BAT is evolving at pace into a global multi-category business. Our purpose is to create A Better Tomorrow™ by Building a Smokeless World.
To achieve our ambition, we are looking for colleagues who are ready to join us on this journey! Tomorrow can’t wait, let’s shape it together!
British American TobaccoGreece has an exciting opportunity for a Global Head of Application and Data Security in Athens
Own for the enterprise Application Security program and the implementation and maturity of Microsoft Purview as the strategic platform for data protection and governance. Define the vision and operating model for secure-by-design development and data lifecycle protection—embedding security into SDLC workflows, standardizing control patterns, and delivering audit-ready evidence aligned to business risk and regulatory obligations. Partner across Digital Business Solutions (DBS) to translate policy and standards into engineered controls, enable product/platform teams to ship securely, and show measurable risk reduction through critical metrics and executive scorecards.
Your key responsibilities will include:
- Threat modelling, secure coding, SAST/SCA/Secrets scanning, DAST, container/K8s and software supply-chain controls; CI/CD guardrails with policy-as-code.
- Implement & mature Microsoft Purview: Information Protection (sensitivity labels), Purview DLP (Email/SharePoint/OneDrive/Teams/Endpoint DLP), records management/retention, information barriers, and (where appropriate) Insider Risk—driving adoption and measurable policy efficiency.
- Operationalize data classification & handling: For MCI/PII/IP across the data lifecycle (at rest, in transit, in use) with clear owner stewardship and critical metrics.
- Publish Application Security and data protection patterns mapped to NIST CSF/800-53 and CIS v8 with acceptance criteria and evidence-by-design. Define Application Security Strategy and Operating model,12–18-month roadmap, outcomes, and important metrics; run intake/build reviews; manage time-boxed exceptions with compensating controls.
- Establish end-to-end data handling standards and monitoring; ensure cross-border, privacy and regulatory constraints are implemented and evidenced. Map controls to NIST/CIS/SOX; define acceptance criteria.
- Advise senior leadership; present posture, trade-offs and decisions in business terms. Build and mentor a high-performing distributed team (architects/engineers/analysts); set decision rights and operating rhythms; drive a metrics-led culture of continuous improvement.
What are we looking for:
- 10+ years in cybersecurity; 5+ years leading Application Security and/or Data Security at enterprise scale (global remit), with a track record building programs from zero to steady state!
- Threat modeling, secure coding standards, SAST/SCA/Secrets/DAST, container/K8s, supply-chain controls, and policy-as-code CI/CD guardrails. Microsoft Purview owner: Implement and mature Information Protection (labels), DLP, records/retention, and (as needed) Insider Risk—drive measurable adoption/efficiency.
- Microsoft E5 & Azure savvy with Entra ID/CA/PIM, Defender family, Defender for Cloud (CSPM/CNAPP), Azure Policy/Bicep/Terraform; AWS familiarity (Security Hub/Config/GuardDuty/IAM AA/Control Tower) a plus.
- Standards → controls - Proven track record to operationalize NIST CSF/800-53, CIS v8, SOX into deployable standards, acceptance criteria, and evidence-by-design reporting. Risk-led prioritization: Uses the pen-test findings and cloud risk signals to drive down exploitable risk on crown-jewel apps;
Positive relationship with Enterprise Architecture, Product/Platform, Cloud/Network/Endpoint, Legal/Records/Privacy, GRC or equivalent experience; excellent executive communication; vendor/budget management. People leader who Builds and mentors a distributed team ; promotes an outcome-focused culture and secure-by-design ways of working
What we offer you?
- We offer a market leading annual performance bonus (subject to eligibility)
- Our range of benefits varies by country and includes diverse health plans, initiatives for work-life balance, transportation support, and a flexible holiday plan with additional incentives
- Your journey with us isn't limited by boundaries; it's propelled by your aspirations. Join us at BAT and become a part of an environment that thrives on internal advancement, where your career progression isn't just a statement – it's a reality we're eager to build together. Seize the opportunity and own your development; your next chapter starts here.
- You'll have access to online learning platforms and personalized growth programs to nurture your leadership skills
- We prioritise continuous improvement within a transformative environment, preparing for ongoing changes
WHY JOIN BAT?
We’re one of the few companies named as a Global Top Employer by the Top Employers Institute – certified in offering excellent employee conditions.
Collaboration, inclusion and partnership underpin everything we do here at BAT. We are looking forward to enabling every individual to thrive, regardless of gender, sexual orientation, marital or civil partnership status, gender reassignment, race, religion or belief, colour, nationality, ethnic or national origin, disability, age, skills, experience, education, socio-economic and professional background, veteran status, perspectives and thinking styles. We know that embracing talent from all backgrounds is what makes us stronger and best prepared to meet our business goals.
We see the career breaks as opportunities not obstacles. Through The Global Returners program, we support professionals looking to restart their careers after an extended absence from the workforce (e.g. time out caring for family, parental leave, national service, sabbatical and/or starting an own venture).
Come bring your difference and see what is possible for you at BAT. Learn more about our culture and our award winning employee experience here.
If you require any reasonable adjustments or accommodations to help you perform at your best during the recruitment process, you are encouraged to notify us. We are fully committed to support you by making appropriate arrangements for you to demonstrate your full potential.