We are looking for a Manager – IT Security to join an established organisation and play a key role in strengthening cybersecurity, infrastructure protection, cloud security and technology risk management.
Key Responsibilities
- Partner with regional/cross-functional IT Security, Infrastructure, Technology Risk and Project teams to strengthen secure network and technology architecture.
- Review and optimise firewall requests and rules, including periodic reviews to identify outdated, redundant or high-risk rules.
- Assess Windows and Linux/Unix server hardening against security standards and review security exceptions.
- Conduct quarterly and ad-hoc vulnerability assessments to identify, prioritise and mitigate infrastructure security risks.
- Monitor AWS and Azure cloud environments for security misconfigurations, policy violations and non-compliant resources using cloud-native and third-party security tools.
- Represent Infrastructure Security in Change Approval Committees (CAC) and assess security implications of technology changes.
- Manage Data Loss Prevention (DLP) controls across endpoints and networks, including cloud storage access and security access requests.
- Support Third-Party Security Assessments, including security reviews during vendor onboarding and appropriate data deletion/offboarding processes.
- Work closely with stakeholders to ensure security controls align with regulatory requirements, internal policies and industry best practices.
What We're Looking For
- Degree in Information Technology, Cybersecurity or a related discipline.
- 5–7 years of relevant IT Security experience.
- Strong understanding of:
- Network architecture, security solutions and infrastructure security
- Security standards, regulatory requirements and best practices
- AWS and/or Azure cloud environments
- Cloud architecture, IAM, networking and compliance controls
- Cloud security frameworks and posture management
- Windows and Unix/Linux OS hardening
- Vulnerability management and security risk assessment
- Strong risk, compliance and problem-solving mindset.
- Ability to take ownership, work independently and collaborate effectively across multiple teams and functions.
- CISSP, CISM, CCSP or other relevant security certifications would be an advantage.