- Develop, implement, and maintain the organization’s information security strategy, policies, and procedures.
- Identify, evaluate, and mitigate security risks across networks, systems, and data.
- Lead the implementation of security tools and technologies to monitor and protect against vulnerabilities, threats, and attacks.
- Conduct and review regular risk assessments, vulnerability scans, and security audits.
- Ensure compliance with data protection regulations, industry standards, and internal policies (e.g., GDPR, HIPAA, NIST, ISO 27001).
- Collaborate with IT and other departments to design and implement secure systems, networks, and applications.
- Investigate and respond to security incidents and breaches, coordinating response efforts effectively.
- Monitor environments for potential incidents, responding to alerts proactively.
- Provide security awareness training to employees and promote a culture of security.
- Stay updated on the latest security trends, threats, and best practices.
- Prepare and present security reports to senior management, including risk analysis and incident response activities.
- Degree in Information Technology, Cybersecurity, or a related field.
- Minimum of 3 years of experience in information security, with a proven track record of managing security programs and teams.
- Strong knowledge of security frameworks and standards (e.g., NIST, ISO 27001, CIS, SOC 2).
- Experience with risk management, incident response, and disaster recovery planning.
- Expertise in security tools and technologies such as firewalls, encryption, intrusion detection/prevention systems, and endpoint security.
- In-depth understanding of security protocols, threat intelligence, and security architecture.
- Strong analytical and problem-solving skills with the ability to make data-driven decisions.
- Excellent communication and interpersonal skills, with the ability to collaborate effectively across teams and with senior leadership.
- Certifications such as CISSP, CISM, CISA, or similar are highly preferred.
- Familiarity with cloud security principles and tools (e.g., AWS, Azure).
- Experience with penetration testing and ethical hacking.
- Ability to manage security budgets and vendor relationships.
- Experience with IT governance and compliance frameworks (e.g., ISO 27001, SOX, PCI DSS).
- Competitive salary and benefits package.
- Opportunities for professional development and certifications.
- A dynamic and collaborative work environment.
- Exciting projects that make a real impact.