IT Security Team Lead

Creative Capsule

United States

On-site

USD 140,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Creative Capsule is seeking an experienced Head of Information Security to lead day-to-day security operations across client projects and internal teams in the United States. You will provide practical technical leadership to address risks, incidents, vulnerabilities and control activities with timely evidence and quality.

You will mentor the IT Security team, coordinate security work with clients and stakeholders, and drive continual improvement of security controls and the compliance

Qualifications

  • Bachelor's degree in a relevant field and professional certifications where applicable.
  • Lead Implementer/Auditor per ISO 27001 preferred.
  • Industry-standard security certifications such as CISSP/CISM/CRISC/CCSP/OSCP preferred.
  • 8–12 years of information security experience, with 3+ years leading security professionals.
  • Experience in SaaS or technology services supporting regulated or data-sensitive clients.

Responsibilities

  • Translate information security and compliance strategy into operational plans and measurable initiatives.
  • Manage day-to-day security operations across endpoints, networks, cloud environments and applications.
  • Coordinate compliance activities including risk assessments, policy implementation and audits.
  • Guide application, infrastructure and cloud security through assessments, threat modelling and DevSecOps improvements.
  • Perform third-party, vendor, SaaS and subprocessor security assessments and track remediation.
  • Implement AI governance and security requirements including data-use safeguards and access controls.
  • Coordinate client security requests, due diligence, audits and defined deliverables.
  • Lead and develop the IT Security team with priorities, capacity and knowledge sharing.
  • Maintain security metrics and provide inputs for management reporting.
  • Provide risk updates and recommendations to leadership and stakeholders.
  • Promote practical security awareness and continuous improvement across teams.
  • Support onboarding and knowledge-sharing for information security roles.

Skills

Team leadership
Mentoring
Security operations
Risk management
Audits & compliance
Client engagement
Security metrics
Communication
Threat modelling
DevSecOps

Education

Bachelor's degree in Computer Science / IT / Cybersecurity
ISO/IEC 27001 Lead Implementer or Lead Auditor
CISSP / CISM / CRISC / CCSP / OSCP

Tools

SIEM
EDR
Nessus
Burp Suite
Kali Linux
Cloud security tooling
AWS
Azure
GCP
Wazuh

Job description

This position is responsible for managing the day-to-day delivery of information security activities across client projects, internal operations, compliance support and team management. The candidate will provide practical technical leadership to ensure that identified security risks, incidents, vulnerabilities and assigned control activities are assessed, communicated and addressed in a timely and proportionate manner. The role will lead and mentor the IT Security team, coordinate security work with clients and internal stakeholders, and support the operation and continual improvement of the company’s security controls and compliance programme. This person will report to the Head of Information Security and Compliance / Director of IT Services.

The person in this position will work regularly with clients, Development, QA, DevOps, Cloud, IT Systems and other business teams. The candidate will translate security and compliance priorities into team plans, coordinate delivery, monitor progress, elevate material risks and ensure that assigned security work is completed with appropriate evidence, quality and follow-through.

