Group Head of IT & Security
- Full-time
- Department: Technology
- Workplace Type: Hybrid
- City: Paris
Company Description
At QIMA, we are on a mission to offer our clients smart solutions to make products you can trust.
Operating in over 100 countries, we serve the consumer products, food, and life sciences industries and help more than 30,000 brands, retailers, manufacturers, and growers achieve quality excellence.
We combine on-the-ground expertise with digital solutions that bring accuracy, transparency and intelligence for quality and compliance data.
What sets us apart is our unique culture. Our 6,000 Qimates live and make decisions every day by our QIMA Values. With client passion, integrity, and a commitment to making things simple, we disrupted the Testing, Inspection, and Certification industry. Are you ready to hop on this exciting ride with us and help us achieve our mission?
Our Global Support Services ensure smooth global operations by providing essential support in IT, Finance, Marketing, HR, Admin, Legal and M&A. We centralize these functions to boost efficiency, maintain consistency, and drive growth across all regions.
Job Description
We are looking for a Group Head of IT & Security to join us on an exciting transformation journey and to embody a clear philosophy to how IT & Security should operate:
We believe IT exists to free QIMAtes to focus on their actual job, not make them navigate it. Support should be fast, tools should get out of the way, and friction should be the exception, not the norm.
We believe security protects the business, it earns customer trust, wins deals, and passes audits. It isn't a checkbox exercise or a source of unnecessary friction. Good security makes QIMA more competitive, not less agile.
We believe automation beats process. We eliminate ticket queues and manual troubleshooting through automation and AI-assisted support, so problems get solved before they become tickets.
This is a dual-pillar leadership role: you'll own our full IT function (infrastructure, support, and systems) across APAC, EMEA, and the Americas and you will also drive the Group's cybersecurity strategy, defining pragmatic policies, leading risk assessments, compliance programs and owning incident response.
We are looking for a strong and pragmatic leader who enjoys building structure across regions, developing teams, and making IT and security work better for the people who rely on it every day.
You'll report directly to our Chief Product & Technology Officer, sit as a key member of the Tech leadership team, and partner closely with all functions of the group.
Key Responsibilities
- IT Strategy: Develop and implement a comprehensive global IT strategy that supports the needs of local teams, providing the right level of support and tools across all regions.
- Infrastructure & Systems: Lead the planning, development, and optimization of IT infrastructure, networks, and systems worldwide, ensuring cloud-first architecture, cost effectiveness, resilience, and low-latency delivery.
- IT Support & Service Delivery: Oversee IT support across all regions (APAC, EMEA, and Americas), ensuring the right level of support, infrastructure, and system administration is in place for every Qimate.
- Governance & Compliance: Establish and enforce pragmatic security policies, standards, and procedures, ensuring compliance with industry regulations and certifications (ISO 27001, SOC2, GDPR, NIST) and responding to compliance questionnaires from suppliers, customers, and auditors.
- Risk Management: Perform security risk assessments, audits, and vulnerability tests, providing mitigation strategies to reduce risks to acceptable levels.
- Incident Response & Management: Lead the incident response function to contain, investigate, and resolve security incidents swiftly and effectively.
- Employee Training & Awareness: Develop and administer IT training plans, along with Security awareness programs to instill a culture of security across the organization.
- M&A Integration: Drive swift IT integration of newly acquired companies, migrating them to QIMA’s tools, processes, and security standards.
- Budget Management: Oversee the IT budget globally, ensuring effective allocation of resources for maximum impact.
- Talent Management: Attract, develop, and retain a high-performing global IT and security team.
Qualifications
In order to succeed in this role, you should have:
- Strong knowledge of IT systems, networks, infrastructure, and administration, with deep experience in cloud-based environments (Azure, AWS, or GCP).
- Expertise in cybersecurity, with a comprehensive understanding of security frameworks, incident management, cloud security, network architecture, and security technologies (firewalls, intrusion detection, data encryption).
- Deep understanding of compliance mandates and standards — ISO 27001, SOC2, NIST, GDPR — and how to operationalize them.
- Strong problem-solving skills, with the ability to develop effective solutions.
- Strong leadership and management skills, with the ability to motivate and develop a global team across both IT and security functions.
- Autonomous and capable of engaging effectively with both the C-suite and field operators.
- Ability to work effectively in a fast-paced, global environment with competing priorities.
- Willingness and ability to travel internationally as needed.
Education & Experience
- Master’s Degree from a top-tier University or Engineering School, preferably in Computer Sciences or Engineering.
- 8+ years of experience managing IT & Security, with demonstrated expertise across both IT and Security in Cloud-based environments.
- A leadership experience heading a sizeable and multicultural team (min. 15-20 people)
- Proven track record of leading globally distributed teams. Experience supporting China and Brazil is a plus.
- Experience with M&A IT integration is a strong plus.
Additional Information
All your information will be kept confidential according to EEO guidelines.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply