US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Security Lead

What You'll Do

The Security Lead is responsible for shaping and operating the organization's information security program.

This is a hands-on leadership role that combines security strategy, governance, risk management, compliance, incident response, and day-to-day execution with a team of security professionals.

The role partners closely with, Infrastructure, DevOps, Risk, Legal, leadership, and external security partners to reduce cyber risk while enabling the business.

Responsibilities

Security Strategy & Governance 


* Develop and maintain a practical information security roadmap aligned with business priorities, client expectations, and organizational risk tolerance. 


* Create, maintain, and operationalize security policies, standards, procedures, and control documentation. 


* Use recognized frameworks such as NIST Cybersecurity Framework, CIS Controls, ISO 27001 concepts, and SOC 2 control expectations where appropriate. 


* Define security program metrics, risk indicators, and reporting materials for executive leadership. 

Risk Management & Compliance 


* Lead recurring cybersecurity risk assessments and maintain a prioritized risk register with remediation plans. 


* Support client security questionnaires, vendor due diligence, cyber insurance requests, and audit evidence collection. 


* Partner with business and technology owners to evaluate risk for new systems, vendors, integrations, and technology changes. 


* Coordinate remediation of audit findings, assessment results, and control gaps. 

Security Operations & Incident Response 


* Oversee day-to-day security operations, including monitoring, alert review, vulnerability management, endpoint protection, identity controls, and threat response. 


* Own and maintain the incident response plan, escalation process, communication templates, and post-incident review process. 


* Coordinate with internal teams and third-party providers such as MSSP, SOC, penetration testing firms, cyber insurance contacts, and outside counsel when needed. 


* Lead or support tabletop exercises, phishing response, vulnerability remediation, and security improvement initiatives. 

Architecture, Cloud & DevSecOps Enablement 


* Partner with Infrastructure, DevOps, application, and business technology teams to embed security into architecture, implementation, and change management. 


* Advise on secure configuration for Microsoft 365, Azure, identity and access management, network security, endpoint security, cloud workloads, and SaaS platforms. 


* Promote secure development, secure deployment, secrets management, least privilege access, logging, and configuration baselines. 


* Evaluate security tools and processes for fit, cost, redundancy, and measurable risk reduction. 

Leadership, Communication & Security Culture 


* Translate technical security risks into business language for senior leadership ...




Share Job