Support the Head of Information Security in the execution of cybersecurity strategy, roadmaps and policies.
Work closely with cross-functional teams, including IT and Legal, to align security objectives with organisational needs.
Manage and optimise areas such as bug bounty program, vulnerability management, Privileged Access Management (PAM), Cloud Security Posture Management (CSPM), managed security services, phishing simulation, attack surface management, red-teaming, tabletop exercises and security incident response.
•
Cloud, Application and DevSecOps Security
Assess AWS and Azure environments and embed threat modelling, secure coding, and SAST, SCA, image and infrastructure-as-code scanning into CI/CD pipelines.
•
AI Security and Automation
Lead AI security assessments and POCs covering data protection, AI gateways, prompt and response controls, agent and MCP security, governance and automation.
•
Vendor and Programme Management
Lead vendor evaluation, POCs, contracts, renewals, service governance, budgets and cross-functional delivery.
•
Policy and Framework Development
Create and implement security policies and standards, ensuring compliance with suitable frameworks like ISO 27001 and NIST CSF.
•
Compliance and Governance
Support audits and compliance activities relating to applicable regulations and standards, including ISO 27001, NIST CSF, SOX and data protection requirements.
Conduct security risk assessments, develop mitigation strategies and assist in contract reviews from information security perspective.
Regularly update the Head of Information Security and leadership on security posture, risks, and initiatives. Develop KPIs to measure security program effectiveness.