.IT Security Lead
Position Summary
At Techture are seeking an experienced IT Security Lead to lead and manage the organisation's cybersecurity strategy, governance, risk management, compliance, and security operations. The role is responsible for protecting the organisation's information assets, infrastructure, applications, and data from cyber threats while ensuring compliance with industry standards and business requirements.
Key Responsibilities
Security Strategy & Governance
-
Develop and implement the organisation's cybersecurity roadmap and strategy.
-
Establish security policies, standards, procedures, and best practices.
-
Align security initiatives with business objectives and regulatory requirements.
-
Report security posture, risks, and improvements to senior leadership.
Risk Management & Compliance
-
Conduct risk assessments and vulnerability management programs.
-
Ensure compliance with standards such as ISO 27001, SOC 2, GDPR, and applicable regulations.
-
Lead internal and external security audits.
-
Manage third-party and vendor security assessments.
Security Operations
-
Oversee Security Operations Centre (SOC) activities and incident response.
-
Monitor security alerts, threats, and vulnerabilities.
-
Lead investigation and remediation of cybersecurity incidents.
-
Establish disaster recovery and business continuity plans.
Infrastructure & Network Security
-
Manage firewall, VPN, IDS/IPS, endpoint protection, email security, and network security controls.
-
Ensure secure configuration and hardening of servers, workstations, and cloud environments.
-
Implement Zero Trust and least-privilege access models.
Application Security
-
Oversee application security reviews, penetration testing, and secure SDLC practices.
-
Implement identity and access management (IAM) solutions.
Team Leadership
-
Lead, mentor, and develop the cybersecurity team.
-
Coordinate with IT, legal, HR, and business units on security initiatives.
-
Manage security budgets, vendors, and technology investments.
Security Awareness
-
Drive organisation-wide security awareness and phishing simulation programs.
-
Conduct employee cybersecurity training and awareness campaigns.
Required Qualifications
-
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
-
5+ years of IT experience with cybersecurity leadership roles.
-
Strong knowledge of network security, cloud security, endpoint security, IAM, and SIEM technologies.
-
Must have experience managing security audits, risk assessments, and compliance programs.
-
Strong incident response and cyber risk management experience.
Preferred Certifications
-
CISSP
-
CISM
-
CCSP
-
CEH
-
ISO 27001 Lead Auditor
Technical Skills
-
Security Operations & Incident Response
-
SIEM & Log Management
-
Vulnerability Assessment & Penetration Testing
-
Firewall & Network Security
-
Endpoint Detection & Response (EDR)
-
Identity & Access Management (IAM)
-
Data Loss Prevention (DLP)
-
Security Governance, Risk & Compliance (GRC)
KPIs
-
Reduction in security incidents and vulnerabilities.
-
Audit and compliance success rate.
-
Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
-
Security awareness training completion rate.
-
Vendor and third-party risk assessment coverage.
Experience Level
-
At least 5 years of experience leading cybersecurity and information security functions.