About the job
Objective: We are in search of a seasoned Cyber Security Lead Engineer to spearhead the design, execution, and ongoing enhancement of our cybersecurity protocols within a hybrid framework. This pivotal role encompasses the supervision of infrastructure, application, and cloud security; managing threat detection and incident response systems; steering the security integrity of internally developed software; and ensuring adherence to regulatory standards via Governance, Risk & Compliance (GRC) frameworks. The ideal candidate will possess a robust technical foundation, exemplary leadership skills, and a proactive approach to safeguarding our digital assets and business operations.
Key Responsibilities:
1. Security Architecture & Strategy
- Design, implement, and uphold a comprehensive security architecture for both on-premises and cloud environments.
- Establish secure network topologies, including segmentation, access controls, and VPN configurations.
- Lead the creation and enforcement of security policies, procedures, and best practices.
- Collaborate with developers and IT architects to integrate security into application and infrastructure design.
2. SOC, SIEM, and Threat Management
- Oversee the operation and optimization of the Security Operations Center (SOC), including SIEM systems.
- Manage endpoint protection through EDR and threat-hunting solutions.
- Enhance email security measures to defend against phishing, malware, and spam while ensuring compliance with organizational security policies.
- Lead incident response initiatives and develop proactive threat prevention strategies.
3. Application and Cloud Security
- Supervise vulnerability assessments and penetration testing for internally developed applications.
- Direct WAF deployment and optimization to safeguard mission-critical web applications.
- Implement security best practices and policy enforcement across multi-cloud environments.
4. Governance, Risk & Compliance (GRC)
- Drive compliance initiatives related to cybersecurity (e.g., SOC 2 Type 2, ISO 27001).
- Lead cross-functional GRC efforts and support internal and external audits.
- Conduct security risk assessments and recommend mitigation strategies.
5. Documentation & Collaboration
- Maintain thorough documentation for security controls, policies, systems, and incidents.
- Organize and conduct quarterly security awareness training sessions to educate staff on emerging cyber threats, best practices, and organizational security policies.
- Collaborate closely with software engineers, network teams, DevOps, and various business units.
