Cybersecurity Domain Lead
Indexed description
As part of the SM Investments (SMIC) Group, you’ll leverage the group’s cybersecurity tools, policies, and 24/7 security monitoring while translating these enterprise-wide mandates into practical solutions that address our unique business and operational needs.
Your core mission is to bridge strategy and execution—ensuring SMIC’s cybersecurity requirements are implemented, validated, and continuously strengthened within the company. You’ll be accountable for cybersecurity execution, control validation, risk escalation, and serving as the primary liaison between the company and SMIC.
Your mission..
- Translate SMIC cybersecurity mandates into company-level execution plans , interpreting security policies and technical standards and defining clear requirements, timelines, owners, and deliverables.
- Drive technical security implementation across Infrastructure, Endpoint, and Application teams , creating detailed technical requirements/tickets, coordinating execution, tracking progress, removing blockers, and escalating delays or resource constraints.
- Validate cybersecurity control implementation and effectiveness through evidence-based checks, including patch compliance, endpoint security agent connectivity, vulnerability remediation, and adherence to required security standards.
- Lead cybersecurity incident triage and response , validating SMIC SOC alerts with company-specific business context, directing containment and remediation activities, and coordinating with technical teams through resolution.
- Identify, assess, and proactively manage cybersecurity gaps across company systems, applications, data, and processes—including technical, regulatory, operational, and resource gaps—and develop practical remediation or compensating controls.
- Manage exceptions and escalations with SMIC , documenting control gaps, assessing business and technical impact, proposing data-backed compensating controls or alternative solutions, and securing formal resolution or exception approval.
- Strengthen company-level threat and vulnerability detection , conducting vulnerability assessments and threat hunting across resources not fully covered by SMIC tools, monitoring logs and reports for anomalies, and providing company-specific context to SMIC’s global security operations.
- A bachelor’s or master’s degree in computer science, cybersecurity, or engineering.
- Solid technical understanding of local IT infrastructure (servers, networks, endpoints, cloud).
- Experience implementing security controls (patching, antivirus, access management, vulnerability and penetration testing, forensic).
- Ability to read and understand security alerts and logs
- Strong documentation skills – you will write gap reports, exception requests, and local runbooks.
- Excellent communication – you must confidently challenge HQ when needed, while maintaining a collaborative relationship.
- 7 to 10 years of experience in IT and cybersecurity, which includes 3 years in managerial capacity
- Experience working in a subsidiary or multi-national company.
- Knowledge of local data protection regulations.
- Certifications: CISM (Certified Information Security Manager), CISSP(Certified Information Security Systems Security Professional)
- Own enterprise impact. You are trusted to influence decisions and enable the business to perform at its best.
- Grow in a valued community. You work in a culture that listens, collaborates, and invests in your long-term success.
- Excel through expertise. You are empowered and recognized for delivering high standards and smart solutions.
- Be recognized and feel valued—at work and beyond. Receive and enjoy competitive compensation, performance bonuses, incentives, travel perks, Day 1 access to health and wellness programs and paid time off designed to support your well-being.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search