← Tillbaka till jobb

Head of Cybersecurity Operations

  • Distans
  • Sverige
  • Engelska
  • Publicerad 31.08.26 17:19

RedCore is an international business group that creates technological solutions for digital markets. Our products and services cover fintech, marketing, e-commerce, customer service, communications, and regulatory technologies. Powering Growth from the Core — this is the key mission laid under RedCore’s strong foundation. This is how we consistently stay ahead: by evolving and creating scalable solutions, while remaining committed to open and transparent communication with our partners. We're looking for a Head of Cybersecurity Operations to join our team! Requirements:- Education: Bachelor’s / Master’s degree in Computer Science, Software Engineering, or Management.- 7+ years of experience in cybersecurity, information security, or related technical security roles.- 3+ years of experience leading cybersecurity, security operations, SOC, IAM, incident response, or other security engineering teams.- Proven experience building, transforming, or significantly improving cybersecurity operational capabilities and processes. Experience implementing or improving a centralized IAM or PAM solution. Experience building or maturing a SOC function from an early-stage or fragmented operating model.- Experience working in complex technology environments with cloud, hybrid, and distributed infrastructure. Experience operating cybersecurity functions in a fast-growing, technology-driven, or multi-product organization.- Ability to translate high-level cybersecurity objectives into practical, measurable operational initiatives. Experience designing and implementing operational processes, escalation models, KPIs, SLAs, and performance metrics.- Strong practical understanding of SOC operating models, including monitoring, alert triage, investigation, escalation, incident handling, and reporting; SIEM platforms, security event correlation, detection engineering, and security analytics.- Proven results in threat hunting and the application of threat intelligence to operational security (security logging, telemetry collection, retention, and investigation requirements).- Pragmatic approach to cybersecurity, with the ability to balance security, operational efficiency, and business needs. Structured and analytical approach to complex security and operational problems.- Experience defining team structures, responsibilities, operating models, and areas of ownership, as well as setting objectives, KPIs, and measurable performance expectations for teams.- Experience in iGaming, fintech, or other regulated environments (strongly preferred).- Relevant certifications are a plus. Responsibilities:The Head of Cybersecurity Operations is responsible for leading and continuously improving the business group's cybersecurity operations and core security capabilities.The role ensures that cybersecurity controls are effectively operated and monitored with particular responsibility for the Security Operations Center (SOC) and Identity and Access Management (IAM) functions. The role works closely with the Head of Infrastructure Security, Head of Application Security, SRE & Incident Management, and other technology and business functions to ensure that cybersecurity risks are identified, detected, contained, and addressed in a coordinated manner. 1. Cybersecurity Operations Leadership- Define and continuously improve the cybersecurity operating model, processes, responsibilities, and operational standards.- Ensure effective coordination between SOC, IAM, Infrastructure Security, Application Security, SRE, and other relevant teams.- Establish clear ownership and escalation paths for security events, incidents, vulnerabilities, and access-related risks. Define cybersecurity-specific escalation procedures and ensure appropriate stakeholders are involved.- Ensure cybersecurity operations are aligned with the organization's security strategy, risk appetite, regulatory obligations, and business priorities. Ensure that operational cybersecurity requirements are clearly communicated to relevant teams and translated into actionable technical and organizational requirements.- Build a scalable cybersecurity operational model capable of supporting a growing portfolio of products, platforms, business domains, and geographical locations. - Continuously improve the efficiency, scalability, and maturity of cybersecurity operations. 2. Security Operations Center (SOC)- Define the SOC operating model, including monitoring, alert triage, investigation, escalation, incident handling, and reporting.- Ensure effective monitoring of relevant infrastructure, systems, identities, endpoints, cloud environments, and security events. Ensure appropriate security telemetry is collected, retained, and available for investigation.- Ensure security events are properly investigated, documented, prioritized, escalated, and resolved. Ensure security incidents are properly classified based on severity, impact, scope, and risk.- Define and continuously improve detection rules, use cases, alerting logic, and threat detection capabilities. Drive threat hunting and proactive identification of suspicious activity and security weaknesses. Ensure emerging threats and relevant threat intelligence are incorporated into security monitoring and detection activities where appropriate.- Ensure lessons learned from security incidents are translated into improvements in detection, controls, processes, and architecture. Track remediation activities resulting from cybersecurity incidents and ensure appropriate ownership and follow-through. 3. Identity and Access Management (IAM)- Define and maintain the organization's access management principles, processes, and operational standards.- Ensure appropriate identity lifecycle management, including onboarding, role changes, access modification, and offboarding. Establish and maintain effective processes for access provisioning, approval, review, and revocation.- Ensure the principle of least privilege is applied across corporate systems, infrastructure, cloud environments, and relevant platforms. Oversee privileged access management and controls for administrative, production, and other high-risk access.- Drive regular access reviews and recertification processes for critical systems and privileged accounts.- Identify and address excessive, unnecessary, orphaned, shared, or otherwise risky access.- Drive automation and standardization of IAM processes where appropriate. Drive automation of repetitive security operations and access management activities. 4. Leadership & People Management- Lead and develop the SOC and IAM teams.- Define team structure, roles, career paths, and competency development.- Hire, mentor, and retain high-performing security engineers and leaders. Build the capabilities required to support a mature and scalable cybersecurity operation.- Establish team objectives, KPIs, and performance metrics. Establish clear goals, performance expectations, and development plans for team members. Benefits:• An exciting and challenging job in a fast-growing business group, the opportunity to be part of a multicultural team of top professionals in Development, Architecture, Management, Operations, Marketing, Legal, Finance, and more• Great working atmosphere with passionate experts and leaders, sharing a friendly culture and a success-driven mindset is guaranteed• Modern corporate equipment based on macOS or Windows, and additional equipment is provided• Paid vacations, sick leave, personal event days, days off• Corporate health insurance program for your well-being• Referral program - enjoy cooperation with your colleagues and get a bonus;• Educational programs: regular internal training sessions, compensation for external education, attendance at specialized global conferences• Rewards program for mentoring and coaching colleagues• In-house Travel Service• Multiple internal activities: online platform for employees with quests, gamification, presents and news, RedCore clubs for movie / book / pets lovers, special office days dedicated to holidays• Corporate events, team buildings