Jobs Companies KBR IT Cyber Security Head-Onsite (IF)

À propos de ce poste IT Cyber Security Head-Onsite (IF) chez KBR

KBR · Sur site · Basra, Al Başrah, Iraq

Title:

IT Cyber Security Head-Onsite (IF)

IT Cyber Security Head

Position Information

Job Title: IT Cyber Security Head
Department: Information Technology / Cybersecurity
Reports To: Cybersecurity Manager
Direct Reports: Location: [Location]
Employment Type: Full-Time

Position Purpose

The Head of Cybersecurity is responsible for leading the day-to-day cybersecurity function, managing cybersecurity operations, and overseeing the implementation of security controls across the organisation's Information Technology (IT) and Operational Technology (OT) environments. The role provides technical leadership to a small cybersecurity team and ensures cybersecurity risks are effectively identified, assessed, monitored, and mitigated.

Working under the direction of the Cybersecurity Manager, the Head of Cybersecurity is accountable for the execution of the cybersecurity strategy, governance requirements, security operations, compliance activities, and cybersecurity improvement initiatives.

Key Responsibilities

Cybersecurity Leadership

  • Lead and manage the cybersecurity team, providing technical guidance, mentoring, and performance management.
  • Coordinate cybersecurity activities across IT, OT, Digital, and business functions.
  • Act as the primary escalation point for cybersecurity operational issues.
  • Develop team capabilities, skills, and professional development plans.
  • Foster a strong cybersecurity culture throughout the organization.

Security Operations

  • Oversee Security Operations Centre (SOC) activities, whether internally delivered or outsourced.
  • Monitor security alerts, incidents, vulnerabilities, and threats.
  • Ensure effective incident detection, triage, investigation, containment, and recovery.
  • Lead cyber incident response activities and coordinate post-incident reviews.
  • Ensure cybersecurity monitoring and logging capabilities are maintained and optimized.

Governance, Risk and Compliance

  • Support the implementation and maintenance of the cybersecurity governance framework.
  • Manage cybersecurity risk assessments and risk treatment activities.
  • Maintain the cybersecurity risk register and track remediation actions.
  • Ensure compliance with applicable cybersecurity standards, regulatory requirements, and corporate policies.
  • Support internal and external cybersecurity audits.

Security Architecture and Controls

  • Ensure security controls are implemented and maintained across infrastructure, endpoints, cloud services, applications, and OT environments.
  • Review and approve security designs for new projects and technology implementations.
  • Support secure network segmentation and defense-in-depth strategies.
  • Oversee vulnerability management and remediation programs.

Identity and Access Management

  • Ensure privileged access management and identity governance controls are implemented and monitored.
  • Oversee periodic access reviews and segregation of duties assessments.
  • Support implementation of role-based access control (RBAC) frameworks.
  • Ensure compliance with least-privilege principles and account management standards.

Vulnerability Management

  • Direct vulnerability assessment and scanning activities.
  • Prioritize remediation activities based on business risk.
  • Monitor closure of identified vulnerabilities.
  • Provide reporting on remediation status and risk exposure.

Third-Party Security

  • Assess cybersecurity risks associated with suppliers and vendors.
  • Participate in vendor security reviews and due diligence assessments.
  • Ensure cybersecurity requirements are incorporated into contracts and procurement processes.

Business Continuity and Resilience

  • Support disaster recovery and business continuity planning.
  • Participate in cyber resilience exercises and simulations.
  • Ensure cybersecurity recovery requirements are incorporated into continuity plans.

Security Awareness

  • Develop and maintain cybersecurity awareness and training programs.
  • Promote security best practices across all levels of the organization.
  • Coordinate phishing simulation and awareness campaigns.

Reporting and Performance Management

  • Prepare cybersecurity dashboards and reports for management.
  • Provide regular updates to the Cybersecurity Manager on security posture, incidents, risks, and initiatives.
  • Track cybersecurity KPIs and KRIs.
  • Monitor progress against the cybersecurity roadmap.

Key Deliverables

  • Cybersecurity Risk Register
  • Security Incident Reports
  • Vulnerability Management Reports
  • Compliance and Audit Reports
  • Cybersecurity KPI/KRI Dashboard
  • Security Awareness Program
  • Security Standards and Procedures
  • Incident Response Plans
  • Privileged Access Reviews
  • Third-Party Security Assessments
  • Cybersecurity Roadmap Progress Reporting

Required Qualifications

Essential

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
  • Minimum 8-10 years of cybersecurity experience.
  • Minimum 3-5 years of cybersecurity leadership or management experience.
  • Experience across security operations, risk management, governance, and security architecture.
  • Experience managing third-party cybersecurity service providers.

