About the Role
Transmed is looking for an experienced and highly skilled IT Security Lead to join its Information Technology team. The successful candidate will play a key role in safeguarding Transmed’s business infrastructure, systems, data, and services against evolving security threats.
The IT Security Lead will be responsible for supporting and leading information security programs, projects, controls, and initiatives while ensuring the organization maintains a strong security posture and complies with applicable security policies, standards, audits, and regulatory requirements.
This role requires a strong combination of technical cybersecurity expertise, risk management capabilities, incident response experience, project management skills, and stakeholder management. The successful candidate will work closely with IT teams, business stakeholders, external partners, and senior management to identify security risks, implement appropriate controls, and continuously improve the organization's security environment.
Key Responsibilities:
Identity & Access Management
- Develop, implement, and maintain Identity and Access Management (IAM) processes, solutions, and technologies.
- Establish and enforce appropriate access controls across systems, applications, infrastructure, and business environments.
- Oversee user provisioning, modification, and deprovisioning procedures.
- Ensure access rights are aligned with business requirements and security policies.
Security Governance, Risk & Compliance
- Establish, maintain, and enforce information security policies, procedures, standards, and controls.
- Ensure compliance with applicable industry standards and regulations, including ISO 27001 and other relevant frameworks.
- Identify, assess, and prioritize information security risks and vulnerabilities.
- Develop and implement effective risk mitigation strategies and security controls.
- Coordinate and participate in internal and external security audits and assessments.
- Track audit findings and ensure appropriate remediation actions are implemented.
Vulnerability Management & Security Testing
- Lead and coordinate vulnerability assessments and penetration testing activities.
- Review security testing results, identify vulnerabilities, and work with relevant IT and business teams to ensure timely remediation.
- Monitor security testing trends and identify opportunities to strengthen the overall security posture.
- Support security patch management by identifying, testing, coordinating, and deploying security patches and updates.
- Ensure compliance with established patch management policies and schedules.
Security Monitoring & Incident Response
- Monitor and analyze security logs, alerts, and events to identify suspicious or anomalous activities.
- Manage and support Security Information and Event Management (SIEM) processes.
- Develop, maintain, and continuously improve security incident response procedures and workflows.
- Lead the investigation, containment, resolution, and documentation of security incidents.
- Collaborate with IT and business stakeholders to investigate and mitigate security incidents.
- Conduct post-incident reviews and implement lessons learned to improve future incident response capabilities.
- Own and support business IT security incident response actions, procedures, and service-level requirements.
Infrastructure, Network & Endpoint Security
- Collaborate with network and infrastructure teams to configure, maintain, and optimize firewalls and intrusion detection/prevention systems.
- Monitor and analyze firewall and IDS/IPS logs for potential security incidents and policy violations.
- Support the selection, deployment, configuration, and management of security technologies, including firewalls, endpoint protection, antivirus solutions, intrusion detection systems, and other security platforms.
- Deploy, maintain, and regularly update endpoint protection software and security policies.
- Ensure security systems and controls are properly configured, maintained, and updated.
Data Protection & Cryptography
- Implement and maintain appropriate encryption mechanisms to protect sensitive information both at rest and in transit.
- Work closely with IT and business teams to ensure appropriate encryption, access control, and data protection configurations.
- Apply security best practices related to cryptography, security protocols, and data protection.
Business Continuity & Security Drills
- Plan and execute security drills and simulations to evaluate incident response and disaster recovery procedures.
- Monitor and document the results of security exercises and identify areas for improvement.
- Support continuous improvement of organizational resilience and security response capabilities.
Security Projects & Technology Management
- Support the evaluation, selection, implementation, and management of information security technologies and solutions.
- Lead or contribute to security projects, ensuring deliverables and milestones are achieved on time, within budget, and according to business requirements.
- Support third-party security assessments and vendor selection processes.
- Contribute to IT security budget planning, cost control, and effective allocation of security resources.
Reporting & Stakeholder Management
- Prepare and present security reports, risk assessments, incident updates, and security performance information to IT leadership and senior business stakeholders.
- Communicate security risks, technical issues, and recommended solutions clearly to both technical and non-technical audiences.
- Work closely with business partners, IT teams, suppliers, and external stakeholders to ensure security requirements are effectively understood and implemented.
Security Awareness
- Promote a strong security-conscious culture across the organization.
- Support and deliver information security awareness initiatives, training, and campaigns.
- Collaborate with HR and Communications teams to promote security best practices and employee awareness.
Key Requirements:
- Bachelor’s degree or diploma in Cybersecurity, Information Security, Computer Science, Information Systems, or a related discipline.
- 8+ years of professional experience in information security, cybersecurity, or IT security services within an enterprise environment.
- Proven experience in IT security leadership, coordination, or managerial-level responsibilities.
- Strong experience implementing and managing IT security solutions within large organizations or complex business environments.
- Strong understanding of infrastructure security, network security, cloud security, operating system security, application security, and risk management.
- Solid experience in Identity and Access Management (IAM).
- Strong knowledge of vulnerability assessment and penetration testing methodologies and tools.
- Practical experience in incident response, security investigations, and forensics.
- Strong knowledge of encryption, cryptography, and security protocols.
- Experience with SIEM, firewalls, IDS/IPS, endpoint protection, and other security technologies.
- Strong understanding of information security standards, governance, risk, and compliance.
- Experience with project management, including managing deliverables, milestones, timelines, budgets, and quality requirements.
- Experience in FMCG business applications and processes is preferred.
- Professional certifications such as CISSP, CISA, or CCSP are preferred.
- Strong English communication skills are required.
Core Competencies:
- Analytical and risk-based thinking
- Strong problem-solving and decision-making abilities
- Incident management and crisis-response capabilities
- Project management and organizational skills
- Strong communication and stakeholder management
- Ability to communicate complex technical concepts to non-technical stakeholders
- Attention to detail and strong documentation skills
- Ability to prioritize and manage multiple security initiatives simultaneously
- Teamwork and collaboration
- Proactive approach to identifying and addressing security risks
- Strong interpersonal and networking skills
- Ability to adapt to evolving technologies, threats, and business requirements
- Strong commitment to security, confidentiality, data integrity, and compliance
What We’re Looking For
We are looking for a security professional who can combine hands-on technical knowledge with strong leadership, risk management, and business awareness. The ideal candidate should be comfortable working across infrastructure, networks, cloud environments, applications, and business functions while effectively communicating security requirements and risks to stakeholders at different levels.
If you have extensive experience in information security and are ready to take ownership of security initiatives within a dynamic enterprise environment, we encourage you to apply.
Apply now and join Transmed’s IT team.
Hiring #ITSecurity #CyberSecurity #InformationSecurity #SecurityLead #CybersecurityJobs #ITJobs #IAM #SIEM #RiskManagement #IncidentResponse