Head of Cyber Security Defense Operations
Job Description
JOB DESCRIPTION
Role : Head of Cyber Security Defense Operations
Location : Abu Dhabi
Role Purpose:
Reporting to the CISO, the Head of Cyber Security Defense Operations is responsible for managing the Information Security Cyber Defense Operations section's practices, operations, performance, and budget. Head of Cyber Security Defense Operations closely collaborates with the CISO and Group Information Security Department (GISD) heads / managers as well as ITD and business stakeholders to ensure appropriate threat management, attack surface reduction, secure monitoring vulnerability management, and incident management activities are conducted in line with the bank's information security strategy and policies.
Key Accountabilities of the role
- Provide information security cyber defense operations-related expertise across ADIB's sections and units.
- Formulate ADIB cyber defense center strategy in alignment with ADIB cybersecurity strategy. Ensure CDC strategy is executed with given resources.
- Manage the Information Security Cyber Defense Operations section's practices, operations, performance, and budget in line with the organizational requirements and strategic objectives.
- Manage the Cyber Security Incident Response, (event analysis, triage, incident handling and management, investigations and forensics).
- Motivate the Information Security Cyber Defense Operations section team and provide continuous guidance and mentorship in order to create a performance-driven culture.
- Manage the Cyber Threat Intelligence capability (data feed / IOC management, and technical and strategic intelligence).
- Lead the information security cyber defense operations practices to strengthen and optimize group capabilities.
- Oversee information security monitoring activities and ensure that the outsourced security monitoring services can properly monitor security events from all systems, devices, applications, databases and solutions.
- Ensure ITD, Business Continuity Management, and other relevant parties at ADIB enable effective incident and disaster management and response.
- Oversee the escalation and follow-up activities related to information security incidents, breaches, and forensic investigations.
- Oversee the Attack Surface Reduction capability, including routine penetration testing, and vulnerability management activities.
- Manage the activities performed to scan for, analyze, and dispose vulnerabilities.
- Oversee the acceptance, triaging, assignment, and disposition of critical events and security incidents.
- Oversee the testing and exercising of business continuity, disaster recovery, and incident management plans.
- Participate in root cause analysis, and action reports development for high-profile and high-impact information security incidents.
- Manage the Cyber Threat Intelligence unit capability by overseeing the collection and analysis of threat intelligence and validating the threat intelligence reports that will be shared with ADIB teams.
- Manage the Threat Defense Operations unit by reviewing the activities associated to threat hunting and detection logic creation and update.
- Manage the design and oversee the implementation of information security cyber defense operations technologies and rules to ensure that adequate alerts are generated and appropriate logs are recorded.
- Provide expertise to ITD to ensure SIEM configuration is aligned with the detection logic developed to address critical use cases.
- Manage the Attack Surface Reduction unit's activities by overseeing how routine penetration testing, and vulnerability management activities are performed.
- Provide expertise for projects and initiatives related to cyber defense operations and ensure their planning and execution is aligned with the Information Security CyberDefense Operations objectives and strategy.
- Ensure created use cases covers critical and high risk attacks and threats.
- Develop and maintain libraries for threats and vulnerabilities.
Specialist Skills / Technical Knowledge Required for this role:
- Excellent interpersonal, verbal, written and presentation skills
- Strong knowledge of information security technologies and solutions such as SIEM, Incident Response Platform and Data Leakage Prevention.
- Strong knowledge of banking processes and modus operandi.
- Knowledge in ISO 27001, NESA, PCI DSS, SWIFT and other information security standards and regulations.
- Minimum bachelor's degree in computer science or information security/cybersecurity related field. Master's degree in Engineering, IT technical, and/or Business-related discipline is an advantage.
- One or more of the following professional certifications: CCIE, CISSP, CISA, CISM, CRISC, CGEIT, PMP, ITIL, COBIT, CIA, CRMA, CIP, CEH, GPEN
Previous Experience:
- More than 15 years of experience in information security with a focus on cyber defense operations, threat intelligence, attack surface reduction and/or incident management.
- In managing information security technologies and solutions in large international banks or financial institutions.
- Lead a team of information security professionals responsible for information security monitoring and incident responding and reporting.
- Experience in setting up and managing a Computer Incident Response Team (CIRT), Computer Security Incident Response Centre (CSIRC), or Security Operations Centre (SOC).
- Experience in information security in banking and financial services.
- Strong executive experience including management-level discussions and presentation's
Job Details
Employment Types:
Full time
Industry:
Banking / Accounting / Financial Services
Function:
IT
Roles:
Security Analyst
Skills:
Head of Cyber Security Defense Operations