Sobre esta vaga de Senior Scrum Master (Cyber) na Haleon
Welcome to Haleon. We’re a purpose-driven, world-class consumer company putting everyday health in the hands of millions. In just three years since our launch, we’ve grown, evolved and are now entering an exciting new chapter – one filled with bold ambitions and enormous opportunity.
Our trusted portfolio of brands – including Sensodyne®, Panadol®, Advil®, Voltaren®, Theraflu®, Otrivin®, and Centrum® – lead in resilient and growing categories. What sets us apart is our unique blend of deep human understanding and trusted science.
Now it’s time to fully realise the full potential of our business and our people. We do this through our Win as One strategy. It puts our purpose – to deliver better everyday health with humanity – at the heart of everything we do. It unites us, inspires us, and challenges us to be better every day, driven by our agile, performance-focused culture.
About the role
The D&T Scrum Manter (Cyber Security / DTIS) is responsible for the end-to-end delivery of cyber security, information security, risk reduction and compliance initiatives within Haleon's Digital & Technology Information Security (DTIS) organisation.
The Scrum Manter is responsible for driving governance, planning, reporting and operational oversight across Cyber Security and Information Security initiatives within the Run and Maintain portfolio. This includes initiatives such as Identity & Access Management (IAM), Privileged Access Management (PAM), Security Operations, Vulnerability Management, Data Protection, Security Compliance, Cloud Security and Cyber Risk Remediation programs. The role ensures delivery predictability, stakeholder transparency, portfolio control and continuous improvement across DTIS initiatives.
The role ensures projects are delivered with discipline, transparency and predictability, operating within established delivery frameworks, cyber security governance standards, risk management processes and portfolio controls. Working closely with business stakeholders, DTIS teams, delivery partners and suppliers, the Scrum Manter maintains clear ownership of scope, plans, risks and security outcomes.
This role is suited to an experienced delivery professional who is comfortable operating in complex, enterprise cyber security environments, managing multiple stakeholders and suppliers, and providing clear, reliable insight throughout the project lifecycle.
Role Purpose
To deliver Cyber Security and DTIS projects safely and predictably, ensuring agreed business and security outcomes are achieved by applying standard delivery frameworks, proactively managing cyber risks and dependencies, and maintaining effective communication with stakeholders and leadership.
Key Accountabilities
The D&T Scrum Manter is accountable for:
Successful end-to-end delivery of assigned Cyber Security and DTIS projects.
Consistent application of DTIS governance, risk management and delivery frameworks.
Effective management of scope, plans, cyber risks, issues and dependencies.
Clear and timely reporting of project status, cyber risk posture and key decisions.
Strong stakeholder, vendor and security partner management.
Maintaining focus on agreed business, compliance and security outcomes.
Supporting the reduction of cyber risk through effective delivery of security remediation initiatives.
Key Responsibilities
1. Project Delivery & Execution
Own the delivery of assigned Cyber Security and DTIS projects from initiation through closure.
Deliver security initiatives including Identity & Access Management (IAM), Privileged Access Management (PAM), Vulnerability Management, Data Protection, Security Operations, Cloud Security and Infrastructure Security.
Ensure projects deliver agreed scope, timelines, quality standards, security controls and business outcomes.
Apply standard D&T delivery approaches (Waterfall, Agile or Hybrid as appropriate).
2. Planning & Control
Develop and maintain robust project plans, including milestones, dependencies and critical paths.
Coordinate delivery activities across security, infrastructure, application and business teams.
Track remediation commitments and ensure timely closure of security actions.
Manage project changes in a controlled and transparent manner.
3. Risk, Issue & Dependency Management
Proactively identify, manage and escalate cyber security risks, issues and dependencies.
Coordinate remediation of findings resulting from security assessments, audits, penetration testing and compliance reviews.
Ensure mitigation actions are clearly defined, owned and tracked to closure.
Maintain an accurate view of project health, cyber risk exposure and delivery confidence at all times.
4. Stakeholder Management & Communication
Act as the primary point of contact for stakeholders across business, DTIS, Risk, Privacy, Infrastructure, Application teams and suppliers.
Provide clear, honest and timely communication regarding project status, cyber risks, remediation progress, decisions and impacts.
Facilitate governance, steering committee and cyber risk review meetings.
Manage expectations and maintain alignment throughout the project lifecycle.