Responsibilities:
  • Translate the information security and compliance strategy into operational plans, team priorities and measurable improvement activities
  • Manage day-to-day security operations across endpoints, networks, cloud environments and applications, including monitoring, incident response, vulnerability management, hardening and remediation
  • Coordinate assigned compliance activities, including risk assessments, policy implementation, control operation, evidence collection, audit support and corrective-action tracking
  • Guide application, infrastructure and cloud security through assessments, penetration testing, threat modelling, secure architecture reviews and practical DevSecOps improvements
  • Perform and coordinate third-party, vendor, SaaS and subprocessor security assessments, escalating material risks and recommended safeguards
  • Implement and monitor approved AI governance and security requirements, including AI tool assessments, data-use safeguards, access controls, supplier reviews, exception tracking and escalation of material AI risks or incidents
  • Coordinate client security requests, due diligence, audits and agreed security work, ensuring clear scope, responsibilities, deliverables and follow-through
  • Lead, coach and develop the IT Security team, managing priorities, capacity, quality, knowledge sharing and succession readiness
  • Maintain operational security metrics covering incidents, vulnerabilities, control activities and remediation progress, and provide accurate inputs for management reporting
  • Provide timely risk updates, operational insights and recommendations to the Director of IT Services / Head of Information Security and Compliance and relevant stakeholders
  • Promote practical security awareness, accountability and continuous improvement across technical and business teams
  • Support interviews, onboarding, documentation and knowledge-sharing activities related to information security roles or responsibilities, when required
  • Continue to upskill in emerging information security, compliance, cloud, AI governance and secure development practices to meet changing business and client requirements
Technical Skills:
  • Experience across information security governance, security operations, risk management, incident response, vulnerability management, application security, cloud security or infrastructure security
  • Practical experience operating or materially supporting an information security and compliance programme after implementation or certification
  • Experience coordinating audits, assessments, evidence collection, remediation tracking and continual improvement activities
  • Experience engaging clients or external stakeholders on security requirements, assessments, findings and risk-based recommendations
  • Proficient in interpreting ISO 27001:2022 requirements and applying applicable legal, regulatory, contractual, industry and client security requirements
  • Proficient in using or overseeing SIEM, EDR, vulnerability scanning and application security testing tools. Exposure to Wazuh, Nessus, Burp Suite, Kali Linux or comparable tools is valuable
  • Proficient in interpreting technical findings and converting them into prioritised, practical actions for business and technical teams
  • Proficient in defining and managing security metrics, dashboards, plans, dependencies, deadlines and stakeholder expectations
  • Proficient in balancing security, compliance, delivery, usability, cost and business risk rather than applying controls mechanically
  • Good understanding of secure software development, threat modelling, cloud security and infrastructure security principles
  • Knowledge of AWS, Azure and/or GCP security practices
  • Knowledge of AI governance and security risks, including approved-use controls, data protection, access management, third‑party AI services, secure AI‑assisted development, monitoring and incident escalation
Personal Skills:
  • Ability to lead from the front while remaining comfortable with practical technical involvement when required
  • Ability to manage, mentor and motivate IT Security Engineers and establish clear ownership and accountability
  • Ability to remain calm, structured and professional during incidents, difficult client discussions and competing priorities
  • Ability to analyse complex situations, solve problems and recommend proportionate solutions
  • Ability to communicate clearly and accurately with leadership, clients, auditors and technical teams
  • Ability to challenge constructively and influence stakeholders without relying solely on authority
  • Ability to priorities short‑term operational needs and long‑term security improvement objectives under changing circumstances
  • Ability to demonstrate integrity, discretion and sound judgement when handling confidential or sensitive information
Education and Work Experience:
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity or a related discipline, or equivalent relevant experience
  • ISO/IEC 27001 Lead Implementer or Lead Auditor certification is preferred
  • A relevant security certification such as CISSP, CISM, CRISC, CCSP, OSCP or an equivalent is preferred
  • 8 to 12 years of information security experience, or an equivalent combination of relevant education and practical experience
  • At least 3 years of experience leading security professionals, security workstreams or a security function
  • Experience in a SaaS or technology services organisation supporting clients in regulated or data‑sensitive sectors is preferred
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Manager
IT Security Manager

SmartRecruiters, Inc. • Olathe (KS)

On-site
USD 90,000 - 120,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Head of Information Security — Insurance & Investments
Head of Information Security — Insurance & Investments

thehivecareers.co • San Juan (PR)

On-site
USD 180,000 - 260,000
Head of Information Security — Insurance & Investments
Head of Information Security — Insurance & Investments

thehivecareers.co • Charlotte Amalie

On-site
USD 180,000 - 280,000
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc. • Dallas (TX)

On-site
USD 90,000 - 130,000
Senior Manager, Information Security
Senior Manager, Information Security

Uniting Holding • Houston (TX)

On-site
USD 120,000 - 150,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000