ACB Insurance - Security Lead
Security Lead is responsible for developing, implementing, and managing the organization‘s cybersecurity strategy, policies, and operations. This role ensures the confidentiality, integrity, and availability of company information assets, systems, networks, and applications. The Security Lead will lead security initiatives, oversee risk management activities, manage incident response processes, and ensure compliance with relevant security standards and regulations.
Key Responsibilities
Security Strategy & Governance
- Develop and maintain the organization‘s information security roadmap aligned with business objectives.
- Establish cybersecurity policies, standards, procedures, and best practices.
- Lead security governance initiatives and ensure security controls are effectively implemented.
- Conduct regular security assessments and gap analyses.
- Provide strategic security recommendations to executive leadership.
Risk Management & Compliance
- Identify, assess, and mitigate cybersecurity risks across the organization.
- Ensure compliance with regulatory requirements and industry frameworks including ISO 27001, NIST, CIS Controls, PCI-DSS, GDPR, and local regulations where applicable.
- Coordinate internal and external security audits.
- Maintain risk registers and remediation plans.
Security Operations
- Oversee Security Operations Center (SOC) functions and security monitoring activities.
- Manage security tools such as:
- SIEM
- EDR/XDR
- IDS/IPS
- Web Application Firewall (WAF)
- Data Loss Prevention (DLP)
- Vulnerability Management platforms
- Ensure continuous monitoring and threat detection capabilities.
Incident Response & Threat Management
- Lead cybersecurity incident response, investigation, containment, and recovery efforts.
- Develop and maintain Incident Response Plans and Playbooks.
- Coordinate forensic investigations when necessary.
- Conduct post-incident reviews and implement corrective actions.
- Monitor emerging threats and vulnerabilities.
Security Architecture & Engineering
- Review and approve secure architecture designs for infrastructure, cloud, and applications.
- Collaborate with IT, DevOps, and development teams to implement security-by-design principles.
- Support cloud security initiatives across AWS, Azure, and Google Cloud environments.
- Oversee vulnerability assessments and penetration testing activities.
Team Leadership
- Lead and mentor security engineers, analysts, and consultants.
- Establish security KPIs, performance objectives, and development plans.
- Manage vendor relationships and third-party security services.
- Promote cybersecurity awareness programs across the organization.
Required Qualifications
Education
- Bachelor‘s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field.
- Master‘s degree is preferred.
Experience
- 7+ years of experience in cybersecurity or information security.
- 3+ years of leadership or team management experience.
- Proven experience managing enterprise security programs.
- Hands-on experience with security monitoring, incident response, and risk management.
Technical Skills
- Strong understanding of:
- Network Security
- Cloud Security
- Application Security
- Identity and Access Management (IAM)
- Security Architecture
- Threat Intelligence
- Vulnerability Management
- Security Operations (SOC)
- Experience with AWS, Microsoft Azure, or Google Cloud security services.
- Knowledge of Zero Trust Architecture and modern cybersecurity frameworks.
- Familiarity with DevSecOps practices and CI/CD security integration.
Security Certifications (Preferred)
One or more of the following:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- GIAC Certifications
- CEH (Certified Ethical Hacker)
- CCSP (Certified Cloud Security Professional)
- ISO 27001 Lead Implementer / Lead Auditor