About this role
The Cybersecurity Lead is responsible for safeguarding the organization’s information assets, operational technology interfaces, digital platforms, and data by leading the enterprise cybersecurity and information security function. Reporting directly to the Chief Technology Officer, the role provides independent oversight of cybersecurity risk, governance, and compliance while supporting safe, reliable, and efficient business and operational outcomes. The role operates within a lean technology organization and works closely with Technology Operations, Digital & Technology Innovation, and Technical Project Management teams to embed cybersecurity controls into day-to-day operations and project delivery.
Responsibilities
- Define the organization’s information and cybersecurity strategy in collaboration with the Digital and Technology Innovation team, and execute it in alignment with operational reliability, safety, and business objectives.
- Establish and maintain cybersecurity policies, standards, and procedures aligned with global best practices and regulatory expectations.
- Ensure security considerations are integrated into infrastructure, cloud, business applications, and digital transformation initiatives.
- Lead enterprise cybersecurity risk management activities, including identification, assessment, mitigation, and reporting of cyber risks, and maintain the cybersecurity and IT risk register.
- Support integration with broader enterprise risk management processes and ensure compliance with applicable regulatory requirements, contractual obligations, and data protection standards relevant to the operating environment.
- Coordinate and support internal and external audits, risk assessments, and assurance activities.
- Provide oversight for outsourced Security Operations Centre (SOC) services and lead cybersecurity incident response activities, including investigation, containment, remediation, and post-incident reviews.
- Ensure incident response plans, escalation procedures, and communication protocols are defined, tested, and operationally practical.
- Oversee vulnerability management and penetration testing programs delivered by third-party providers and coordinate remediation with Technology Operations based on risk.
- Monitor emerging cyber threats and translate insights into practical control improvements.
- Oversee Identity and Access Management (IAM) controls, including privileged access management and user lifecycle processes, and promote least-privilege, segregation of duties, and zero-trust principles.
- Provide security input into system architecture, solution designs, and technology standards.
- Assess and manage cybersecurity risks in relation to vendors, service providers, and technology partners, and embed appropriate security controls within contracts.
- Deliver security awareness and targeted training to improve cyber hygiene, and guide technology and digital delivery teams on secure practices; line-manage and mentor a Cybersecurity Analyst to build internal security capability.
- Report cybersecurity risks, incidents, and overall security posture to the CTO and act as the primary cybersecurity contact across the organization.
Requirements
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related discipline.
- 5–8 years of experience in cybersecurity, information security, or IT GRC roles within enterprise environments.
- Practical experience with governance frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, or similar.
- Proven experience conducting cybersecurity risk assessments, audits, and compliance activities.
- Familiarity with security operations, incident response, vulnerability management, and third-party security oversight.
- Experience in regulated or asset-intensive industries (e.g., oil & gas, energy, utilities, or heavy industry) is advantageous.
- Relevant professional certifications (or working towards them) such as ISO 27001, CISSP, CISM, or CRISC are desirable.
- Strong understanding of both technical cybersecurity controls and IT governance, risk, and compliance, with a practical, risk-based approach suited to operational environments where availability, safety, and business continuity are critical.