Job Description :
Head of Security Operations
Reporting to Mynt's Chief Information Security Officer (CISO), the Head of Security Operations is responsible for the day-to-day Cybersecurity operations detecting and responding to Cybersecurity threats, events, and incidents. The role supports the overall Cybersecurity program and provides leadership to develop, support, and advance strategies, programs, and projects designed to continually improve and enhance Mynt's cyber and information security posture and resiliency.
In This Role, The Successful Candidate Will
Establish and implement security tools, technologies, processes, and procedures appropriate to the detection of threats and attacks against company infrastructure and information. Furthermore, this position also directs the company response to attacks and incidents including the containment and eradication strategy to ensure minimal impact to business operations.
Regularly review operation of security controls and recommend changes designed to improve effectiveness and/or counter emerging risks.
Maintain threat, attack and risk models and perform regular analysis to ensure Mynt is adequately mitigating risks.
Make appropriate recommendations for security enhancements to the CISO including tools, technologies, services, policies, procedures, and other areas as needed.
Lead efforts to evaluate and select vendors for security assessments, penetration testing, and other similar security services.
Manage budgets, maintain financial forecasts, develop and present business cases.
Establish objectives and milestones and manage activities to deliver high quality results within budget and schedule.
Hire and retain adequate staff, team expertise and other resources (e.g., advisors and counsel) as needed to fulfill obligations.
Other duties and obligations as assigned by the CISO
Key Job Functions
Cybersecurity Operations
Manage and oversee the Security Operations Center and managed service provider to perform daily detection and reporting activities
Participate in the Information Security Risk Oversight Committee
Oversee all processes and projects managed by the Security Operations Center Team
Develop annual Cybersecurity operations strategy to detect and counter threats and attacks
Incident Management
Manage the company process for all Cybersecurity incidents impacting the company
Perform responsibilities of the company Incident Response Commander to ensure appropriate response, containment, and recovery from Cybersecurity incidents.
Ensure appropriate planning, training, and tabletop exercises and in place to respond effectively to threats and incidents
Vulnerability Management & Penetration Testing
Lead efforts to evaluate and select vendors for security assessments, penetration testing, and other similar security services
Manage the enterprise process for identification and remediation of technical vulnerabilities
Ensure effective tools, technologies and processes are in place to identify and report vulnerabilities for remediation
Coordinate and report on vulnerability remediation
Operational Planning & Management
Support all activities performed by the Cybersecurity team associated with the deployment and maintenance of all Cybersecurity detection systems such as the Security Incident Event Management system, threat intelligence system, and other detection and automation tools
Provide annual budget planning and participate in the development of the annual strategy
Develop and implement Cybersecurity training programs for team members according to their role and responsibilities
Manage projects with the IT and product development teams and for projects internal to Cybersecurity
Assist with general administrative activities in collaboration with all team members
Manage vendors activities and relationships as needed including SOWs, maintenance renewals, licensing updates, etc.
Prepare project plans and associated documentation
Prepare status reports and other management metrics as needed
Documentation, Reporting & Analytics
Manage the design and implementation of an operational reporting framework that will provide regular metrics and statistics about Cybersecurity operations; analyze trends in security events, activities, etc. to better understand risks, insufficiencies in our solutions, staffing and processes; report security metrics and statistics to the CISO and other key stakeholders such as the Information Security Risk Oversight Committee
Manage all SOC requirements with regards to Cybersecurity metrics and ensure that metrics are gathered daily
Manage all Cybersecurity metrics for the CISO dashboard and other reporting requirements
Manage the vulnerability threat assessment report and ensure all stakeholders are effectively informed of the status of system vulnerabilities
EDUCATION And/or EXPERIENCE
Bachelor's degree or equivalent business experience in Computer Science, Business Management, or MIS required
Certified training in security management, risk and compliance solutions and practices. CISSP, C-CISO, CISA, CISM, GSEC, CRISC, or related certification(s) required
Qualifications
10+ years of broad technology experience in application development and infrastructure services with a strong record of success in managing information security. Specific focus on resiliency / continuity planning, auditing and risk management preferred.
Deep working knowledge of industry best practices (NIST, ISO, SANS, COBIT, CERT) and Legislative and Regulatory and Industry Compliance Requirements (SOX, PCI, HIPPA, etc.).
Must have experience managing complex information technology programs, preferably within the financial services or information security industries.
Experience managing vendor sourced solutions and consultants, ensuring vendor performance and deliverables meet specifications.
Intelligent, articulate and persuasive leader with excellent interpersonal, verbal, written communication and presentation skills.
Must possess the ability to communicate security-related concepts, the state of security and risks, as well as cost effective program design and mechanics to a broad range of stakeholders including: a Board of Directors, senior business executives, technical and non-technical associates, customers, business partners, vendors, etc.
Accomplished and effective change leader with prior people management responsibility. Candidates should have demonstrable evidence of their ability to implement and drive adoption of risk management programs.
Must direct members across the organization, ensuring alignment of resources across functions and matrix. Creative, innovative and thorough approach with the ability to operate autonomously.
Others:
Senior Manager
Working Budget: 170-200K
With People mgt experience
Head of Security Operations
Reporting to Mynt's Chief Information Security Officer (CISO), the Head of Security Operations is responsible for the day-to-day Cybersecurity operations detecting and responding to Cybersecurity threats, events, and incidents. The role supports the overall Cybersecurity program and provides leadership to develop, support, and advance strategies, programs, and projects designed to continually improve and enhance Mynt's cyber and information security posture and resiliency.
