Description
We are seeking a seasoned Head of IT Security to own the end-to-end cybersecurity posture of the organization. This is a senior leadership role responsible for protecting a complex hybrid-cloud environment and converged IT/OT landscape (including manufacturing, IoT, and SCADA/ICS systems), while building and leading a high-performing security function across people, process, and technology. The role carries direct accountability for translating technical risk into business language for the C-Suite and Board of Directors.
- Define and lead the enterprise cybersecurity strategy and roadmap, aligning security investment with business risk and budget priorities.
- Build and mature a Zero Trust and SASE architecture, including ZTNA, micro-segmentation, and cloud-native secure access (CASB, FWaaS, SWG).
- Own security for converged IT/OT environments, applying the Purdue Model to segment industrial networks and manage ICS/SCADA security posture.
- Establish and scale an AI-driven Security Operations Center (SOC), integrating UEBA, AI-powered SOAR playbook automation, and proactive threat detection mapped to MITRE ATT&CK.
- Lead identity and endpoint security strategy: self-healing Unified Endpoint Management (UEM), passwordless authentication (FIDO2), and dynamic Privileged Access Management (PAM).
- Drive secure software delivery by embedding Cloud Security Posture Management (CSPM), Kubernetes security, and automated DAST/SAST scanning into CI/CD pipelines.
- Govern enterprise risk and compliance across ISO 27001:2022, NIST CSF 2.0, CIS Controls v8, PCI-DSS, TISAX, DORA, and applicable privacy regulations (e.g., GDPR, Indonesia's PDP Law).
- Report cybersecurity risk, incidents, and program maturity to the C-Suite and Board in clear, quantifiable financial and business terms.
- Recruit, mentor, and lead the security team; manage security budget, vendor relationships, and third-party risk.
- Own incident response planning, crisis management, and post-incident review for security events across IT and OT domains.
Requirements
- 12–15+ years of progressive enterprise cybersecurity experience, including significant time in a senior leadership capacity.
- Proven track record leading holistic security transformations spanning budget, people, and technology.
- Deep, hands-on expertise in Zero Trust architecture, SASE, and modern network security controls.
- Practical experience securing IT/OT convergence, manufacturing facilities, IoT, and industrial control systems.
- Strong background in AI-driven SecOps, SOAR automation, and threat intelligence operations.
- Working mastery of global governance frameworks: ISO 27001:2022, NIST CSF 2.0, CIS Controls v8, PCI-DSS, TISAX, DORA, and GDPR.
- Demonstrated ability to communicate technical cyber risk to non-technical executive and Board audiences.
- Bachelor's degree in Information Security, Computer Science, Engineering, or a related field; advanced degree a plus.
Preferred Certification
- CISSP — Certified Information Systems Security Professional
- CISM — Certified Information Security Manager
- CISA — Certified Information Systems Auditor
- GICSP — Global Industrial Cyber Security Professional
- CCSP — Certified Cloud Security Professional
- CRISC — Certified in Risk and Information Systems Control
- GIAC GDSA — Defensible Security Architecture
- CEH / OSCP