Manager, IT Security
Indexed description
ROLE SUMMARY:
The Manager, IT Security is responsible for leading the strategy, governance, and day-to-day operations of the organization's IT Security program across the company. This role provides both strategic direction and hands-on leadership for security operations, risk management, compliance, and incident response, ensuring the confidentiality, integrity, and availability of information systems. The Manager leads a team of IT Security specialists, sets security policy and standards, and partners closely with IT, OT, Cybersecurity and business, to embed security into every technology and business initiative.
ROLES & RESPONSIBILITIES:
• Develop, own, and continuously refine the enterprise IT security strategy, roadmap, and reference architecture aligned with ISO 27001, NIST, and applicable national/industry regulations.
• Lead, mentor, and manage the IT Security team (Senior Specialists and Specialists), including workload planning, performance management, capability development, and succession planning.
• Direct the implementation and administration of enterprise security technologies, including firewalls, IDS/IPS, endpoint protection, anti-malware, email security gateways, SIEM, vulnerability management, and Privileged Access Management (PAM) solutions.
• Oversee enterprise risk assessments, vulnerability management programs, and penetration testing exercises; prioritize, track, and report on remediation of identified risks.
• Own the organization's security incident response program — lead major incident and breach response, forensic investigations, root cause analysis, and post-incident reviews.
• Establish, maintain, and regularly test disaster recovery (DR) and business continuity plans (BCP) for security critical systems and services.
• Develop, approve, and enforce information security policies, standards, procedures, and guidelines across the organization; drive ongoing security awareness and training programs for all employees.
• Ensure compliance with applicable regulatory, contractual, and industry frameworks (ISO 27001, NIST, SOX, GDPR/PDPL, SOC 2, etc.), and act as the primary point of contact for internal and external security audits.
• Manage the IT Security budget, vendor relationships, contract negotiations, and procurement of security tools and services in collaboration with Procurement and Finance.
• Experience in IT Infrastructure, Network, Applications, Cloud, and Service Desk teams to embed security-by-design principles into projects, systems, and change management processes.
• Provide regular reporting and dashboards on security posture, risk exposure, KPIs, and incident trends to IT leadership and executive management.
QUALIFICATION & EDUCATION:
• Bachelor’s degree in computer science, Information Security, Cybersecurity, or a related field; a master’s degree or professional certification in Information Security/Management is preferred.
EXPERIENCE:
• Minimum of 10 years of progressive experience in IT/cybersecurity, including at least 3-5 years in managerial or team-lead capacity overseeing IT security operations.
SKILLS:
Technical Skills
• Strong knowledge of security frameworks and standards (ISO 27001, NIST CSF/SP 800-53, COBIT).
• Hands-on and strategic experience with SIEM, vulnerability management, IDS/IPS, firewalls, endpoint protection, PAM, and email security platforms.
• Solid understanding of cloud security (Azure, AWS), network security fundamentals, and identity and access management (Active Directory, Azure AD/Entra ID).
• Familiarity with servers, virtualization (VMware, Hyper-V), Networks and container security (Docker, Kubernetes).
• Working knowledge of scripting/automation (PowerShell, Python, Bash) to support security operations and reporting.
• Strong understanding of ITSM/ITIL practices, change management, and IT governance frameworks.
Soft Skills and Leadership Competencies
• Proven leadership, team management, coaching, and mentoring capabilities.
• Excellent stakeholder management and executive communication skills, with the ability to translate technical risk into business terms.
• Strong analytical, decision-making, and crisis-management skills, particularly during security incidents.
• Ability to manage budgets, vendors, and multiple concurrent projects and priorities.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search