Security Operations Lead
Mandaluyong, Metro Manila, Philippines
Job Summary
Core responsibilities will be to drive and manage people, process, and technology controls to protect the College’s information systems, information assets, infrastructure, and networks from potential threats. The role will be critical in leading compliance and awareness activities, as well as managing security incidents and risk mitigation activities to drive the College’s information security strategy and roadmap.
This position reports to the IT Operations Manager.
Service Delivery
- Develop, drive, and manage controls to protect the College’s information assets.
- Lead compliance and awareness activities such as security awareness campaigns and training.
- Manage potential information security incidents and risk mitigation activities.
- Assess business impacts of current and emerging threats and recommend strategies to address them.
- Provide advice and hands-on operational support for security technologies including but not limited to managed services, perimeter defence, identity and access management, and creating scripts to automate processes for improved efficiency.
- Contribute to development of the Information Security Roadmap and drive capability maturity uplift through fit-for-purpose people, process, and technology controls.
- Develop and enforce information security policies, and standards to align with known frameworks and best practice.
- Maintain and enhance security standards, and lead compliance programs to continually improve operational systems and processes.
- Lead targeted awareness campaigns, training, and tabletop exercises for security awareness to mitigate risks and improve incident response maturity.
- Participate in governance meetings, contribute to the strategic and operational risk registers, oversee the implementation of mitigation controls and monitor their effectiveness by tracking changes in risk levels.
- Collaborate and communicate with internal and external stakeholders to design and implement fit-for-purpose security solutions.
- Perform forensic analysis of potential cyber security incidents.
- Test, verify and report on the effectiveness of security controls.
- Hardening technology platforms such as Microsoft Azure, Microsoft 365, firewalls, servers (physical or virtual), and networking equipment.
- Involvement in projects that require IT security expertise and input.
- Escalation point for IT Service Desk where information security expertise assistance is required.
- Provide guidance and support on new developments, upgrades, refreshes, and configurations of services ensuring security by design
- Monitor the organization's security infrastructure and systems and carry out proactive threat hunting to identify potential security risks
- Collaborate with managed security partners to detect and analyse security events and incidents and lead containment, eradication, and recovery activities. This includes determining impact and severity levels, escalating and notifying relevant parties as appropriate, and contributing to troubleshooting and resolution.
- Ensure that activities follows the appropriate methodology – e.g. change management, incident management, ITIL best practices.
- Manage delivery of all assigned technical project activities to ensure they are planned and tracked to completion.
- Manage the delivery of all root cause analysis reports for high severity information security incidents.
- Create and maintain information security documentation.
- Escalate and manage incident/request to external technology partners when required.
Technical
- Perform forensic analysis of potential cyber security incidents.
- Test, verify and report on the effectiveness of security controls.
- Hardening technology platforms such as Microsoft Azure, Microsoft 365, firewalls, servers (physical or virtual), and networking equipment.
- Involvement in projects that require IT security expertise and input.
- Escalation point for IT Service Desk where information security expertise assistance is required.
- Provide guidance and support on new developments, upgrades, refreshes, and configurations of services ensuring security by design
- Monitor the organization's security infrastructure and systems and carry out proactive threat hunting to identify potential security risks
- Collaborate with managed security partners to detect and analyse security events and incidents and lead containment, eradication, and recovery activities. This includes determining impact and severity levels, escalating and notifying relevant parties as appropriate, and contributing to troubleshooting and resolution.
Process
- Ensure that activities follows the appropriate methodology – e.g. change management, incident management, ITIL best practices.
- Manage delivery of all assigned technical project activities to ensure they are planned and tracked to completion.
- Manage the delivery of all root cause analysis reports for high severity information security incidents.
- Create and maintain information security documentation.
- Escalate and manage incident/request to external technology partners when required.
Requirements
Essential
- 3-5 years' experience within the cyber security field as Security Operations Team Lead.
- Demonstrated knowledge of cyber security standards, frameworks, and policies
- Proven experience in cyber security operations, managing security incidents and response, threat hunting, and conducting forensic investigations
- Strong knowledge of on-premise and cloud security technologies, infrastructure, capabilities and services, including endpoint security, operating system patching and hardening, vulnerability management, identity and access management, cloud security, email security, and SIEM solutions
- Strong knowledge across information and communication technologies
- Demonstrated experience as a Security Specialist/Consultant in an information security role
- Excellent written and verbal communication skills
- Excellent stakeholder engagement skills
- Relevant cyber security certifications
- Strong fundamental understanding of enterprise technologies and infrastructure including Networking, Servers & Storage, cloud platforms, and virtualisation.
- Good understanding of ITIL principles and methodologies.
- Methodical approach to problem solving with attention to detail.
- Team oriented, self-starter with a ‘can-do’ attitude and the ability to work flexibly as part of a dynamic and fast-paced organisation.
- Strong focus on stakeholder engagement and customer service.
- A willingness to take direction, manage multiple tasks of varying priority whilst always putting the customer first.
- Self-motivated and driven to learn and grow.
- Must be amendable for a hybrid setup (3x/week onsite. Early morning shift schedule. Physical OfficeL Mega Tower, Mandaluyong City.
Benefits
Standard Job Benefits:
- HMO on Day 1
- Paid Time-Off
- Quarterly Sick-Leave conversion
- Paid Government-Mandated Benefits
- Equipment provided
Standard Job Highlights:
- Career growth and development opportunities
- Stable organization and industry leader
- Collaborative and fruitful company culture
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Azure Cloud Compliance Endpoint security Firewalls Governance IAM Incident response ITIL Security strategy SIEM Strategy Vulnerability management
Perks/benefits: Career development Gear Startup environment Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open CISM-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs