Skip to content
← Back to job listings

Cyber Security Operations Manager

Fa Emqh Saasfaprod1 · India

CybersecurityImported listingfull-timeabout 17 hours ago

About The Role

Kent is looking for a Cyber Security Operations Manager to lead the end-to-end operation and continuous improvement of our cyber security capability, and to help embed security across the wider technology estate. The role is accountable for detecting, responding to and reducing cyber risk across Kent's global technology environment through effective security operations, threat detection, incident response and vulnerability management, working alongside colleagues in Infrastructure, Cloud, Service Operations, Enterprise Architecture, Applications and Compliance to deliver measurable risk reduction.
Working within a lean global cyber security function, the role combines operational leadership with the development of longer-term capability. The Cyber Security Operations Manager is the technical authority for security operations and a trusted partner to the wider technology teams, setting security requirements, coordinating specialist activity and assuring that controls are operating effectively. Infrastructure, Cloud, Network, Applications and Service Operations teams remain accountable for the day-to-day management of the platforms and services within their remit. Success in this role is measured by improved security outcomes and measurable risk reduction across Kent rather than by direct administration of technology platforms.
We are looking for a proactive and collaborative security professional with sufficient technical depth to provide credible direction and challenge across endpoint security, identity security, Microsoft 365, Azure, vulnerability management, threat intelligence and security monitoring. The role will raise the organisation's security maturity by working through the teams that design, own and operate these services.
Skills and Responsibilities:

  1. Security Operations & Incident Response
  • Provide security leadership and oversight for Kent's cybersecurity monitoring and response capabilities, including defining requirements, service expectations, escalation paths and measures of effectiveness.
  • Lead and coordinate the response to significant or complex security events and incidents, working with the teams responsible for the affected platforms and services.
  • Lead incident containment, eradication, recovery and post-incident review activities.
  • Develop and maintain incident response procedures, playbooks and escalation processes.
  • Coordinate internal and external stakeholders during security incidents.
  • Conduct root cause analysis and ensure remedial actions are implemented and tracked.
  1. Security Monitoring & Threat Detection
  • Define and oversee improvements to security monitoring and detection capabilities, agreeing technical changes with the teams responsible for administering the relevant platforms.
  • Develop and tune detection rules, alerts and use cases to improve visibility of threats.
  • Conduct proactive threat hunting using available security telemetry and intelligence sources.
  • Track and assess emerging threats and vulnerabilities relevant to Kent's operating environment.
  • Benchmark detection and response capabilities against recognised frameworks including MITRE ATT&CK.
  1. Vulnerability & Exposure Management
  • Lead the end-to-end vulnerability management process by setting the framework, risk-based priorities and reporting requirements, while Infrastructure, Cloud, Applications and other service owners remain accountable for assessment support, remediation and operational change within their environments.
  • Develop risk-based prioritisation processes for remediation activities.
  • Track remediation performance and provide reporting to stakeholders.
  • Coordinate vulnerability assessments, penetration testing and security reviews.
  • Verify remediation activities and security improvements.
  1. Security Technology Management
  • Act as the security service owner for key cybersecurity capabilities, including CrowdStrike Falcon, by defining security requirements, control outcomes, roadmap priorities and service performance expectations. Day-to-day platform administration remains with the designated Infrastructure or Platform team.
  • Review the configuration and effectiveness of security tooling, identify required improvements and work with the relevant platform owners to plan, implement and validate changes
  • Provide technical guidance on security controls relating to endpoint security, identity management, email security, cloud security and data protection.
  • Assist in evaluating and implementing new security technologies and capabilities.
  1. Identity, Cloud & Microsoft Security
  • Provide security oversight for Microsoft 365, Azure and Entra ID environments by defining control requirements, reviewing risk and working with the responsible Platform and Infrastructure teams to prioritise improvements.
  • Monitor identity-related threats and security events.
  • Define Zero Trust security requirements and oversee their implementation by the teams responsible for identity, endpoint, network, cloud and application services.
  • Review security configurations and recommend improvements across cloud-based platforms.
  1. Attack Surface & Offensive Security
  • Manage external attack surface monitoring activities.
  • Coordinate third-party penetration testing and red team exercises.
  • Review security findings and ensure appropriate remediation is planned and completed.
  • Identify opportunities to reduce external exposure and improve resilience.
  1. Governance, Reporting & Continuous Improvement
  • Develop and report operational security metrics and key performance indicators.
  • Contribute to monthly security reporting and governance forums.
  • Support security audits, risk assessments and compliance activities.
  • Maintain operational security standards, procedures and documentation.
  • Drive continuous improvement initiatives to enhance the maturity of Kent's cybersecurity capability.
  1. Cross-Functional Collaboration & Security by Design
  • Work as a trusted partner to Infrastructure, Cloud, Network and Application teams to embed security-by-design principles into solutions from the outset.
  • Partner with Service Operations to ensure security incidents, vulnerabilities and remediation activities are properly operationalised through ITSM processes, clear ownership models and escalation paths.
  • Support Enterprise Architecture and project teams to identify and address security risks early in the solution lifecycle rather than after implementation.
  • Improve visibility of technology assets by aligning asset management, endpoint management and security monitoring.
  • Champion the use of automation to reduce manual security effort and improve response times.
  • Provide oversight and guidance on AI, Copilot and emerging technology risks as adoption grows across the business.
  • Work with Compliance, Internal Audit and business stakeholders to translate security activity into measurable risk reduction.