In This Role, The Successful Candidate Will
Establish and implement security tools, technologies, processes, and procedures appropriate to the detection of threats and attacks against company infrastructure and information. Furthermore, this position also directs the company response to attacks and incidents including the containment and eradication strategy to ensure minimal impact to business operations.
Regularly review operation of security controls and recommend changes designed to improve effectiveness and/or counter emerging risks.
Maintain threat, attack and risk models and perform regular analysis to ensure Mynt is adequately mitigating risks.
Make appropriate recommendations for security enhancements to the CISO including tools, technologies, services, policies, procedures, and other areas as needed.
Lead efforts to evaluate and select vendors for security assessments, penetration testing, and other similar security services.
Manage budgets, maintain financial forecasts, develop and present business cases.
Establish objectives and milestones and manage activities to deliver high quality results within budget and schedule.
Hire and retain adequate staff, team expertise and other resources (e.g., advisors and counsel) as needed to fulfill obligations.
Other duties and obligations as assigned by the CISO
Key Job Functions
Cybersecurity Operations
Manage and oversee the Security Operations Center and managed service provider to perform daily detection and reporting activities
Participate in the Information Security Risk Oversight Committee
Oversee all processes and projects managed by the Security Operations Center Team
Develop annual Cybersecurity operations strategy to detect and counter threats and attacks
Incident Management
Manage the company process for all Cybersecurity incidents impacting the company
Perform responsibilities of the company Incident Response Commander to ensure appropriate response, containment, and recovery from Cybersecurity incidents.
Ensure appropriate planning, training, and tabletop exercises and in place to respond effectively to threats and incidents
Vulnerability Management & Penetration Testing
Lead efforts to evaluate and select vendors for security assessments, penetration testing, and other similar security services
Manage the enterprise process for identification and remediation of technical vulnerabilities
Ensure effective tools, technologies and processes are in place to identify and report vulnerabilities for remediation
Coordinate and report on vulnerability remediation
Operational Planning & Management
Support all activities performed by the Cybersecurity team associated with the deployment and maintenance of all Cybersecurity detection systems such as the Security Incident Event Management system, threat intelligence system, and other detection and automation tools
Provide annual budget planning and participate in the development of the annual strategy
Develop and implement Cybersecurity training programs for team members according to their role and responsibilities
Manage projects with the IT and product development teams and for projects internal to Cybersecurity
Assist with general administrative activities in collaboration with all team members
Manage vendors activities and relationships as needed including SOWs, maintenance renewals, licensing updates, etc.
Prepare project plans and associated documentation
Prepare status reports and other management metrics as needed
Documentation, Reporting & Analytics
Manage the design and implementation of an operational reporting framework that will provide regular metrics and statistics about Cybersecurity operations; analyze trends in security events, activities, etc. to better understand risks, insufficiencies in our solutions, staffing and processes; report security metrics and statistics to the CISO and other key stakeholders such as the Information Security Risk Oversight Committee
Manage all SOC requirements with regards to Cybersecurity metrics and ensure that metrics are gathered daily
Manage all Cybersecurity metrics for the CISO dashboard and other reporting requirements
Manage the vulnerability threat assessment report and ensure all stakeholders are effectively informed of the status of system vulnerabilities
EDUCATION And/or EXPERIENCE
Bachelor's degree or equivalent business experience in Computer Science, Business Management, or MIS required
Certified training in security management, risk and compliance solutions and practices. CISSP, C-CISO, CISA, CISM, GSEC, CRISC, or related certification(s) required
Qualifications
10+ years of broad technology experience in application development and infrastructure services with a strong record of success in managing information security. Specific focus on resiliency / continuity planning, auditing and risk management preferred.
Deep working knowledge of industry best practices (NIST, ISO, SANS, COBIT, CERT) and Legislative and Regulatory and Industry Compliance Requirements (SOX, PCI, HIPPA, etc.).
Must have experience managing complex information technology programs, preferably within the financial services or information security industries.
Experience managing vendor sourced solutions and consultants, ensuring vendor performance and deliverables meet specifications.
Intelligent, articulate and persuasive leader with excellent interpersonal, verbal, written communication and presentation skills.
Must possess the ability to communicate security-related concepts, the state of security and risks, as well as cost effective program design and mechanics to a broad range of stakeholders including: a Board of Directors, senior business executives, technical and non-technical associates, customers, business partners, vendors, etc.
Accomplished and effective change leader with prior people management responsibility. Candidates should have demonstrable evidence of their ability to implement and drive adoption of risk management programs.
Must direct members across the organization, ensuring alignment of resources across functions and matrix. Creative, innovative and thorough approach with the ability to operate autonomously.
Others:
Senior Manager
Working Budget: 170-200K
With People mgt experience
Other Info
Head of Security Operations
eTeam Workforce Pte Ltd
Philippines
10-13 years
Not Specified
eTeam Workforce Pte Ltd
Philippines
10-13 years
Not Specified
Submit profile
eTeam Workforce Pte Ltd
About the company
eTeam Workforce Pte Ltd jobs
Philippines
Position Head of Security operations recruited by the company eTeam Workforce Pte Ltd at , Joboko automatically collects the salary of Not Specified, finds more jobs on Head of Security Operations or eTeam Workforce Pte Ltd company in the links above
About the company
eTeam Workforce Pte Ltd jobs
Philippines