Cybersecurity Operation Lead
We are seeking a dynamic and experienced Cybersecurity Operation Lead to play a pivotal role in safeguarding our organization's digital assets and ensuring the integrity of our security operations. The ideal candidate will be a seasoned professional with a strong background in security management and dedicated to maintaining a resilient and secure digital landscape. The responsibilities of this role encompass designing IT security architecture, overseeing IT security KPIs/SLAs, and providing assistance in IT security audits and assessments to safeguard our platforms, applications, and data from cyber threats.
NEED TO DO
Security Strategy:
- Develop and drive the platform security strategy in alignment with organizational goals and objectives.
- Create and enforce platform security standards and policies.
Security Architecture:
- Design and implement robust IT security architecture for our digital platforms, ensuring the highest levels of security and compliance.
- Evaluate and select security technologies and tools.
Security Policy and Standards:
- Develop and maintain application security policies, standards, and guidelines.
- Ensure compliance with industry standards and regulatory requirements.
IT Security KPI/SLA Management:
- Define and manage IT security Key Performance Indicators (KPIs) and Service Level Agreements (SLAs) to measure and improve security performance.
- Implement reporting mechanisms to track and report on security metrics.
Subject Matter Expert:
- Act as the subject matter expert for digitalization security technologies, systems, and solutions.
- Incident Response and Investigation:
- Lead the platform security incident response process, ensuring timely and effective resolution of security incidents and breaches.
- Coordinate with internal and external teams to contain, investigate, and mitigate security incidents. Conduct detailed investigations and provide post-incident analysis.
Security Operations:
- Oversee the day-to-day operations of the platform security team.
- Monitor and assess security events, logs, and alerts to detect and respond to potential threats.
Security Compliance:
- Ensure platform security compliance with industry standards and regulatory requirements.
- Conduct regular security assessments and audits to identify and address compliance gaps.
Security Awareness and Training:
- Develop and deliver security training and awareness programs for employees to improve the organization's security posture.
- Promote security awareness and best practices among employees.
Security Technologies:
- Evaluate and implement security technologies, including firewalls, intrusion detection systems, and data encryption solutions.
- Ensure these tools are optimally utilized and aligned with security objectives.
IT Security Audit/Assessment Support:
- Provide support for IT security audits and assessments, collaborating with audit teams to ensure compliance.
- Address audit findings and implement corrective actions.
NEED TO KNOW & NEED TO BE
- Bachelor's degree in computer science required, information security, or a related field. A master's degree is preferred.
- 8-12 years of experience in large-scale IT environments, with a focus on information security and risk.
- Leadership experience, especially in designing and assessing IT security solutions, preferably in financial services.
- Strong knowledge of security technologies, best practices, and compliance requirements. Proficiency in security assessment tools and technologies.
- Proven track record in managing complex projects and effectively handling competing demands. Adaptable to the dynamic cybersecurity landscape, staying updated on the latest security technologies.
- Possesses an impressive ability to drive forward the IT security strategy.
- Skilled in making well-informed and timely decisions.
- Expertise in cloud security technologies, and a solid understanding of Windows/Unix systems and security best practices.
- Strong familiarity with security best practices and concepts.
- Advanced knowledge and hands-on experience with enterprise IT security solutions.
- Familiarity with VPN technologies and the ability to articulate threats and risks to business and technology leaders.
- Demonstrates strong leadership qualities, stakeholder engagement, and independent work.
- Effective at building relationships and interacting with internal and external parties.
- Strong analytical, technical, and written and verbal communication skills.
- Security certifications, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM), are a plus