In addition to the responsibilities listed herein, the employee may be required to perform other ad-hoc tasks as needed or directed by the supervisor or management. These tasks will be within the reasonable scope of the employee's skills, capabilities, and role within the organization. The intent of this provision is to allow for flexibility and adaptability in meeting the dynamic needs of the organization, ensuring that operational requirements can be met efficiently. All such tasks will be assigned considering the employee's current workload and with respect to their professional development.
Your knowledge/skills, education, and experience:
Knowledge/ Qualification/ Training/ Certification:
Essential

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science or a related discipline.
  • Minimum 7-10 years of cybersecurity experience with at least 5 years focused on security operations, incident response and vulnerability management.
  • Demonstrable experience providing technical leadership, assurance or service ownership for CrowdStrike Falcon or a comparable enterprise endpoint security platform.
  • Experience in incident response, threat hunting and security investigations.
  • Strong understanding of Microsoft 365, Azure and Entra ID security capabilities.
  • Experience managing vulnerability management and penetration testing programmes.
  • Knowledge of security frameworks including NIST CSF, ISO27001, CIS Controls and MITRE ATT&CK.

Desirable

  • Experience with SIEM, SOAR, CASB, DLP, Email Security and Cloud Security platforms.
  • Knowledge of OT and industrial environments within the energy sector.
  • Scripting and automation experience using PowerShell, Python or similar technologies.
  • Experience creating operational dashboards and security reporting.
  • Experience working through ITSM/ITIL processes and partnering with service operations, infrastructure and architecture teams.

Certifications
One or more of the following certifications would be advantageous:

  • CISSP
  • GIAC GCIH
  • CompTIA Security+
  • Microsoft Security Certifications (SC-200, SC-300, SC-100)
  • CrowdStrike CCFA or CCFR
  • OSCP or equivalent offensive security certification

Communication

  • Excellent command of the English language in both oral and written communication and skills.
  • Ability to communicate technical findings and incident summaries clearly to both technical and non-technical stakeholders.

Behavior/ Core Competencies:

  • Strong technical troubleshooting and investigative skills.
  • Ability to assess cyber risk and make pragmatic risk-based decisions.
  • Excellent stakeholder management and communication skills.
  • Ability to explain technical risks to non-technical audiences.
  • Self-motivated and able to operate independently while working collaboratively across teams.
  • Strong analytical and problem-solving capability.
  • Maintains composure and effectiveness during security incidents and high-pressure situations.
  • Demonstrates ownership, accountability and continuous improvement mindset.
  • Collaborative by nature, building trusted relationships across technology and business teams.
  • Focused on outcomes and measurable risk reduction rather than tooling alone.

HSSEQ:
The Employee shall observe the Health, Safety, Sustainability, Environment and Quality rules of the Company; it’s clients and the governing authorities of the host country.
Details about the role:

  • Location: Mumbai (Hybrid, 2-3 Days a week in the Office)
  • Relocation required: No
  • Travel required: Sometimes
  • Contract type: Regular
  • Experience level: 10-15 Years

Foster a culture of equity, diversity and inclusion – a safe and respectful workplace. In addition to the responsibilities listed herein, the employee may be required to perform other ad-hoc tasks as needed or directed by the supervisor or management. These tasks will be within the reasonable scope of the employee's skills, capabilities, and role within the organization. The intent of this provision is to allow for flexibility and adaptability in meeting the dynamic needs of the organization, ensuring that operational requirements can be met efficiently. All such tasks will be assigned considering the employee's current workload and with respect to their professional development.
Kent | The Energy Within

This is an external listing. JobSpring does not represent or verify the employer. Report this listing