Information Security Operations Lead
$$$$
🪖 DefTech
Product
We are looking for an Information Security Operations Lead to own the company’s day-to-day security operations — from incident response and SOC performance to vulnerability management, access governance, and ISO 27001 readiness. The role reports to the CISO, sits within the Security & Risk Department, and is the main point of contact for operational security across IT and other business units.
Responsibilities
- Act as the single point of contact for IT, R&D, Manufacturing, and other departments on operational security matters, including reviews for new services, integrations, and vendor access
- Lead and coordinate the SOC analyst team: prioritization, quality control, mentoring, performance management
- Own incident response end-to-end: coordinating participants, timeline and communication, containment, remediation, and reporting with lessons learned for the CISO
- Maintain SOC playbooks, runbooks, and triage/response procedures; run regular case reviews and turn findings into process improvements
- Improve SIEM detections, reduce false positives, and drive automation
- Drive vulnerability remediation together with IT: prioritization, timelines, tracking, and overdue reporting
- Organize regular access reviews together with IT and system owners
- Own SOC-related ISMS controls under ISO 27001 (incident, vulnerability, and log management per Annex A); prepare audit evidence for internal and certification audits
- Maintain the security incident register per ISMS requirements and close related corrective actions within agreed timelines
- Contribute operational incident and threat data to risk assessment reviews
- Track and report security operations metrics (MTTD, MTTR, SLA, overdue vulnerabilities) to the CISO and leadership
Required Skills & Experience
- 5+ years of experience in SOC, Incident Response, or Security Operations
- Experience leading a SOC team or acting as a technical lead
- Hands-on experience with SIEM, EDR/XDR, and incident management
- Experience coordinating vulnerability management and access reviews with IT
- Hands-on experience with ISO 27001 or a similar security framework
- Strong stakeholder management and communication skills, including with non-technical audiences
Nice to Have
- Cloud security experience (AWS, Azure, GCP)
- SOAR, automation, or scripting experience
- Experience supporting ISO 27001 certification audits
- Certifications: CISSP, GCIH, GCIA, SC-200, Splunk, or similar
The company offers:
- Official employment with a competitive salary and clear, transparent terms of cooperation.
- Paid vacation (24 calendar days per year) and paid sick leave.
- Support for your professional growth — the company is actively expanding, and you’ll have the opportunity to grow together with it.
- An atmosphere of trust, open communication, and leadership — initiative is welcomed, ideas are brought to life, and the team supports your progress.
Required skills
Information Security (InfoSec), ISO 27001, Cybersecurity, Network Security, SIEM
+ 1 more
Risk Management
Required languages
English
B1 - Intermediate
Ukrainian
Native
Published 7 October
14 views
·
0 applications
📊
Average salary range of similar jobs in
analytics →
Loading...