Cyber Security Lead
Position Summary
The Cyber Security Lead is responsible for developing, implementing, and maintaining the organization's cybersecurity strategy, policies, and security controls. This role provides technical leadership and operational oversight for all cybersecurity initiatives, ensuring the confidentiality, integrity, and availability of company systems, networks, applications, and data. The Cyber Security Lead partners with business leaders, IT teams, vendors, and stakeholders to identify risks, improve security posture, maintain compliance requirements, and respond to cybersecurity threats. This individual serves as the primary security subject matter expert and drives continuous improvement of the organization's security program.
Essential Duties And Responsibilities
Security Operations
Lead the day-to-day cybersecurity operations of the organization.
Monitor and respond to security alerts, incidents, and threats.
Oversee security tools including SIEM, endpoint protection, vulnerability management, email security, and identity management platforms.
Coordinate incident response activities, investigations, containment, remediation, and post-incident reviews.
Develop and maintain cybersecurity monitoring and alerting processes.Risk Management
Conduct cybersecurity risk assessments and recommend mitigation strategies.
Identify vulnerabilities and oversee remediation efforts.
Develop and maintain risk registers and security improvement roadmaps.
Evaluate security risks associated with new technologies, vendors, and business initiatives.Governance, Compliance, and Policy Management
Develop, maintain, and enforce cybersecurity policies, standards, and procedures.
Ensure compliance with applicable regulatory, contractual, and industry requirements.
Support internal and external audits.
Maintain cybersecurity documentation, evidence, and reporting requirements.
Collaborate with legal, HR, and business stakeholders on security-related matters.Security Architecture and Engineering
Provide security guidance for infrastructure, cloud, network, and application projects.
Review and approve security designs and configurations.
Recommend and implement security best practices across Microsoft 365, Azure, Windows Server, VMware, networking, and enterprise applications.
Support secure deployment and configuration standards.Identity and Access Management
Oversee identity governance and access control processes.
Review privileged access management practices.
Ensure appropriate user provisioning, deprovisioning, and access reviews are conducted.
Support implementation of Zero Trust security principles.Security Awareness and Training
Develop and manage cybersecurity awareness programs.
Conduct phishing simulations and user education initiatives.
Promote a security-focused culture throughout the organization.
Provide security guidance and training to IT staff and business users.Vendor and Third-Party Security
Assess cybersecurity controls of vendors and service providers.
Participate in vendor selection and contract review processes.
Monitor third-party risks and ensure security requirements are met.Leadership and Reporting
Serve as the primary cybersecurity advisor to IT leadership and business stakeholders.
Develop security metrics, dashboards, and executive reporting.
Lead cybersecurity projects and initiatives.
Mentor IT personnel on cybersecurity best practices.
Manage relationships with external security vendors, consultants, and auditors.