Search by job title, skills, company or browse by categories.
Cybersecurity Lead
Full-timeOn-site
- Plaines Wilhems
- Salary not disclosed
- Posted Sep 7, 2026
- Closing 07/10/2026
- ICT / IT / Web
- Cybersecurity Lead
- It Security Lead
- Information Security Specialist
- Security Analyst
Sector
Skills
Job Description
Role Purpose
Owns the organization's information security strategy, governance, and day-to-day security operations. Leads incident response, drives compliance with regulatory and industry frameworks, and provides technical oversight for the Cloud & Security Administrator and other IT staff on security-related matters.
Key Responsibilities
Cybersecurity governance
- Define and maintain the organization's information security policies, standards, and procedures
- Drive compliance with relevant frameworks/regulations (e.g. ISO 27001 and applicable cybersecurity laws and regulations applicable to ITL such as the FSC Cyber Governance Guideline and Cloud Computing Guideline)
- Conduct or coordinate regular access reviews, audits, and risk assessments
- Sign off on security-critical changes made by other IT staff (e.g. access grants, Conditional Access policy changes)
- Act as primary liaison with external auditors, regulators, and security vendors
Cybersecurity advisory
- Act as subject matter expert by providing management with recommendations aligned with business objectives
- Provides cross functional advisory from a cybersecurity perspective to other business units in digital transformation projects in areas such as data protection/AI governance/data governance
- Collaborate with the wider IT team to ensure that cybersecurity best practices are consistently implemented
Security monitoring, incident response and reporting
- Lead security incident response: detection, containment, investigation, and post-incident review
- Oversee the organization's security tooling stack (email security, endpoint security, managed extended detection and response [MXDR]), cloud infrastructure, and ensure proper configuration and monitoring, with the Cloud & Security Administrator handling day-to-day administration
Vulnerability management
- Own vulnerability management program: risk prioritization, remediation oversight, penetration test coordination
- Perform or guide junior staff in performing vulnerability assessment and penetration testing as and when needed
Cybersecurity awareness
- Perform or guide junior staff in running spear phishing drills
- Provide security awareness and guidance to new joiners and refreshers
Third party risk management
- Perform or guide junior staff in performing cybersecurity due diligence on third parties as part of the company’s Technology Procurement process
Project Management
- Spearhead and oversees implementation of cybersecurity related projects and ensures liaison with third parties, internal IT team and other business stakeholders
Required Skills / Experience
- 6+ years in information security roles (mix of hands-on and cybersecurity governance), including incident response and risk management
- Strong knowledge of network security and cloud security (M365/Azure) along with novel threats such as AI driven threats
- Knowledge in offensive security/defensive security/digital forensics is good to have
- Understanding of firewall configuration/fine-tuning of firewall rules
- Relevant certifications preferred: CISSP, CISM, CRISC, eJPT or equivalent
- Experience in a regulated industry (financial/professional services) strongly preferred
- Strong stakeholder management and communication skills, this role interfaces with leadership, auditors, and regulators