Агенція оборонних закупівель DOT

Head of Information Security

$$$$
🪖 DefTech

The Defense Procurement Agency (DOT) is a state-owned enterprise responsible for procuring military equipment, ammunition, UAVs, fuel, food, clothing, and other critical supplies for the Armed Forces of Ukraine and the Defense Forces.

 

Our mission: Strengthening Ukraine's defense capabilities by ensuring reliable procurement and supporting the development of the national defense industry.

 

Our vision: To become the driving force behind a modern defense procurement ecosystem built according to NATO standards.

 

We are looking for a Head of Information Security to lead and strengthen our Information Security function across governance, engineering, and security operations. This role combines strategic leadership with hands-on technical expertise, ensuring the continuous development of our Information Security Management System (ISMS), alignment with the NIST Cybersecurity Framework, and the organization's readiness to prevent, detect, and respond to cyber threats.

 

What You'll Accomplish (First 6–12 Months)

 

  • Ensure continued NIST compliance for DOT Chain and define the roadmap for future security initiatives, including platforms such as Azure AI Foundry.
  • Strengthen the security posture of IT Enterprise by implementing and maintaining NIST security controls, establishing regular risk assessments, exception management, and vulnerability remediation processes.
  • Build a high-performing security organization with defined OKRs, KPIs, resource planning, and performance management.
  • Enhance Azure-based Security Operations by improving monitoring, incident response, vulnerability management, identity governance, and RBAC.
  • Lead Red Team and Purple Team exercises (including ransomware readiness and identity compromise scenarios) and translate findings into engineering improvements.
  • Establish vendor security governance, including security assessments, NDA/SLA/DPA requirements, and third-party security audits.

 

Responsibilities

 

Leadership & Team Management

 

  • Lead both Information Security Governance (ISMS, Risk & Compliance) and Cybersecurity Engineering & Operations.
  • Manage, mentor, and develop the Information Security team through structured performance management, OKRs, and individual development plans.
  • Collaborate closely with Engineering, IT, Product, and business stakeholders to prioritize security initiatives and protect critical services.

 

Governance, Risk & Compliance

 

  • Develop and maintain security policies, standards, procedures, and risk registers.
  • Lead internal and external security audits and coordinate remediation activities.
  • Drive the organization's transition toward NIST-based security practices while maintaining alignment with ISO 27001 where required.
  • Own Incident Response Plans (IRP), post-incident reviews, and continuous improvement.
  • Ensure compliance with Ukrainian legislation related to information security and personal data protection.

 

Security Engineering & Operations

 

  • Oversee enterprise security technologies, including:
  • Microsoft Sentinel
  • Microsoft Defender
  • EDR/XDR
  • SIEM
  • DLP
  • PAM
  • IAM / Microsoft Entra ID
  • MDM
  • Lead incident monitoring and response activities.
  • Manage vulnerability lifecycle from discovery through remediation.
  • Improve identity security through MFA, PIM, Least Privilege, JML processes, Key Vault, secrets management, and centralized logging.
  • Define and improve SOC processes, runbooks, SLAs, and operational metrics.

 

Application Security & Secure SDLC

 

  • Strengthen application security throughout the software development lifecycle.
  • Drive Threat Modeling, Security Architecture Reviews, DevSecOps practices, automated code scanning (SAST/DAST), SBOM generation, and CI/CD security.
  • Integrate Red/Purple Team findings into engineering roadmaps and development practices.

 

Vendor Security

 

  • Evaluate and audit third-party vendors integrated with DOT Chain.
  • Establish and maintain supplier security requirements, including NDA, SLA, DPA, and third-party security assessments.

 

Strategy, Reporting & Budget

 

  • Report regularly to executive leadership on security posture, KPIs, risks, vulnerability remediation, and incident readiness.
  • Own the Information Security budget and define a 12–18 month security roadmap with prioritized initiatives and measurable business value.

 

Requirements

 

Experience

 

  • 5+ years of experience in Information Security or Cybersecurity.
  • 3+ years leading Information Security teams and security programs.
  • Proven experience implementing enterprise Information Security strategies and governance.
  • Hands-on experience with Red Team/Purple Team exercises, attack simulations, ransomware preparedness, and identity compromise scenarios.
  • Strong experience implementing and maintaining NIST Cybersecurity Framework and/or ISO 27001.
  • Experience building or managing Security Operations (SOC/SecOps), incident response, vulnerability management, and security monitoring.
  • Strong Microsoft Azure security expertise, including:
  • Microsoft Defender for Cloud
  • Defender for Endpoint
  • Defender for Identity
  • Defender for Office 365
  • Microsoft Sentinel
  • Microsoft Entra ID
  • Azure Key Vault
  • Understanding of Secure SDLC, Application Security, DevSecOps, SAST/DAST, CI/CD security, Infrastructure as Code, and secret management.
  • Experience securing .NET and PHP application environments is an advantage.

 

Technical Knowledge

 

  • Strong practical knowledge of:
  • NIST Cybersecurity Framework (CSF 2.0)
  • NIST SP 800 Series
  • ISO/IEC 27001
  • Knowledge of Ukrainian regulations related to information security and personal data protection.

 

Leadership & Soft Skills

 

  • Strong leadership, people management, and stakeholder management skills.
  • Experience establishing KPIs, OKRs, and performance management frameworks.
  • Ability to balance strategic governance with hands-on technical leadership.
  • Excellent communication skills, including the ability to explain technical risks to executive stakeholders.
  • Strong analytical thinking and decision-making skills.
  • Zero tolerance for corruption.

 

Preferred Qualifications

 

  • CISSP
  • CISM
  • ISO 27001 Lead Implementer or Lead Auditor
  • Microsoft certifications such as SC-100, SC-200, SC-300, SC-400, or AZ-500.
  • Experience working within government organizations or other highly regulated environments.

 

What We Offer

 

  • Meaningful work that directly contributes to strengthening Ukraine's defense capabilities.
  • Official employment with competitive salary and full social benefits.
  • Professional development, learning opportunities, and career growth.
  • Structured onboarding and dedicated mentorship.
  • A collaborative, supportive, and mission-driven team.
  • Modern office near the metro with reliable internet and equipped shelter.
  • Opportunity to build and lead cybersecurity for one of Ukraine's most strategically important digital ecosystems.

 

By joining our team, you will contribute to one of Ukraine's largest digital transformation initiatives in the defense sector and help build the future of defense procurement.

 

Ready to make a real impact? We'd love to hear from you. Apply today!

 

* By submitting your CV, you consent to the processing of your personal data in accordance with applicable legislation.

** Due to the high volume of applications, only candidates whose qualifications best match the position will be contacted.

Required languages

English A2 - Elementary
Ukrainian Native
Published 2 July · Updated 30 July
55 views
·
0 applications
Response activity: High
Last responded 3 days ago
To apply for this and other jobs on Djinni login or signup.
Loading...