Director of IT Security Operations (Americas and EMIA)
Midrand, South Africa
WSP Africa
WSP ist eines der weltweit führenden Planungs- und Beratungsunternehmen für das Bauwesen, mit rd. 54.000 talentierten Mitarbeiterinnen und Mitarbeitern in mehreren Büros in der ganzen Welt.Company Description
We are WSP - Join us and make your career future ready!
Think bigger scale. Think higher profile. Think ground-breaking. Join WSP, and you’ll be at the heart of a team of international experts all dedicated to growing and sharing their expertise, and working on projects that transform society for all of us.
WSP is one of the most diverse consulting firms in Africa, and the largest environmental consulting firm globally. To further our strategic business execution plan, we are seeking leaders who share our guiding principles – we value our people and our reputation; we are locally dedicated with international scale; we are future-focused and challenge the status quo; we foster collaboration; we have an empowering culture and hold ourselves accountable.
Job Description
WSP’s Security Engineering and Operations Team is responsible for managing the global organization’s security technologies and systems.
The role of Director Security Operations reports directly to the Global Vice President Security Engineering and Operations and is responsible for leading our Security Operations Centre and working with the Manager of Incident Response and Manager of SOC Tools and Operations. This is primarily an internally facing role, although some interaction with clients and third parties may be required.
Specific areas of responsibility may fall into any one of the following areas of Security Operations, as assigned by the staff’s management.
Security Analysis
Threat and Vulnerability Management
Network, Database, Server and Endpoint, and Application Security
Penetration Testing
Antivirus and Antimalware analysis
Event Analysis
Incident Response
Ethical Hacking
Management
Privileged access management
The Director of Security Operations will have multiple security-related roles within the organization. Their main goal will be to provide a secure computing environment for the organization to conduct their business. The global security operations team will have overlapping duties however each role will have more specifically focused duties. As such, the role and essential duties will fit into the below classifications most closely.
The director will be responsible for the overall direction and planning for both the incident response and tools team, liaising with our contracted partner for Level 1 and 2 Security Operations, 24/7 incident response, Security tool management, etc.
Incident Management Process and Forensics – assist in providing forensic capabilities for the incident management process when needed. Monitor and manage infrastructure logging for security, including perimeter network devices, malware prevention, and intrusion prevention.
Definition and implementation of controls - Defines security configuration and operations standards for security systems and applications, including policy assessment and compliance tools, network security appliances, and host-based security systems. Develops and validates baseline security configurations for operating systems, applications, and networking and telecommunications equipment.
Endpoint Protection Strategy – Formulate the companies’ Endpoint protection strategy, including but not exclusive to malware, host intrusion, encryption, browser protection and hardware level security controls.
Network infrastructure security – responsible for determining and maintaining the technical standards for configurations of routers, switches, firewalls, IPS and IDS devices.
Privileged access management – responsible for maintaining our PAM toolset, ensuring least based privilege across the organization, including secret management and elevated account management.
Leadership and People Responsibilities:
Director of two separate managers within the security organization, 2nd level management of Incident response and tools teams.
Displays leadership and independence in performing their role, with an ability to make complex decisions with limited input and review from senior staff.
High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
Assist in the hiring, training, and coaching of new and existing staff, and provide coaching to staff executing all aspects of information security and risk assessment and support.
Develop positive working relationships with other team members and business partners and partner across teams to align with WSP internal and external client demands.
Capable of rapidly assimilating and internalizing new complex business, technology, and risk management concepts and dependencies.
Capable of clearly defining, presenting and selling recommended strategies to senior management teams in a business or technical context as appropriate.
Critical thinker with strong problem-solving skills, project management skills; financial/budget management, scheduling and resource management.
Able to interpret and apply laws, regulations, policies and guidance relevant to the organization information security objectives.
Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate between specialized groups of business unit and IT professionals.
Accommodation of schedule for international conference calls, limited travel within the regions you are responsible for.
Ability to work with people from different backgrounds and cultures across the region and the world.
Provide review feedback for analyst and other direct reports.
Capacity Management within the SOC teams, including growth expectations, M&A onboarding etc.
Finance/Budgetary Responsibilities:
Support the Global Vice President Security Engineering and Operations in developing the budget projections based on short-and long-term goals and objectives.
Qualifications
Related experience in information security, risk, compliance, or similar position
Bachelor's degree or equivalent in Information Technology, Computer Science, Engineering or related field
Certification in Information Security (CISSP, ISC, or CISM) practices and policies
Knowledge of security technologies (encryption, data protection, network intrusion prevention, EDR, firewalls, privilege access, etc.)
Knowledge of enterprise IT security concerns and technologies, including but not limited to VPNs, network security, encryption, authentication, application-level network protocols, PKI, IPSec, Firewall, SSH, SSL, , LAN/WAN, and TCP/IP
Knowledge of security best practices with relation to applications, network and client setups
Experience with IT Governance frameworks such as COBIT, ITIL and ISO 2700x, NIST
Experience with governance, compliance, and audit within IT environments
Experience of risk management, including risk analysis, mitigation, and monitoring
Knowledge of information security regulations applicable to WSP
Preferred:
Master’s degree in information technology, Computer Science, Engineering or related field
Knowledge of KQL, Python and PowerShell is a plus.
Additional Information
What's in it for you?
What if we can have work-life balance? What if we can be rewarded in ways that support our individual needs? What if we can be accepted for who we are? Here at WSP – we can!
WSP recognizes that work is only one part of our lives and making time for the other things in our life is important – be that our families, our friends or ourselves. So, if working from home, working part-time or having flexible start and finish time will help with this let us know as part of your application.
As well as rewarding you with competitive pay, WSP offers standard benefits including first class medical cover, generous days annual leave, and paid professional subscriptions.
Be you, be happy - we strive to have a friendly and inclusive culture which respects and maximizes the contribution individuals can bring to WSP. We recognize the benefits that people with varying backgrounds and experiences can bring. Here at WSP we positively encourage applications from suitably qualified and eligible candidates regardless of sex, race, disability, age, religion or belief, marital status, pregnancy or maternity/paternity. We will interview all disabled applicants who meet the essential criteria.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Antivirus Application security CISM CISSP COBIT Compliance Computer Science EDR Encryption Ethical hacking Finance Firewalls Forensics Governance IDS Incident response Intrusion prevention IPS ITIL Malware Monitoring Network security NIST Pentesting PKI PowerShell Python Risk analysis Risk assessment Risk management Security analysis SOC SSH Strategy TCP/IP VPN Vulnerability management
Perks/benefits: Career development Competitive pay Flex hours Medical leave Parental leave Startup environment Travel
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.