Job description:
Key Responsibilities
Security Leadership & Governance
- Serve as the primary cybersecurity lead and focal point for the NETS Group Business Unit and NETS Group SOC.
- Provide SOC oversight across the Business Unit systems, applications, infrastructure, and operational processes.
- Ensure cybersecurity risks are identified, assessed, communicated, and mitigated appropriately.
- Drive SOC governance initiatives and security awareness across Business Unit teams.
- Represent Business Unit during cybersecurity reviews, tabletop exercises, audits, assessments, and management forums.
Security Monitoring & Detection Oversight
- Partner closely with NETS Group SOC to ensure effective security monitoring and detection coverage for Business Unit assets.
- Review and validate security use cases, alerting requirements, and detection strategies relevant to card processing environments.
- Ensure critical Business Unit systems are onboarded into SIEM, EDR/XDR, and monitoring platforms.
- Identify visibility gaps and drive improvements in monitoring capabilities.
- Review security alerts, investigations, and escalations impacting Business Unit systems.
- Support threat hunting activities and proactive risk identification initiatives.
Security Incident Management
- Act as the Business Unit security lead during cyber incidents affecting Business Unit security operations.
- Coordinate incident response activities between Business Unit teams and Group SOC.
- Support triage, containment, eradication, recovery, and post-incident activities.
- Ensure timely communication of incidents, risks, and remediation plans to management.
- Lead security-related post-incident reviews and lessons-learned sessions.
- Track remediation actions through to completion.
Regulatory Compliance
- Lead and coordinate Business Unit cybersecurity activities supporting compliance.
- Ensure security controls remain effective and aligned with regulatory requirements.
- Coordinate remediation of audit findings, compliance gaps, and security control deficiencies.
- Support internal and external security assessments and audits.
- Maintain awareness of applicable regulatory and industry requirements including:
- CCoP (as applicable)
- Cyber Trust Mark
- MAS TRM Guidelines
- Cyber Hygiene requirements
- NETS security policies and standards
Stakeholder Management
- Serve as the principal liaison between:
- Business Unit Management
- Group SOC
- Technology Teams
- Risk & Compliance
- Internal Audit
- External Auditors
- Provide regular security posture updates and risk reporting to management.
- Facilitate security discussions, governance reviews, and operational meetings.
- Build strong partnerships to ensure security objectives are integrated into business operations.
Continuous Improvement & Security Strategy
- Identify opportunities to improve Business Unit security maturity and operational resilience.
- Drive enhancements in monitoring, detection, incident response, and security controls.
- Support implementation of new security technologies and capabilities.
- Contribute to enterprise security initiatives led by Group SOC.
- Develop and maintain security metrics, KPIs, and management reporting.
Required Qualifications & Experience
- 10+ years of cybersecurity, information security, or security operations experience.
- Minimum 5 years in a leadership, security management, or senior security operations role.
- Strong experience in:
- Security Operations (SOC)
- Security Monitoring & Detection
- Cyber Incident Response
- Vulnerability Management
- Security Governance
- Risk Management
- Compliance & Audit Management
- Experience supporting PCI-DSS environments.
- Strong understanding of:
- Payment systems and card processing environments
- Security monitoring technologies
- SIEM platforms
- EDR/XDR solutions
- Security controls and frameworks
- Experience managing security initiatives in regulated environments.
Preferred Qualifications
- Experience within:
- Payments
- Banking
- Financial Services
- Critical National Infrastructure
- Familiarity with:
- PCI-DSS
- MAS TRM Guidelines
- NIST Cybersecurity Framework
- ISO 27001
- MITRE ATT&CK
- Experience working with:
- SIEM Solutions (Elastic, LogRhythm, etc).
- Trend Micro Solutions
- Microsoft Defender
Preferred Certifications
- CISSP
- CISM
- CRISC
- CCSP
- PCI Professional (PCIP)
- GIAC Certifications
- AWS, Azure or Microsoft Security Certifications
Key Competencies
- Strong stakeholder management and executive communication skills
- Security leadership and advisory capabilities
- Risk-based decision making
- Strong understanding of SOC and detection operations
- Excellent incident management skills
- Ability to influence without direct authority
- Strategic thinking with hands-on operational knowledge
- Strong analytical and problem-solving skills
What Success Looks Like
- Strong security partnership established between Business Unit and Group SOC.
- Effective monitoring and detection coverage across all critical Business Unit assets.
- Regulatory requirements consistently met.
- Security incidents managed effectively with minimal business impact.
- Security risks proactively identified and mitigated.
- Improved security maturity and resilience across the Business Unit environment.
- Trusted advisor status with Business Unit leadership and NETS executive stakeholders.