About this IT Cyber Security Head-Onsite (IF) role at KBR
Title:
IT Cyber Security Head-Onsite (IF)IT Cyber Security Head
Position Information
Job Title: IT Cyber Security Head
Department: Information Technology / Cybersecurity
Reports To: Cybersecurity Manager
Direct Reports: Location: [Location]
Employment Type: Full-Time
Position Purpose
The Head of Cybersecurity is responsible for leading the day-to-day cybersecurity function, managing cybersecurity operations, and overseeing the implementation of security controls across the organisation's Information Technology (IT) and Operational Technology (OT) environments. The role provides technical leadership to a small cybersecurity team and ensures cybersecurity risks are effectively identified, assessed, monitored, and mitigated.
Working under the direction of the Cybersecurity Manager, the Head of Cybersecurity is accountable for the execution of the cybersecurity strategy, governance requirements, security operations, compliance activities, and cybersecurity improvement initiatives.
Key Responsibilities
Cybersecurity Leadership
- Lead and manage the cybersecurity team, providing technical guidance, mentoring, and performance management.
- Coordinate cybersecurity activities across IT, OT, Digital, and business functions.
- Act as the primary escalation point for cybersecurity operational issues.
- Develop team capabilities, skills, and professional development plans.
- Foster a strong cybersecurity culture throughout the organization.
Security Operations
- Oversee Security Operations Centre (SOC) activities, whether internally delivered or outsourced.
- Monitor security alerts, incidents, vulnerabilities, and threats.
- Ensure effective incident detection, triage, investigation, containment, and recovery.
- Lead cyber incident response activities and coordinate post-incident reviews.
- Ensure cybersecurity monitoring and logging capabilities are maintained and optimized.
Governance, Risk and Compliance
- Support the implementation and maintenance of the cybersecurity governance framework.
- Manage cybersecurity risk assessments and risk treatment activities.
- Maintain the cybersecurity risk register and track remediation actions.
- Ensure compliance with applicable cybersecurity standards, regulatory requirements, and corporate policies.
- Support internal and external cybersecurity audits.
Security Architecture and Controls
- Ensure security controls are implemented and maintained across infrastructure, endpoints, cloud services, applications, and OT environments.
- Review and approve security designs for new projects and technology implementations.
- Support secure network segmentation and defense-in-depth strategies.
- Oversee vulnerability management and remediation programs.
Identity and Access Management
- Ensure privileged access management and identity governance controls are implemented and monitored.
- Oversee periodic access reviews and segregation of duties assessments.
- Support implementation of role-based access control (RBAC) frameworks.
- Ensure compliance with least-privilege principles and account management standards.
Vulnerability Management
- Direct vulnerability assessment and scanning activities.
- Prioritize remediation activities based on business risk.
- Monitor closure of identified vulnerabilities.
- Provide reporting on remediation status and risk exposure.
Third-Party Security
- Assess cybersecurity risks associated with suppliers and vendors.
- Participate in vendor security reviews and due diligence assessments.
- Ensure cybersecurity requirements are incorporated into contracts and procurement processes.
Business Continuity and Resilience
- Support disaster recovery and business continuity planning.
- Participate in cyber resilience exercises and simulations.
- Ensure cybersecurity recovery requirements are incorporated into continuity plans.
Security Awareness
- Develop and maintain cybersecurity awareness and training programs.
- Promote security best practices across all levels of the organization.
- Coordinate phishing simulation and awareness campaigns.
Reporting and Performance Management
- Prepare cybersecurity dashboards and reports for management.
- Provide regular updates to the Cybersecurity Manager on security posture, incidents, risks, and initiatives.
- Track cybersecurity KPIs and KRIs.
- Monitor progress against the cybersecurity roadmap.
Key Deliverables
- Cybersecurity Risk Register
- Security Incident Reports
- Vulnerability Management Reports
- Compliance and Audit Reports
- Cybersecurity KPI/KRI Dashboard
- Security Awareness Program
- Security Standards and Procedures
- Incident Response Plans
- Privileged Access Reviews
- Third-Party Security Assessments
- Cybersecurity Roadmap Progress Reporting
Required Qualifications
Essential
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- Minimum 8-10 years of cybersecurity experience.
- Minimum 3-5 years of cybersecurity leadership or management experience.
- Experience across security operations, risk management, governance, and security architecture.
- Experience managing third-party cybersecurity service providers.
Preferred Certifications
One or more of:
- CISSP
- CISM
- CRISC
- GSEC
- GIAC Certifications
- ISO 27001 Lead Implementer or Lead Auditor
- IEC 62443 Cybersecurity Certifications
- Microsoft Security Certifications
- CCSP
Knowledge and Experience
Technical Knowledge
- Security Operations and Incident Response
- SIEM and Security Monitoring Platforms
- Endpoint Detection and Response (EDR/XDR)
- Microsoft Security Technologies
- Identity and Access Management
- Privileged Access Management
- Vulnerability Management
- Cloud Security (Azure/AWS)
- Network Security
- OT/ICS Cybersecurity
- Security Architecture Principles
Governance Knowledge
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST Incident Response Framework
- IEC 62443
- ISO 27001
- CIS Critical Security Controls
- Risk Management Frameworks
Key Competencies
- Leadership and Team Management
- Strategic Thinking
- Risk-Based Decision Making
- Communication and Stakeholder Management
- Incident Management
- Problem Solving
- Vendor Management
- Project Management
- Analytical Thinking
- Report Writing and Executive Presentation Skills
Authority Levels
The Head of Cybersecurity is authorized to:
- Direct cybersecurity operational activities.
- Lead cybersecurity incident response activities.
- Escalate significant cyber risks to the Cybersecurity Manager.
- Recommend security control implementations.
- Initiate emergency security containment actions during cybersecurity incidents.
- Review and approve cybersecurity operational standards and procedures.
Key Performance Indicators (KPIs)
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Vulnerability Remediation Compliance Rate
- Security Awareness Completion Rate
- Audit Finding Closure Rate
- Privileged Access Review Completion Rate
- Security Incident Reduction Trends
- Cybersecurity Roadmap Delivery Performance
- Third-Party Security Assessment Completion Rate
- Compliance with Security Standards and Policies