Director of IT Security Operations

2 weeks ago


Midrand, Gauteng, South Africa WSP Africa Full time
Job Description

WSP's Security Engineering and Operations Team is responsible for managing the global organization's security technologies and systems.

The role of Director Security Operations reports directly to the Global Vice President Security Engineering and Operations and is responsible for leading our Security Operations Centre and working with the Manager of Incident Response and Manager of SOC Tools and Operations. This is primarily an internally facing role, although some interaction with clients and third parties may be required.

Specific areas of responsibility may fall into any one of the following areas of Security Operations, as assigned by the staff's management.

  • Security Analysis
  • Threat and Vulnerability Management
  • Network, Database, Server and Endpoint, and Application Security
  • Penetration Testing
  • Antivirus and Antimalware analysis
  • Event Analysis
  • Incident Response
  • Ethical Hacking
  • Management
  • Privileged access management

The Director of Security Operations will have multiple security-related roles within the organization. Their main goal will be to provide a secure computing environment for the organization to conduct their business. The global security operations team will have overlapping duties however each role will have more specifically focused duties. As such, the role and essential duties will fit into the below classifications most closely.

The director will be responsible for the overall direction and planning for both the incident response and tools team, liaising with our contracted partner for Level 1 and 2 Security Operations, 24/7 incident response, Security tool management, etc.

Incident Management Process and Forensics – assist in providing forensic capabilities for the incident management process when needed. Monitor and manage infrastructure logging for security, including perimeter network devices, malware prevention, and intrusion prevention.

Definition and implementation of controls - Defines security configuration and operations standards for security systems and applications, including policy assessment and compliance tools, network security appliances, and host-based security systems. Develops and validates baseline security configurations for operating systems, applications, and networking and telecommunications equipment.

Endpoint Protection Strategy – Formulate the companies' Endpoint protection strategy, including but not exclusive to malware, host intrusion, encryption, browser protection and hardware level security controls.

Network infrastructure security – responsible for determining and maintaining the technical standards for configurations of routers, switches, firewalls, IPS and IDS devices.

Privileged access management – responsible for maintaining our PAM toolset, ensuring least based privilege across the organization, including secret management and elevated account management.

Leadership and People Responsibilities:

  • Director of two separate managers within the security organization, 2nd level management of Incident response and tools teams.
  • Displays leadership and independence in performing their role, with an ability to make complex decisions with limited input and review from senior staff.
  • High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
  • Assist in the hiring, training, and coaching of new and existing staff, and provide coaching to staff executing all aspects of information security and risk assessment and support.
  • Develop positive working relationships with other team members and business partners and partner across teams to align with WSP internal and external client demands.
  • Capable of rapidly assimilating and internalizing new complex business, technology, and risk management concepts and dependencies.
  • Capable of clearly defining, presenting and selling recommended strategies to senior management teams in a business or technical context as appropriate.
  • Critical thinker with strong problem-solving skills, project management skills; financial/budget management, scheduling and resource management.
  • Able to interpret and apply laws, regulations, policies and guidance relevant to the organization information security objectives.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate between specialized groups of business unit and IT professionals.
  • Accommodation of schedule for international conference calls, limited travel within the regions you are responsible for.
  • Ability to work with people from different backgrounds and cultures across the region and the world.
  • Provide review feedback for analyst and other direct reports.
  • Capacity Management within the SOC teams, including growth expectations, M&A onboarding etc.

Finance/Budgetary Responsibilities:

  • Support the Global Vice President Security Engineering and Operations in developing the budget projections based on short-and long-term goals and objectives.
Qualifications
  • Related experience in information security, risk, compliance, or similar position
  • Bachelor's degree or equivalent in Information Technology, Computer Science, Engineering or related field
  • Certification in Information Security (CISSP, ISC, or CISM) practices and policies
  • Knowledge of security technologies (encryption, data protection, network intrusion prevention, EDR, firewalls, privilege access, etc.)
  • Knowledge of enterprise IT security concerns and technologies, including but not limited to VPNs, network security, encryption, authentication, application-level network protocols, PKI, IPSec, Firewall, SSH, SSL, , LAN/WAN, and TCP/IP
  • Knowledge of security best practices with relation to applications, network and client setups
  • Experience with IT Governance frameworks such as COBIT, ITIL and ISO 2700x, NIST
  • Experience with governance, compliance, and audit within IT environments
  • Experience of risk management, including risk analysis, mitigation, and monitoring
  • Knowledge of information security regulations applicable to WSP

Preferred:

  • Master's degree in information technology, Computer Science, Engineering or related field
  • Knowledge of KQL, Python and PowerShell is a plus.
Additional Information

What's in it for you?

What if we can have work-life balance? What if we can be rewarded in ways that support our individual needs? What if we can be accepted for who we are? Here at WSP – we can

WSP recognizes that work is only one part of our lives and making time for the other things in our life is important – be that our families, our friends or ourselves. So, if working from home, working part-time or having flexible start and finish time will help with this let us know as part of your application.

As well as rewarding you with competitive pay, WSP offers standard benefits including first class medical cover, generous days annual leave, and paid professional subscriptions.

Be you, be happy - we strive to have a friendly and inclusive culture which respects and maximizes the contribution individuals can bring to WSP. We recognize the benefits that people with varying backgrounds and experiences can bring. Here at WSP we positively encourage applications from suitably qualified and eligible candidates regardless of sex, race, disability, age, religion or belief, marital status, pregnancy or maternity/paternity. We will interview all disabled applicants who meet the essential criteria.



