Manager – Security Operations
Job Brief
Indecomm is looking to hire a Security Operations Manager who will be an integral part of the Information Security Team, responsible for managing, implementing, and monitoring secure IT systems and processes in alignment with the approved Enterprise Architecture and IT Strategy. The role will involve leading a team and overseeing the development and maintenance of the Company’s Security Operations function.
Roles and Responsibilities
- Design and implement a comprehensive risk management process for the organization, including an analysis of the financial impact of risks.
- Conduct policy and compliance audits, collaborating with internal and external auditors.
- Review compliance requirements for existing and new contracts or internal business proposals.
- Promote risk awareness among staff by providing support and training within the company.
- Provide support, education, and training to build ISO awareness within the organization.
- Lead, coordinate, and manage the security team, setting goals and providing performance and professional development feedback.
- Collaborate with the security operations team to support analysts with performance feedback, training, and career guidance.
- Manage and coordinate incident response and forensic processes.
- Monitor and enforce guidelines for best practices in security and compliance.
- Support routine regulatory and compliance audit initiatives.
- Orchestrate daily compliance requirements and tasks as needed.
- Demonstrate strong leadership skills during incident and crisis management situations.
- Possess a technical understanding of current cybersecurity threats and trends.
- Exhibit comprehensive knowledge of vulnerability assessment and penetration testing techniques, methodologies, and tools, covering:
- Operating system and network level assessment.
- Web application assessment.
- MDM security assessment.
- Cloud security assessment.
- Evaluate client security environments based on project scope and provide practical and suitable recommendations.
- Design, build, and implement enterprise-class security systems for a production SaaS environment.
- Identify security design gaps in existing and proposed architectures and propose changes or enhancements.
Requirements
- Graduate degree in Computer Science, IT, or equivalent.
- Minimum of 7 to 10 years of relevant experience in security operations.
- Experience in implementing security guidelines/best practices such as OWASP, OSSTMM, NIST, COSO, CCM, etc., and providing guidance to enhance customer security posture.
- Familiarity with SOC/Security assessment tools (e.g., LogRhythm, LogRhythm Netmon, Fortianalyzer, SolarWinds, Nessus, Acunetix, AppScan, etc.).
- Broad knowledge of local and international standards/regulatory requirements such as ISO 27001, PCI-DSS, GDPR, NIST, CCPA, CPRA, GLBA, SOX, HIPAA, etc.
- Hold at least one of the following certifications (mandatory):
- CISSP
- CSSP
- CISA
- CISM
- CRISC
- The ability to update assessment methodologies to address the latest threats and vulnerabilities.
- Strong ability to prioritize effectively and see the big picture.
- Demonstrated ability to adapt to new technologies and learn quickly.
- Excellent written and oral communication skills.
- Strong stakeholder management and leadership skills.
- Demonstrates a high level of flexibility.
- Proactive, influential, and collaborative.