Role Description
The Cybersecurity Operations Manager is charged with the management of all globally aligned security focused defense services within a specific operational site This includes the overall efficiency and effectiveness of the site the detection management and response to global information and cybersecurity incidents during active hours of operation and the complete handover of duties from the previous site and to the next as part of a 247 global capability
The Cybersecurity Operations Manager is accountable for
- Leading a team of 4050 highly skilled security professionals providing a global service to detect and respond to cyber security threats
- Working seamlessly with their global peers to provide 24 x 7 x 365 coverage for the critical global Cybersecurity Operations services
- Developing managing and maintaining a highly skilled efficient and effective local team across all Cybersecurity Operations service lines Including the definition management and continuous improvement of core functions and processes that underpin a successful effective and globally scaled monitoring ing and security incident response capability
- Owning and managing collaboration with the wider Cybersecurity and CTO teams to ensure that the core underlying technological capabilities that underpin an effective and efficient operational response to current and anticipated threats and trends remain fit for purpose
- Identification of processes that can be automated and orchestrated to ensure maximum efficiency of global Cybersecurity Operations resources
- Ensuring analysis time is efficiently focused on the more challenging and potentially higher risk problems and tasks not on highvolumelow risk repetitive tasks or processes thus helping to effectively reduce false positive and false negative events
- Managing and owning the collaboration with the wider Cybersecurity teams and wider business function teams where applicable in the production and maintenance of efficient and effective security event monitoring and ing usecases and incident response playbooks
- Maintaining a global view of the GCOI mission and work with local stakeholders in region and country to bring together both the global perspective as well as the more local message in a clear and effective way that demonstrates
Technical Skills
- Expert level knowledge and demonstrated experience of common intelligence sharing platforms protocols and experience operating within a collective defence environment with internal stakeholders and external partners
- Expert level knowledge of common enterprise technology infrastructure platforms and tooling including Windows Linux infrastructure management and networking hardware
- Expert level knowledge of intelligence analysis principles either though formal education training or equivalent professional experience
- Expert level knowledge and demonstrated experience in analysis and dissection of advanced attacker tactics techniques and procedures in order to inform adjustments to the control plane
- Expert level knowledge of scripting programming andor development of bespoke tooling or solutions to solve unique problems
- Ability to identify develop and track key performance indicator KPI metrics for accurate and contextual evaluation of operational effectiveness as well as providing recommendations for control improvement and mitigating control adjustments
- Expert knowledge and technical experience of 3rd party cloud computing platforms such as AWS Azure and Google
- Industry Experience and Qualifications
- Industry recognised cyber security related certifications including CEH EnCE SANS CISSP CISM CRISC andor CISA
- Formal education and advanced degree in Information Security Cyber security Computer Science or similar andor commensurate demonstrated work experience in the same
- A broad and extensive security operations background
- Operated at a senior management level with exposure to global executives
- Experience in a senior leadership position within a large global and highly regulated organisation including handson experience of complex data centre environments managing large highly technical teams in operational environments preferably with shift management experience
- 10 years of experience in Cyber security operations management Cyber security management in a leadership position
Skills
Mandatory Skills : Automation, Major incident management, Stakeholder Management