  • Midrand, Gauteng, South Africa WSP Africa Full time

    Company DescriptionWe are WSP - Join us and make your career future readyThink bigger scale. Think higher profile. Think ground-breaking. Join WSP, and you'll be at the heart of a team of international experts all dedicated to growing and sharing their expertise, and working on projects that transform society for all of us.WSP is one of the most diverse...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSETheSenior Security Operations Lead is responsible for customers' SLA management and service delivery by all Security Delivery Teams across all Nexio customers. The Senior Security Operations Lead plans, coordinates, and directs all daily operational activities of the Security Services Teams show in the organogram.The Senior Security Operations...


  • Midrand, Gauteng, South Africa Sabenza IT Full time

    PostgreSQL Operations Specialist DBA (SQL), Database Administrator - ITMenlyn - Gauteng - South Africa, Midrand - Gauteng - South AfricaGet your career into gear Our clients in the Automotive space are looking for a PostgreSQL Operations Specialist to fuel their team Drift your way across the world and experience a great Hybrid position that comes with the...


  • Midrand, Gauteng, South Africa MSD Full time

    Reporting to the Associate Director, Regional Security Middle East Africa (MEA), the Regional Security Senior Specialist will be responsible for supporting Global Security Group (GSG) Operations in Sub-Sahara Africa (French West Africa, English & Portuguese Africa, South Africa). He/She will be responsible for providing primary security support for all...


  • Midrand, Gauteng, South Africa Liquid Tech (Pty) Ltd. Full time

    Role PurposeTo deliver day-to-day managed security services (MSS), related to SOC deliverables. Critical in this regard is to execute according to Standard Operating Procedure (SOP) expectations and meeting all related service level agreements (SLAs).It is further expected that these services will be enhanced and matured so that customer value can be...


  • Midrand, Gauteng, South Africa Code Red Recruitment Full time

    Our Client, An Internet Service Provider that offers Connectivity, Cloud, Voice & Security products is looking to hire an exceptional leader in the capacity of Sales Director to join their executive team.The Sales Director will be responsible to lead and manage the sales team, whilst driving the customer engagement model for existing customers and partners....


  • Midrand, Gauteng, South Africa Jordan HR Full time

    ESSENTIAL SKILLS REQUIREMENTS: Experience in operation of Linux and/or Windows Systems Experience in Windows Client OS, GPO and device control Experience with security standards and their implementation Experience with Security solutions (OnPrem/Cloud) Experience with Endpoint Detection and Response solutions (OnPrem/Cloud) Experience with Advance Threat...

  • Finance Director

    2 weeks ago


    Midrand, Gauteng, South Africa Servest Careers Full time

    Job Context:SERVEST SECURITY, A DIVISION OF SERVEST HAS A VACANCY FOR A FINANCE DIRECTOR BASED AT WATERFAL HEAD OFFICE.Responsibility for their company's financial health. To combine operational and strategic roles, manage accounting and financial control functions, and establish a financial strategy for the profitable long-term growth of the...


  • Midrand, Gauteng, South Africa 27M Growth Group Full time

    PA Administrator to Director | Urgent Position Available Dikwena Tsa Molao Security Services seeks a PA Administrator to join their team. Ideally from the Security Guarding industry.This position is office based, in Midrand. Must have transportation.Duties: Carry out administrative tasks and projects as required and timeously Typing of documents Responding...


  • Midrand, Gauteng, South Africa Talent Scout Full time

    Our OEM client is seeking an After Sales Director (As an Executive Committee member), to oversee all post-sales operations and services. This crucial role requires a seasoned professional with extensive experience in managing after-sales services, including technical, warranty services, supply chain and parts management.If you have proven experience in an...

  • Project Director

    2 weeks ago


    Midrand, Gauteng, South Africa International SOS Full time

    ..... URGENT.... International SOS - Project Director - Saudi Arabia As International SOS' footprint in Saudi Arabia continues to grow, so does the need for further resourcing. This includes well established Project Directors with the skill set identified below. Start Date: ASAP (NB: visa processing may take up to 4-6 weeks) Country: Saudi...

  • Security Architect

    2 weeks ago


    Midrand, Gauteng, South Africa XET SOLUTIONS Full time

    Job Description:We are in search of an individual who will be in charge of developing database solutions, installing and configuring information systems, analyzing structural requirements for innovative software, migrating data from outdated systems, and designing conceptual and logical data models.About the Company: We are a leading company in the tech...

  • Security Specialist

    2 weeks ago


    Midrand, Gauteng, South Africa Jurumani Solutions Full time

    Jurumani offers an environment where creativity and the practice of building things is believed to be fundamentally useful to both the Client and Jurumani Solutions. Providing opportunity to focus on making products and business operating capabilities work, which means we often are more concerned with how systems align, orchestrate and integrate to achieve...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Manager - Cybersecurity Prevent will coordinate the team, tools, processes and operations of the Cyber Security Prevent Team responsible for managing, optimizing and deploying Cybersecurity solutions and capabilities to safeguard the information assets and reduce the Cybersecurity risk for M-Pesa Africa and its customers. The role holder...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Cyber Defence is one of MPA's critical Cyber Security teams. The Cyber Defence team's mission is to deliver a highly effective end to end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events; and managing cyber security incident responses to minimise...

  • Area Security Manager

    2 weeks ago


    Midrand, Gauteng, South Africa Enshrine Placements Full time

    Area Security Manager - Midrand, Gauteng - Job-3692Area Security Manager needed to develop and roll out the best security practices for the security discipline at North Stations.Position details:Type: PermanentReports to: Security Business Unit ManagerReporting, total staff compliment:Job titles of direct reports: Assistant Station Head Security, Security...


  • Midrand, Gauteng, South Africa Adcorp Holdings Full time

    SynopsisOur Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa.HybridMidrand basedon the hunt for an experienced and highly skilled Cyber Security Senior...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.Your responsibilities will include:Provide technology security assurance, guidance and support...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role you will:Identify potential cyber security risks for new products,...