Responsibilities
• Design, implement and maintain advanced security controls across on-premises, cloud and SaaS environments.
• Define and maintain security architecture standards and assess new technology integrations.
• Lead application security assessments and promote secure development lifecycle practices.
• Configure, manage and optimise enterprise firewalls and WAF solutions.
• Oversee security technologies including SIEM, EDR, DLP, web servers and vulnerability management platforms.
• Develop security automation strategies for threat detection, response and ITSM integration.
• Establish security operational procedures and playbooks while mentoring junior team members.
• Manage relationships, SLAs and performance metrics with outsourced SOC providers.
• Lead major security incident investigations, forensic analysis and root-cause investigations.
• Act as the escalation point for critical security incidents and coordinate cross-functional responses.
• Drive proactive threat hunting and advanced security analytics.
• Develop and manage vulnerability and patch management strategies.
• Provide executive-level reporting on security risks, vulnerabilities and remediation progress.
• Architect and enforce identity governance using Microsoft Entra ID and implement Zero Trust and privileged access management principles.
• Develop and deliver cybersecurity awareness programmes, campaigns and educational content.
• Ensure security alignment with relevant regulatory, compliance and industry frameworks.
• Lead technical audits, penetration testing and red/blue team exercises.
• Develop security metrics, risk dashboards and executive/board-level reports.
• Analyse threat intelligence and security trends and recommend improvements to the organisation’s security posture.
• Maintain detailed documentation and reporting relating to firewall and WAF configurations, changes and performance.
Competency
• Strong information security and cybersecurity expertise.
• Excellent analytical, problem-solving and troubleshooting skills.
• Strong understanding of security architecture, risk management and threat management.
• Excellent communication skills, with the ability to engage with both technical and executive audiences.
• Strong leadership, mentoring and team-development capabilities.
• Excellent organisational, documentation and reporting skills.
• Ability to analyse data, identify trends and translate findings into actionable recommendations.
• Strong ITSM and Microsoft Office proficiency.
• Ability to manage multiple priorities and work effectively in a fast-paced environment.
• Strong stakeholder and customer service orientation.
• Highly ethical, resilient and security-conscious.
• Results and achievement orientated.
• Collaborative team player with a positive and motivated attitude.
• Commitment to continuous improvement and staying current with evolving cybersecurity threats and technologies.