5. Financial & Resource Management (Project Level)
Manage project budgets, forecasts and financial controls within delegated authority.
Work with Finance partners to provide accurate financial reporting and visibility of variances.
Ensure project resources, security SMEs and technical teams are planned and utilised effectively.
6. Supplier & Third-Party Management
Manage delivery contributions from third-party security vendors, managed security service providers (MSSPs) and implementation partners.
Ensure suppliers deliver to agreed timelines, quality, security and contractual requirements.
Escalate supplier performance issues through appropriate governance channels.
7. Governance & Reporting
Operate within established cyber security governance frameworks, ensuring all required artefacts and controls are maintained.
Provide accurate, decision-oriented reporting into DTIS leadership, portfolio, assurance and risk forums.
Support internal audits, external audits, compliance assessments and stage-gate reviews.
Track and report cyber risk reduction and remediation metrics.
8. Outcomes, Adoption & Handover
Maintain focus on agreed business, security and compliance outcomes throughout delivery.
Support operational transition and handover activities to Security Operations and support teams.
Contribute to benefits realisation and cyber risk reduction tracking.
9. Continuous Improvement & Professional Standards
Apply lessons learned and cyber security best practices to improve delivery effectiveness.
Contribute positively to DTIS delivery standards, governance maturity and ways of working.
Demonstrate accountability, professionalism and strong delivery discipline.
Promote a culture of security awareness and risk-based decision making.
What Good Looks Like
Cyber Security and DTIS projects are delivered with few surprises and clear delivery confidence.
Security risks, vulnerabilities and audit findings are identified early and remediated proactively.
Stakeholders have clear visibility of project progress, security posture and remediation status.
Cyber governance processes are followed consistently and professionally.
Security controls are successfully implemented and adopted.
Business, compliance and security outcomes are achieved.
The Scrum Manter is seen as reliable, organised and accountable.
Qualifications & Skills
Essential
8 – 13 years of experience delivering projects in Cyber Security, Information Security, Technology Risk, Digital or Technology environments.
Strong understanding of cyber security domains including:
Identity & Access Management (IAM)
Privileged Access Management (PAM)
Vulnerability Management
Security Operations (SOC)
Endpoint Security
Network Security
Data Protection
Cloud Security
Experience managing security remediation programs arising from audits, penetration testing and risk assessments.
Strong understanding of cyber risk management, security governance and compliance requirements.
Experience managing risks, dependencies and stakeholder expectations in complex environments.
Strong planning, organisational and communication skills.
Comfortable working in global, matrixed and highly regulated environments.
Preferred
Experience operating within enterprise cyber security governance and portfolio frameworks.
Experience working with Security Operations Centres (SOC) and Managed Security Service Providers (MSSPs).
Exposure to security frameworks including ISO 27001, NIST Cyber Security Framework, CIS Controls and GDPR/Data Privacy requirements.
Experience delivering cloud security initiatives across Azure, AWS or GCP environments.
Experience managing third-party suppliers and security technology vendors.
Relevant delivery certifications (PRINCE2, PMP, Agile Practitioner or equivalent).
Security certifications such as CISSP, CISM, CRISC, CCSP or ISO 27001 Lead Implementer/Auditor.
Job Posting End Date
2026-09-26
Equal Opportunities
Haleon are committed to mobilising our purpose in a way that represents the diverse consumers and communities who rely on our brands every day. It guides us in creating an inclusive culture, where different backgrounds and views are valued and respected – all in support of understanding and best serving the needs of our consumers and unleashing the full potential of our people. It’s important to us that Haleon is a place where all our employees feel they truly belong.
During the application process, we may ask you to share some personal information, which is entirely voluntary. This information ensures we meet certain regulatory and reporting obligations and supports the development, refinement, and execution of our inclusion and belonging programmes that are open to all Haleon employees.
The personal information you provide will be kept confidential, used only for legitimate business purposes, and will never be used in making any employment decisions, including hiring decisions.
Adjustment or Accommodations Request
If you require a reasonable adjustment or accommodation or other assistance to apply for a job at Haleon at any stage of the application process, please let your recruiter know by providing them with a description of specific adjustments you are requesting. We’ll provide all reasonable adjustments to support you throughout the recruitment process and treat all information you provide us in confidence.
Note to candidates
The Haleon recruitment team will contact you using a Haleon email account (@haleon.com). If you are not sure whether the email you received is from Haleon, please get in touch.