- Company Name
- bpost
- Job Title
- Domain Lead Group SOC (CISO)
- Job Description
-
Job title: Domain Lead Group SOC (CISO)
Role Summary: Lead the design, execution, and governance of a centralized Security Operations Center for a multi‑entity organization. Build and scale integrated threat detection, incident response, and vulnerability management capabilities, ensuring compliance with NIS2, ISO 27001, DORA, and internal standards.
Expectations: Deliver a cohesive, auditable SOC program that reduces mean time to detect (MTTD) and mean time to recover (MTTR), maintains high-level exposure and patch compliance, and supports enterprise risk management at the executive level.
Key Responsibilities:
- Define and execute the group‑wide Threat & Response and Exposure Management strategy.
- Align with BU CISOs to establish accountability, coverage, and continuous improvement.
- Maintain regulatory and standard compliance (NIS2, ISO 27001, DORA, ISO 27k, NIST).
- Oversee daily SOC operations: monitoring, triage, incident response, post‑incident reviews.
- Integrate network, endpoint, IAM, cloud, and OT security tools into SIEM/SOAR.
- Consolidate and manage exposure platforms, leading EASM deployment and threat intelligence coordination.
- Track KPIs/KRIs (MTTD, MTTR, patch compliance, exposure reduction).
- Produce executive dashboards, incident governance reports, and budget oversight.
- Manage MSSP relationships and SOC‑related budgeting.
- Build, mentor, and lead a multidisciplinary SOC team (engineering, threat intel, vulnerability management).
- Foster cross‑entity collaboration and contribute to the Group Security Leadership Team.
Required Skills:
- 6+ years in cybersecurity operations, including 3+ in SOC/IR/vulnerability leadership.
- Deep expertise in SIEM, SOAR, EDR/XDR, threat intelligence, and EASM tools.
- Experience leading security programs across multi‑entity or international environments.
- Strong knowledge of cloud, network, endpoint, IAM, and OT security domains.
- Proficiency with ISO 27k, NIST, NIS2, and DORA frameworks.
- Crisis leadership, strategic planning, stakeholder alignment, risk prioritization.
- Excellent communication with technical and executive audiences.
- Commitment to continuous improvement and professional integrity.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (preferred).
- Relevant certifications such as CISSP, CISM, GCIA, GCIH (preferred).
---