Director of IT Security Operations (Americas and EMIA)

  • iNingizimu Afrika
  • Wsp Global Inc.
Director of IT Security Operations (Americas and EMIA)
  • Full-time

We are WSP - Join us and make your career future ready!

Think bigger scale. Think higher profile. Think ground-breaking. Join WSP, and you’ll be at the heart of a team of international experts all dedicated to growing and sharing their expertise, and working on projects that transform society for all of us.

WSP is one of the most diverse consulting firms in Africa, and the largest environmental consulting firm globally. To further our strategic business execution plan, we are seeking leaders who share our guiding principles – we value our people and our reputation; we are locally dedicated with international scale; we are future-focused and challenge the status quo; we foster collaboration; we have an empowering culture and hold ourselves accountable.

WSP’s Security Engineering and Operations Team is responsible for managing the global organization’s security technologies and systems.

The role of Director Security Operations reports directly to the Global Vice President Security Engineering and Operations and is responsible for leading our Security Operations Centre and working with the Manager of Incident Response and Manager of SOC Tools and Operations. This is primarily an internally facing role, although some interaction with clients and third parties may be required.

Specific areas of responsibility may include:

  • Security Analysis
  • Threat and Vulnerability Management
  • Network, Database, Server and Endpoint, and Application Security
  • Penetration Testing
  • Antivirus and Antimalware analysis
  • Event Analysis
  • Ethical Hacking
  • Privileged access management

The Director of Security Operations will have multiple security-related roles within the organization. Their main goal will be to provide a secure computing environment for the organization to conduct their business. The global security operations team will have overlapping duties however each role will have more specifically focused duties.

The director will be responsible for the overall direction and planning for both the incident response and tools team, liaising with our contracted partner for Level 1 and 2 Security Operations, 24/7 incident response, Security tool management, etc.

Key Responsibilities:

  • Incident Management Process and Forensics: Assist in providing forensic capabilities for the incident management process when needed. Monitor and manage infrastructure logging for security, including perimeter network devices, malware prevention, and intrusion prevention.
  • Definition and implementation of controls: Define security configuration and operations standards for security systems and applications, including policy assessment and compliance tools, network security appliances, and host-based security systems.
  • Network infrastructure security: Responsible for determining and maintaining the technical standards for configurations of routers, switches, firewalls, IPS and IDS devices.
  • Privileged access management: Responsible for maintaining our PAM toolset, ensuring least privilege across the organization.

Leadership and People Responsibilities:

  • Director of two separate managers within the security organization.
  • Displays leadership and independence in performing their role, with an ability to make complex decisions with limited input and review from senior staff.
  • Assist in the hiring, training, and coaching of new and existing staff.
  • Develop positive working relationships with other team members and business partners.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills.

Finance/Budgetary Responsibilities:

  • Support the Global Vice President Security Engineering and Operations in developing the budget projections based on short-and long-term goals and objectives.

Minimum Requirements:

  • Related experience in information security, risk, compliance, or similar position.
  • Bachelor's degree or equivalent in Information Technology, Computer Science, Engineering or related field.
  • Certification in Information Security (CISSP, ISC, or CISM) practices and policies.
  • Knowledge of security technologies (encryption, data protection, network intrusion prevention, EDR, firewalls, privilege access, etc.).
  • Knowledge of enterprise IT security concerns and technologies.
  • Experience with IT Governance frameworks such as COBIT, ITIL and ISO 2700x, NIST.
  • Experience with governance, compliance, and audit within IT environments.
  • Experience of risk management, including risk analysis, mitigation, and monitoring.
  • Knowledge of information security regulations applicable to WSP.

Preferred:

  • Master’s degree in information technology, Computer Science, Engineering or related field.
  • Knowledge of KQL, Python and PowerShell is a plus.

What’s in it for you?

WSP recognizes that work is only one part of our lives and making time for the other things in our life is important – be that our families, our friends or ourselves. So, if working from home, working part-time or having flexible start and finish time will help with this let us know as part of your application.

As well as rewarding you with competitive pay, WSP offers standard benefits including first class medical cover, generous days annual leave, and paid professional subscriptions.

WSP positively encourages applications from suitably qualified and eligible candidates regardless of sex, race, disability, age, religion or belief, marital status, pregnancy or maternity/paternity. We will interview all disabled applicants who meet the essential criteria.

#J-18808-Ljbffr