Responsibilities
- Continuously monitor and assess cyber threats, vulnerabilities, and attack surfaces.
- Aggregate findings from vulnerability scans, threat intelligence, penetration tests, and red teaming.
- Identify critical exposures and prioritise based on business risk and impact.
- Manage takedown services with external providers.
- Leverage internal and external threat intelligence sources.
- Map threats to organisational assets and vulnerabilities.
- Track emerging threats, zero-days, and active campaigns.
- Coordinate vulnerability scanning activities and ensure coverage.
- Validate scan results and eliminate false positives.
- Work with Group IT/International Business Units teams to remediate vulnerabilities.
- Identify and monitor internal and external attack surfaces.
- Discover shadow IT, exposed assets, and misconfigurations.
- Ensure external-facing assets are secured and continuously assessed.
- Use AI-driven agents to safely simulate and validate exploitability of exposures (AEV) in production-like environments.
- Continuously identify and validate attack paths, privilege escalation, and lateral movement risks.
- Correlate simulation results into actionable risk insights with proven exploitability.
- Work closely with SOC, Incident Response, Group IT and International Business Units and regional business partners to carry out monitoring of systems for security anomalies and detection of breaches.
- Advise system owners on remediation and risk mitigation strategies.
- Support security governance and audit requirements.
- Conduct quarterly Cybersecurity Table-top exercises with line of business.
- Conduct annual Group wide cybersecurity drill.
Requirements
- Proven track record of execution in ensuring the desired outcomes are tied to business needs.
- Strong experience in IT Operations, developing architectural artifacts including reference architectures, roadmaps, architectural principles, technology standards, security non-functional requirements, architectural decisions and design patterns.
- Possess strong analytical, problem solving and decision-making skills in a fast paced and dynamic environment.
- Ability to establish and manage effective working relationships in a matrix environment with other departments, groups and staff with whom work must be coordinated or interfaced.
- Exhibit excellent interpersonal skills among team members and other stakeholders with strong written and oral communication skills.
Skills
- Network Security
- Web Security
- Application Security
- Agentic Exposure Simulation (AES) / Agentic Exposure Validation (AEV) platforms or similar continuous security validation technologies
Experience Level
- 3-5 years of experience as a technical lead in information security field
Education Level
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology or related fields.
- Possession of one or more industry-recognised cybersecurity certifications (e.g., CISSP, CISM, CEH, GIAC) is an added advantage.
