Title:IT Cybersecurity Project Lead
IT Cyber Security Project Lead
Position Information
Job Title: IT Cyber Security Head
Department: Information Technology / Cybersecurity
Reports To: IT Cyber Security Head
Location: [Location]
Employment Type: Full-Time
Position Purpose
The Cybersecurity Operations Engineer is responsible for the implementation, operation, monitoring, and continuous improvement of cybersecurity controls across the organization's Information Technology (IT) and Operational Technology (OT) environments.
The role focuses on security monitoring, incident response, vulnerability management, endpoint security, identity security, and security tooling administration. The position plays a key role in protecting organizational assets from cyber threats while supporting compliance with cybersecurity policies, standards, and regulatory requirements.
The Cybersecurity Operations Engineer works closely with IT infrastructure, cloud, network, application, and OT teams to ensure security controls are implemented and operating effectively.
Key Responsibilities
Security Operations
Monitor security events and alerts generated by security monitoring platforms.
Investigate suspicious activities and security incidents.
Perform incident triage, containment, eradication, and recovery activities.
Support cyber incident response and forensic investigations.
Participate in on-call cyber incident response activities where required.
Maintain incident records and lessons learned documentation.
Security Monitoring & SIEM
Administer and maintain SIEM platforms.
Develop and tune detection rules and alert thresholds.
Monitor log sources and ensure adequate security event coverage.
Investigate security alerts and escalate critical findings.
Develop use cases and threat detection analytics.
Endpoint and Server Security
Manage Endpoint Detection and Response (EDR/XDR) solutions.
Support endpoint protection platforms such as Microsoft Defender, CrowdStrike, Trend Micro, or equivalent.
Monitor and investigate endpoint threats.
Ensure security agents remain operational and compliant.
Support server hardening and security baseline implementation.
Vulnerability Management
Perform vulnerability scanning activities.
Analyse vulnerability assessment reports.
Prioritize remediation actions based on risk.
Coordinate remediation efforts with infrastructure and application teams.
Monitor closure of identified vulnerabilities.
Produce vulnerability metrics and reporting.
Identity and Access Management
Support privileged access management solutions.
Monitor privileged account usage.
Assist with periodic access reviews.
Support identity governance activities.
Ensure compliance with least-privilege principles.
Security Tool Administration
Administer cybersecurity technologies including:
SIEM
EDR/XDR
PAM
Vulnerability Management Platforms
Email Security Solutions
Web Security Gateways
Security Monitoring Platforms
Threat Intelligence Platforms
Maintain health and performance of cybersecurity systems.
Support technology upgrades and deployment activities.
Threat Management
Monitor emerging cyber threats and vulnerabilities.
Review threat intelligence feeds.
Assess threats for organisational relevance.
Recommend protective measures and compensating controls.
Support threat hunting activities.
OT/Industrial Cybersecurity Support
Assist with cybersecurity monitoring of OT environments.
Support IEC 62443-aligned control implementation.
Monitor OT security events and vulnerabilities.
Participate in OT risk assessments.
Support secure network segmentation initiatives.
Security Compliance
Assist in design and implementation of cybersecurity policies and standards.
Support cybersecurity audits and assessments.
Maintain operational evidence for compliance activities.
Support implementation of NIST, ISO 27001, and IEC 62443 requirements.
Reporting
Prepare operational cybersecurity reports.
Produce incident and vulnerability metrics.
Maintain dashboards and KPI reporting.
Provide regular status updates to the Head of Cybersecurity.
Key Deliverables
Security Incident Reports
Vulnerability Assessment Reports
SIEM Monitoring Dashboards
Threat Intelligence Briefings
Security Control Compliance Reports
Security Monitoring Use Cases
Security Technology Health Reports
Privileged Access Monitoring Reports
Cybersecurity KPIs and Metrics
Required Qualifications
Essential
Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
Minimum 3-5 years of cybersecurity operations experience.
Experience supporting enterprise security technologies.
Experience investigating cybersecurity incidents.
Experience with security monitoring and vulnerability management.
Preferred Certifications
One or more of:
CompTIA Security+
CompTIA CySA+
Microsoft Security Certifications
SC-200 Security Operations Analyst
CISSP Associate
GIAC Certifications
GSEC
SSCP
CEH
Technical Skills
Security Operations
Incident Response
Threat Detection
Threat Hunting
Security Monitoring
Digital Forensics Fundamentals
Security Platforms
Microsoft Sentinel
Microsoft Defender XDR
CrowdStrike
Trend Micro
Tenable
Qualys
Rapid7
Splunk
QRadar
Infrastructure Security
Windows Server
Active Directory
Entra ID (Azure AD)
Linux Administration
Network Security
Firewalls
VPN Technologies
Cloud Security
Microsoft Azure
Microsoft 365 Security
AWS Security Fundamentals
OT Security (Preferred)
Industrial Control Systems (ICS)
SCADA Security
IEC 62443
OT Network Security
Knowledge Requirements
NIST Cybersecurity Framework (CSF)
NIST SP 800-53
IEC 62443
ISO 27001
CIS Critical Security Controls
Cyber Kill Chain
MITRE ATT&CK Framework
Vulnerability Management Processes
Security Incident Lifecycle Management
Key Competencies
Analytical Thinking
Problem Solving
Technical Troubleshooting
Incident Management
Attention to Detail
Teamwork and Collaboration
Communication Skills
Risk Awareness
Continuous Learning
Customer Service Orientation
R2129879