Job Title: Head of IT Operations & Cyber Security
Location: Dublin, Ireland - Hybrid
Executive Summary
My client is seeking a Head of Information Security & Cyber Defence to hold end-to-end accountability for safeguarding their digital assets, customer platforms, and infrastructure. This role balances strategic oversight defining security frameworks, risk tolerances, and control objectives with direct, technical leadership during active cyber threats.
This is a practitioner-led position suited for a technical leader who prefers active involvement in defensive operations, incident command, and detection strategy over purely administrative governance. Serving as the primary technical security authority, this role collaborates closely with software engineering, infrastructure, and cloud platform teams to ensure security standards are embedded directly into the technical delivery lifecycle.
Responsibility
- Cyber Defence Operations: Directs internal security operations, shapes detection engineering, commands critical incident responses, and oversees managed security service providers (MSSPs). Active participation in SIEM analysis, incident bridges, and threat hunting is expected.
- Security Design Authority: Defines policies, baseline security controls, and incident response strategy across cloud services, distributed physical endpoints, and customer-facing web/mobile platforms.
- Cross-Functional Partner: Works as a technical peer alongside Architecture, Platform Engineering, and Infrastructure leads to establish actionable security benchmarks.
- Regulatory & Executive Liaison: Serves as the primary technical point of contact for external audits, regulatory assessments, and executive management updates.
The Job:
- Develop and execute a comprehensive cyber security strategy aligned with enterprise risk tolerances and technical operational goals.
- Maintain dotted-line technical authority over security architecture and engineering output-validating design blueprints, enforcing baseline controls, and reviewing architectural risk trade-offs.
- Oversee regulatory compliance for cyber resilience across European and UK operational jurisdictions, ensuring alignment with relevant statutory security standards and data protection frameworks.
- Deliver regular threat intelligence, risk posture updates, and incident reports to executive leadership and board stakeholders.
Operational Defence & Incident Command
- Lead internal threat detection and response capabilities, prioritizing detection backlogs, threat-hunting initiatives, and external MSSP deliverables.
- Command major (Severity 1) security incidents, driving containment, mitigation, regulatory notifications, and stakeholder communication.
- Steer detection engineering strategy, promoting detection-as-code principles and continuous validation of security rules.
- Oversee continuous purple-teaming programs to systematically validate and improve defensive capabilities.
- Conduct post-incident analyses to extract root causes and feed lessons back into core infrastructure and application development lifecycles.
Partner & Ecosystem Governance
- Manage third-party SOC and MSSP vendor relationships, enforcing key performance metrics, service level agreements (SLAs), and detection quality standards.
- Direct engagements with offensive security teams, external penetration testers, and emergency incident response retainers.
Technical Oversight & Security Culture
- Supervise threat modeling, vulnerability management, and security controls across identity services, transactional customer flows, and distributed operational endpoints.
- Establish baseline security specifications for cloud migrations, containerized microservices architectures, hardware refreshes, and third-party API integrations.
- Foster an operational security culture across engineering teams through pragmatic threat awareness, practical exercises, and developer-focused engagement.
Required Experience & Technical Qualifications
- Defensive Security Background: Substantial career history leading technical defensive operations (e.g., SOC Lead, Detection Engineering Lead, or Incident Response Lead) with direct experience commanding live security incidents within the past 24 months.
- SIEM/XDR & Operational Tooling: Modern, practical expertise with enterprise SIEM/XDR platforms, SOAR automation, endpoint detection and response (EDR) tuning, and log management pipelines.
- Cloud Infrastructure Depth: Strong operational understanding of public cloud security environments (specifically AWS, IAM, native security services, and container orchestration/Kubernetes threat vectors) with ability to navigate cloud consoles and CLI interfaces.
- Threat Modeling & Tradecraft: Proficiency mapping attacker tradecraft to the MITRE ATT&CK framework across cloud, identity, and application vectors.
- MSSP Oversight: Proven track record of managing outsourced SOC/MSSP partners and driving operational accountability.
- Technical Communication: Demonstrated ability to translate complex technical vulnerabilities into business risk for executive boards while maintaining technical credibility with engineering teams.
Preferred Background
- Experience operating within high-volume, highly regulated online consumer sectors (e.g., e-commerce, digital financial services, online gaming, or payments).
- Experience managing security posture across hybrid environments combining modern cloud-native architectures with legacy databases and distributed physical estates.
- Practical familiarity with enterprise identity and endpoint management stacks (e.g., Entra ID, Microsoft Defender/Intune) alongside enterprise network/endpoint security platforms.
Professional Certifications
- Hands-on practitioner certifications are preferred over purely administrative designations (e.g., GIAC credentials such as GCIH, GCFA, GNFA; offensive or practical credentials such as OSCP, CRTO; or vendor-specific XDR/SIEM practitioner certifications). Strategic certifications (CISSP, CISM) are welcome as supplementary qualifications.
- A bachelor's degree in Computer Science, Cyber Security, or a related field is helpful, but demonstrated technical capability and a track record of operational execution are prioritized.