Head of Information Security
We are seeking an experienced Head of Information Security to develop and oversee the organization’s security strategy, ensuring protection of our systems, data, and assets against cyber threats. The ideal candidate is a strategic and analytical thinker with extensive experience in cybersecurity, risk management, and compliance. As the Head of Information Security, you will lead a team of security professionals, collaborate across departments, and establish policies and practices to safeguard our information infrastructure.
Job Scope
Information Security Strategy & Governance:
- Develop Security Strategy: Create and execute a comprehensive security strategy that aligns with business objectives and mitigates organizational risk.
- Policy Development: Establish and enforce security policies, standards, and guidelines to protect data, systems, and applications.
- Governance & Compliance: Ensure compliance with industry regulations and standards (e.g., ISO 27001, GDPR, HIPAA) and oversee audits, certifications, and regulatory requirements.
Cybersecurity Operations:
- Threat Detection & Prevention: Oversee the deployment of threat intelligence, intrusion detection, and prevention systems to proactively identify and mitigate security risks.
- Incident Response: Establish and lead incident response protocols, ensuring rapid detection, containment, and recovery from security breaches.
- Vulnerability Management: Implement and manage regular vulnerability assessments, penetration testing, and security audits to identify and address security gaps.
Risk Management:
- Risk Assessment: Conduct regular risk assessments to evaluate and address security vulnerabilities across all organizational assets.
- Third-Party Risk: Assess and monitor risks associated with third-party vendors, partners, and external service providers.
- Disaster Recovery & Business Continuity: Develop and maintain disaster recovery and business continuity plans to ensure minimal impact from potential security incidents.
Team Leadership & Development:
- Build & Manage Security Team: Lead, mentor, and develop a high-performing information security team, fostering a culture of continuous learning and collaboration.
- Training & Awareness: Oversee security training and awareness programs for all employees to promote a security-conscious culture within the organization.
- Cross-Functional Collaboration: Work closely with IT, legal, compliance, and business units to integrate security into all operational processes.
Requirements
- Education: Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Experience:
- 10+ years of experience in information security or cybersecurity roles, with at least 5 years in a leadership position.
- Demonstrated experience in designing and implementing security frameworks and policies in large, complex environments.
- Technical Skills:
- Proficiency in security tools and platforms (e.g., SIEM, IDS/IPS, firewalls, DLP, endpoint security).
- Strong knowledge of regulatory and compliance standards (e.g., ISO 27001, NIST, GDPR, PCI-DSS).
- Strong experience with security in cloud environments (AWS, Azure, GCP), identity and access management (IAM), and network security.
- Leadership Skills:
- Excellent leadership and people management abilities, with experience in building and developing high-performing security teams.
- Strong communication skills to explain complex security concepts to non-technical stakeholders.
- Analytical and strategic thinking, with the ability to prioritize and make risk-based decisions.
- Knowledge of Agile methodologies and experience in an Agile work environment, uses of Jira .
Preferred Qualifications
- Certifications such as CISSP, CISM, CISA, or CRISC.
- Experience with DevSecOps practices and integrating security in CI/CD pipelines.
- Knowledge of threat intelligence and security incident response best practices.
We are seeking an experienced Head of Information Security to develop and oversee the organization’s security strategy, ensuring protection of our systems, data, and assets against cyber threats. The ideal candidate is a strategic and analytical thinker with extensive experience in cybersecurity, risk management, and compliance. As the Head of Information Security, you will lead a team of security professionals, collaborate across departments, and establish policies and practices to safeguard our information infrastructure.
Job Scope
Information Security Strategy & Governance:
- Develop Security Strategy: Create and execute a comprehensive security strategy that aligns with business objectives and mitigates organizational risk.
- Policy Development: Establish and enforce security policies, standards, and guidelines to protect data, systems, and applications.
- Governance & Compliance: Ensure compliance with industry regulations and standards (e.g., ISO 27001, GDPR, HIPAA) and oversee audits, certifications, and regulatory requirements.
Cybersecurity Operations:
- Threat Detection & Prevention: Oversee the deployment of threat intelligence, intrusion detection, and prevention systems to proactively identify and mitigate security risks.
- Incident Response: Establish and lead incident response protocols, ensuring rapid detection, containment, and recovery from security breaches.
- Vulnerability Management: Implement and manage regular vulnerability assessments, penetration testing, and security audits to identify and address security gaps.
Risk Management:
- Risk Assessment: Conduct regular risk assessments to evaluate and address security vulnerabilities across all organizational assets.
- Third-Party Risk: Assess and monitor risks associated with third-party vendors, partners, and external service providers.
- Disaster Recovery & Business Continuity: Develop and maintain disaster recovery and business continuity plans to ensure minimal impact from potential security incidents.
Team Leadership & Development:
- Build & Manage Security Team: Lead, mentor, and develop a high-performing information security team, fostering a culture of continuous learning and collaboration.
- Training & Awareness: Oversee security training and awareness programs for all employees to promote a security-conscious culture within the organization.
- Cross-Functional Collaboration: Work closely with IT, legal, compliance, and business units to integrate security into all operational processes.
Requirements
- Education: Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Experience:
- 10+ years of experience in information security or cybersecurity roles, with at least 5 years in a leadership position.
- Demonstrated experience in designing and implementing security frameworks and policies in large, complex environments.
- Technical Skills:
- Proficiency in security tools and platforms (e.g., SIEM, IDS/IPS, firewalls, DLP, endpoint security).
- Strong knowledge of regulatory and compliance standards (e.g., ISO 27001, NIST, GDPR, PCI-DSS).
- Strong experience with security in cloud environments (AWS, Azure, GCP), identity and access management (IAM), and network security.
- Leadership Skills:
- Excellent leadership and people management abilities, with experience in building and developing high-performing security teams.
- Strong communication skills to explain complex security concepts to non-technical stakeholders.
- Analytical and strategic thinking, with the ability to prioritize and make risk-based decisions.
- Knowledge of Agile methodologies and experience in an Agile work environment, uses of Jira .
Preferred Qualifications
- Certifications such as CISSP, CISM, CISA, or CRISC.
- Experience with DevSecOps practices and integrating security in CI/CD pipelines.
- Knowledge of threat intelligence and security incident response best practices.