance shall be escalated through the Group Information Security Committee (GISC), QRMC and other relevant governance forums as appropriate. Key Accountabilities1. Lead the Group Cyber, AI and Technology Risk Management Transformation planDeliver the cyber, AI and technology risk roadmap and establish and mature Group's independent 2LoD cyber, AI and technology risk oversight capability.Develop the future operating model, capability and resourcing (including use of offshore Delivery Platforms) required to support long-term sustainability.Establish an “Assure Once” model, working with Group Internal Audit and other assurance providers to reduce duplication, enable reliance on common evidence and strengthen the Three Lines of Defence2. Establish Policy, Risk Appetite and Oversight FrameworkOwn the Group's cyber, AI and technology risk policy framework including risk appetite, minimum control expectations, oversight and assurance requirements and governance standards.Oversee the Group AI governance framework, including principles for responsible AI, model lifecycle, governance, accountability, transparency and risk management.Ensure policies remain aligned to regulatory obligations, client expectations, business priorities and emerging risks.Set expectations and oversee the effectiveness of Group cyber awareness, executive education and behavioural risk programmes, ensuring they reflect current threat, regulatory and client expectations.3. Provide Independent Oversight of Cyber, AI and Technology RiskDesign and operate a proportionate Group-wide oversight framework covering member firms, shared services, strategic providers and critical third parties, enabling reliance on common activities, consistent risk reporting and proportionate local implementation.Provide independent oversight and challenge of the effectiveness of cyber, AI and technology risk management, including control effectiveness, risk treatment, resilience readiness, and the remediation of material findings arising from reviews, incidents, inspections and assurance activities.Oversee and challenge remediation of material cyber, AI and technology risk findings arising from assurance activities, Internal Audit reviews, regulatory inspections and major incidents.Identify systemic weaknesses and emerging risk themes through assurance and oversight activities and Internal Audit outcomes, escalating material issues through Group governance forums as appropriate.Ensure risk oversight evolves in line with the Group's AI, digital strategy and shared services strategy and translate emerging risks into priorities.4. Provide Executive Governance, Reporting and InfluenceChair the GISC and act as principal point of contact for QRMC on cyber, AI and technology risk matters.Provide decision-ready, timely reporting on risk posture, assurance outcomes, emerging threats and remediation progress.Promote consistent accountability and informed decision-making across the Group, maintaining constructive engagement with first-line leaders, Internal Audit and other assurance providers. Candidate ProfilePreferred ExperienceSenior leadership experience in cyber security, technology risk, AI risk role.Proven experience establishing or leading a second-line risk, governance or oversight capability within a complex, federated or international organisation.Strong practical experience of the Three Lines of Defence model, including the distinction between first-line control ownership, second-line oversight and challenge, and third-line independent assurance.Demonstrable experience reporting material cyber, AI and technology risks to Boards, Audit or Risk Committees, or executive leadership.Strong knowledge of cyber security, cloud, identity, AI and third-party technology risk, with familiarity with recognised frameworks such as NIST CSF and ISO 27001.Experience overseeing control effectiveness, risk treatment, remediation, resilience and lessons learned following material incidents or assurance findings.Experience leading organisational transformation, developing scalable risk operating models and supporting client assurance or due-diligence programmes, ideally within professional services, shared services or a networked organisation. Leadership CompetenciesStrategic judgement: Translates complex cyber, AI and technology risks into clear business, client, regulatory and governance implications and priorities.Independent challenge: Provides confident, objective, proportionate and evidence-based challenge while maintaining constructive relationships with first-line leaders.Enterprise influence:Operate effectively across member firms, shared service functions and Group governance forums without relying on direct authority.Transformation leadership:Builds sustainable capabilities, operating disciplines, teams and reporting from a developing current state.Executive communication:Delivers concise, high quality, decision-ready advice and reporting to senior executives and Group governance bodiesCollaborative leadership:Develops people, draws effectively on expertise across the organisation and promotes shared accountability, collaboration and constructive problem-solving.Prepared to accompany the QRM - Group Information Security & Technology Risk Roadmap FY26-28.