Cyber Security Lead
Role & responsibilities Lead and manage cybersecurity strategy, operations, and security initiatives aligned with business objectives and regulatory requirements. Define enterprise security architecture, policies, standards, controls, and governance frameworks. Develop and execute cybersecurity roadmaps covering threat management, risk reduction, compliance, and security maturity improvement. Lead Security Operations Center (SOC) functions including monitoring, threat detection, incident response, and security investigations. Oversee implementation and management of security technologies including SIEM, SOAR, EDR/XDR, IAM, PAM, DLP, WAF, IDS/IPS, and vulnerability management platforms. Conduct cybersecurity risk assessments, threat modeling, security reviews, and control assessments for applications, infrastructure, and cloud environments. Drive cloud security initiatives across AWS, Microsoft Azure, and Google Cloud environments. Establish and enforce Zero Trust security principles, identity management controls, encryption standards, and access governance. Lead incident response activities including investigation, containment, remediation, root cause analysis (RCA), and post-incident improvements. Implement DevSecOps practices by integrating security controls into CI/CD pipelines and software development lifecycle processes. Manage vulnerability management programs including vulnerability scanning, remediation tracking, and security improvement plans. Ensure compliance with security frameworks and regulations including ISO 27001, NIST, CIS Controls, PCI DSS, GDPR, and industry-specific requirements. Develop security policies, procedures, playbooks, incident response plans, and operational documentation. Lead security audits, penetration testing activities, third-party risk assessments, and compliance reviews. Manage relationships with security vendors, MSSPs, technology partners, and internal stakeholders. Mentor cybersecurity engineers, analysts, and SOC teams while promoting security awareness and best practices. Provide executive-level security reporting, risk insights, and recommendations to leadership teams.
Preferred candidate profile Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Information Security, or a related technical discipline. 8 to 13 years of experience in Cybersecurity, Information Security, Security Operations, Security Engineering, or Security Architecture roles. Proven experience leading enterprise cybersecurity programs, security operations, and risk management initiatives. Strong hands-on experience with security architecture, threat management, incident response, vulnerability management, and security governance. Extensive knowledge of SIEM, SOAR, EDR/XDR, IAM, PAM, DLP, WAF, IDS/IPS, and security monitoring solutions. Experience with security platforms such as Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, CrowdStrike, SentinelOne, Palo Alto Networks, Fortinet, and Check Point. Strong understanding of cloud security architecture across AWS, Microsoft Azure, and Google Cloud Platform. Experience implementing Zero Trust Architecture, IAM, MFA, encryption, PKI, identity governance, and data protection controls. Strong knowledge of DevSecOps, secure SDLC, application security, API security, OWASP Top 10, and container security. Experience with cybersecurity frameworks including NIST CSF, ISO 27001, CIS Controls, PCI DSS, GDPR, and risk management frameworks. Strong understanding of network security, endpoint security, malware analysis, threat intelligence, and digital forensics. Excellent leadership, stakeholder management, communication, and decision-making skills. Experience managing cybersecurity teams, vendors, audits, and enterprise security projects. Ability to translate technical security risks into business impact and executive-level recommendations.
Preferred certifications CISSP (Certified Information Systems Security Professional) CISM (Certified Information Security Manager) CCSP (Certified Cloud Security Professional) CISA Microsoft Certified: Cybersecurity Architect Expert AWS Certified Security Specialty Google Professional Cloud Security Engineer CEH SABSA Security Architect Certification TOGAF Certified Enterprise Architect ISO 27001 Lead Auditor / Lead Implementer GIAC Security Certifications #J-18808-Ljbffr