
IT Cybersecurity Project Lead
- Incident Response
- Vulnerability Management
- triage
- SIEM
- EDR
- Microsoft Defender
- CrowdStrike
- Threat Intelligence
- IEC
- NIST
- ISO 27001
- CompTIA Security+
- CySA+
- CISSP
- GSEC
- CEH
- Microsoft Sentinel
- Tenable
- Qualys
- Splunk
- Windows Server
- Active Directory
- Azure AD
- Linux
- Network Security
- Azure
- SCADA
- Incident Management
Title:
IT Cybersecurity Project LeadIT Cyber Security Project Lead
Position Information
Job Title: IT Cyber Security Head
Department: Information Technology / Cybersecurity
Reports To: IT Cyber Security Head
Location: [Location]
Employment Type: Full-Time
Position Purpose
The Cybersecurity Operations Engineer is responsible for the implementation, operation, monitoring, and continuous improvement of cybersecurity controls across the organization's Information Technology (IT) and Operational Technology (OT) environments.
The role focuses on security monitoring, incident response, vulnerability management, endpoint security, identity security, and security tooling administration. The position plays a key role in protecting organizational assets from cyber threats while supporting compliance with cybersecurity policies, standards, and regulatory requirements.
The Cybersecurity Operations Engineer works closely with IT infrastructure, cloud, network, application, and OT teams to ensure security controls are implemented and operating effectively.
Key Responsibilities
Security Operations
- Monitor security events and alerts generated by security monitoring platforms.
- Investigate suspicious activities and security incidents.
- Perform incident triage, containment, eradication, and recovery activities.
- Support cyber incident response and forensic investigations.
- Participate in on-call cyber incident response activities where required.
- Maintain incident records and lessons learned documentation.
Security Monitoring & SIEM
- Administer and maintain SIEM platforms.
- Develop and tune detection rules and alert thresholds.
- Monitor log sources and ensure adequate security event coverage.
- Investigate security alerts and escalate critical findings.
- Develop use cases and threat detection analytics.
Endpoint and Server Security
- Manage Endpoint Detection and Response (EDR/XDR) solutions.
- Support endpoint protection platforms such as Microsoft Defender, CrowdStrike, Trend Micro, or equivalent.
- Monitor and investigate endpoint threats.
- Ensure security agents remain operational and compliant.
- Support server hardening and security baseline implementation.
Vulnerability Management
- Perform vulnerability scanning activities.
- Analyse vulnerability assessment reports.
- Prioritize remediation actions based on risk.
- Coordinate remediation efforts with infrastructure and application teams.
- Monitor closure of identified vulnerabilities.
- Produce vulnerability metrics and reporting.
Identity and Access Management
- Support privileged access management solutions.
- Monitor privileged account usage.
- Assist with periodic access reviews.
- Support identity governance activities.
- Ensure compliance with least-privilege principles.
Security Tool Administration
- Administer cybersecurity technologies including:
- SIEM
- EDR/XDR
- PAM
- Vulnerability Management Platforms
- Email Security Solutions
- Web Security Gateways
- Security Monitoring Platforms
- Threat Intelligence Platforms
- Maintain health and performance of cybersecurity systems.
- Support technology upgrades and deployment activities.
Threat Management
- Monitor emerging cyber threats and vulnerabilities.
- Review threat intelligence feeds.
- Assess threats for organisational relevance.
- Recommend protective measures and compensating controls.
- Support threat hunting activities.
OT/Industrial Cybersecurity Support
- Assist with cybersecurity monitoring of OT environments.
- Support IEC 62443-aligned control implementation.
- Monitor OT security events and vulnerabilities.
- Participate in OT risk assessments.
- Support secure network segmentation initiatives.
Security Compliance
- Assist in design and implementation of cybersecurity policies and standards.
- Support cybersecurity audits and assessments.
- Maintain operational evidence for compliance activities.
- Support implementation of NIST, ISO 27001, and IEC 62443 requirements.
Reporting
- Prepare operational cybersecurity reports.
- Produce incident and vulnerability metrics.
- Maintain dashboards and KPI reporting.
- Provide regular status updates to the Head of Cybersecurity.
Key Deliverables
- Security Incident Reports
- Vulnerability Assessment Reports
- SIEM Monitoring Dashboards
- Threat Intelligence Briefings
- Security Control Compliance Reports
- Security Monitoring Use Cases
- Security Technology Health Reports
- Privileged Access Monitoring Reports
- Cybersecurity KPIs and Metrics
Required Qualifications
Essential
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- Minimum 3-5 years of cybersecurity operations experience.
- Experience supporting enterprise security technologies.
- Experience investigating cybersecurity incidents.
- Experience with security monitoring and vulnerability management.
Preferred Certifications
One or more of:
- CompTIA Security+
- CompTIA CySA+
- Microsoft Security Certifications
- SC-200 Security Operations Analyst
- CISSP Associate
- GIAC Certifications
- GSEC
- SSCP
- CEH
Technical Skills
Security Operations
- Incident Response
- Threat Detection
- Threat Hunting
- Security Monitoring
- Digital Forensics Fundamentals
Security Platforms
- Microsoft Sentinel
- Microsoft Defender XDR
- CrowdStrike
- Trend Micro
- Tenable
- Qualys
- Rapid7
- Splunk
- QRadar
Infrastructure Security
- Windows Server
- Active Directory
- Entra ID (Azure AD)
- Linux Administration
- Network Security
- Firewalls
- VPN Technologies
Cloud Security
- Microsoft Azure
- Microsoft 365 Security
- AWS Security Fundamentals
OT Security (Preferred)
- Industrial Control Systems (ICS)
- SCADA Security
- IEC 62443
- OT Network Security
Knowledge Requirements
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53
- IEC 62443
- ISO 27001
- CIS Critical Security Controls
- Cyber Kill Chain
- MITRE ATT&CK Framework
- Vulnerability Management Processes
- Security Incident Lifecycle Management
Key Competencies
- Analytical Thinking
- Problem Solving
- Technical Troubleshooting
- Incident Management
- Attention to Detail
- Teamwork and Collaboration
- Communication Skills
- Risk Awareness
- Continuous Learning
- Customer Service Orientation
IT Cybersecurity Project Lead ยท KBR Wyle Services, LLC