Key Responsibilities
Security Strategy & Governance
- Develop and maintain the organization's information security roadmap aligned with business objectives.
- Establish cybersecurity policies, standards, procedures, and best practices.
- Lead security governance initiatives and ensure security controls are effectively implemented.
- Conduct regular security assessments and gap analyses.
- Provide strategic security recommendations to executive leadership.
Risk Management & Compliance
- Identify, assess, and mitigate cybersecurity risks across the organization.
- Ensure compliance with regulatory requirements and industry frameworks including ISO 27001, NIST, CIS Controls, PCI-DSS, GDPR, and local regulations where applicable.
- Coordinate internal and external security audits.
- Maintain risk registers and remediation plans.
Security Operations
- Oversee Security Operations Center (SOC) functions and security monitoring activities.
- Manage security tools such as:
- SIEM
- EDR/XDR
- IDS/IPS
- Web Application Firewall (WAF)
- Data Loss Prevention (DLP)
- Vulnerability Management platforms
- Ensure continuous monitoring and threat detection capabilities.
Incident Response & Threat Management
- Lead cybersecurity incident response, investigation, containment, and recovery efforts.
- Develop and maintain Incident Response Plans and Playbooks.
- Coordinate forensic investigations when necessary.
- Conduct post-incident reviews and implement corrective actions.
- Monitor emerging threats and vulnerabilities.
Security Architecture & Engineering
- Review and approve secure architecture designs for infrastructure, cloud, and applications.
- Collaborate with IT, DevOps, and development teams to implement security-by-design principles.
- Support cloud security initiatives across AWS, Azure, and Google Cloud environments.
- Oversee vulnerability assessments and penetration testing activities.
Team Leadership
- Lead and mentor security engineers, analysts, and consultants.
- Establish security KPIs, performance objectives, and development plans.
- Manage vendor relationships and third-party security services.
- Promote cybersecurity awareness programs across the organization.
Required Qualifications
Education
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field.
- Master's degree is preferred.
Experience
- 7+ years of experience in cybersecurity or information security.
- 3+ years of leadership or team management experience.
- Proven experience managing enterprise security programs.
- Hands-on experience with security monitoring, incident response, and risk management.
Technical Skills
- Strong understanding of:
- Network Security
- Cloud Security
- Application Security
- Identity and Access Management (IAM)
- Security Architecture
- Threat Intelligence
- Vulnerability Management
- Security Operations (SOC)
- Experience with AWS, Microsoft Azure, or Google Cloud security services.
- Knowledge of Zero Trust Architecture and modern cybersecurity frameworks.
- Familiarity with DevSecOps practices and CI/CD security integration.
Security Certifications (Preferred)
One or more of the following:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- GIAC Certifications
- CEH (Certified Ethical Hacker)
- CCSP (Certified Cloud Security Professional)
- ISO 27001 Lead Implementer / Lead Auditor