Preferred Certifications

One or more of:

  • CISSP
  • CISM
  • CRISC
  • GSEC
  • GIAC Certifications
  • ISO 27001 Lead Implementer or Lead Auditor
  • IEC 62443 Cybersecurity Certifications
  • Microsoft Security Certifications
  • CCSP

Knowledge and Experience

Technical Knowledge

  • Security Operations and Incident Response
  • SIEM and Security Monitoring Platforms
  • Endpoint Detection and Response (EDR/XDR)
  • Microsoft Security Technologies
  • Identity and Access Management
  • Privileged Access Management
  • Vulnerability Management
  • Cloud Security (Azure/AWS)
  • Network Security
  • OT/ICS Cybersecurity
  • Security Architecture Principles

Governance Knowledge

  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST Incident Response Framework
  • IEC 62443
  • ISO 27001
  • CIS Critical Security Controls
  • Risk Management Frameworks

Key Competencies

  • Leadership and Team Management
  • Strategic Thinking
  • Risk-Based Decision Making
  • Communication and Stakeholder Management
  • Incident Management
  • Problem Solving
  • Vendor Management
  • Project Management
  • Analytical Thinking
  • Report Writing and Executive Presentation Skills

Authority Levels

The Head of Cybersecurity is authorized to:

  • Direct cybersecurity operational activities.
  • Lead cybersecurity incident response activities.
  • Escalate significant cyber risks to the Cybersecurity Manager.
  • Recommend security control implementations.
  • Initiate emergency security containment actions during cybersecurity incidents.
  • Review and approve cybersecurity operational standards and procedures.

Key Performance Indicators (KPIs)

  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • Vulnerability Remediation Compliance Rate
  • Security Awareness Completion Rate
  • Audit Finding Closure Rate
  • Privileged Access Review Completion Rate
  • Security Incident Reduction Trends
  • Cybersecurity Roadmap Delivery Performance
  • Third-Party Security Assessment Completion Rate
  • Compliance with Security Standards and Policies

Prêt à postuler chez KBR ?
Postuler chez KBR

À propos de KBR

KBR — Delivering Solutions, Changing the World. KBR brings together the best and brightest to deliver science, technology and engineering solutions that help governments and companies around the world accomplish their most critical missions and objectives. In everything we do, we are guided by our ONE KBR Values: We Value Our People – We create diverse, inclusive environments in which each person can feel safe, respected and valued, and where everyone has opportunities to grow and reach their full potential. We Deliver – We are uncompromising in our commitment to deliver innovative, high-quality, technology-led solutions for our customers and exceptional, sustainable value for all our stakeh

Voir tous les emplois chez KBR →

Emplois similaires

KBR
Senior Pricing Specialist
KBR
⚡ Postuler tôt Remote - U.S. Hybride $83,000–$125,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
KBR
Senior Wargamer (Level III)
KBR
⚡ Postuler tôt Joint Base Anacostia-Bolling,... Sur site $332,800–$332,800
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
KBR
Deputy Program Manager
KBR
⚡ Postuler tôt Chantilly, Virginia Sur site $177,300–$236,300
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
KBR
Special Operations Clinical Psychologist (75th Ranger Regiment, Fort Moore,GA)
KBR
⚡ Postuler tôt Fort Moore, Georgia Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
KBR
Special Operations Clinical Psychologist (75th Ranger Regiment, Fort Moore, GA)
KBR
⚡ Postuler tôt Fort Moore, Georgia Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
KBR
Engineering Technician
KBR
⚡ Postuler tôt North Charleston, South Caroli... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
KBR
Maritime & Coastal Engineer
KBR
⚡ Postuler tôt Sydney, New South Wales, Austr... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
KBR
Assistant Quality Assurance Manager
KBR
⚡ Postuler tôt Melbourne, Victoria, Australia Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 15 h
KBR
Fabrication Static Supervisor
KBR
⚡ Postuler tôt Jubail, Saudi Arabia Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 15 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez KBR

Voir tous les emplois chez KBR →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit