Posted on: 29/06/2026
Confidential Job Posting
This role is from a verified company that prefers not to disclose its name at this stage. Learn More
Role Purpose :
The Head Cybersecurity will be responsible for defining and executing the organization's enterprise cybersecurity strategy across corporate IT infrastructure, manufacturing environments, Operational Technology (OT), cloud platforms, and digital transformation initiatives. The incumbent will establish robust security governance, mitigate cyber risks, ensure compliance with global regulatory requirements, and strengthen the organization's cyber resilience.
This role requires close collaboration with IT, Manufacturing, Engineering, Digital Transformation, Quality Assurance, Regulatory Affairs, and senior business leadership to safeguard critical business operations and intellectual property while enabling secure business growth.
Key Responsibilities :
Cybersecurity Strategy & Governance :
- Develop and execute a comprehensive enterprise cybersecurity strategy aligned with business objectives and regulatory requirements.
- Define security policies, standards, procedures, and governance frameworks across enterprise IT and OT environments.
- Build a long-term cybersecurity roadmap supporting digital transformation initiatives.
- Present cybersecurity posture, risks, and strategic recommendations to executive leadership.
- Develop security KPIs, governance dashboards, and periodic risk reports for senior management.
Enterprise Security Architecture :
- Design and maintain secure enterprise architecture covering on-premise infrastructure, cloud environments, endpoints, applications, and manufacturing systems.
- Establish Zero Trust security principles across the organization.
- Implement defense-in-depth security architecture to minimize organizational risk.
- Review infrastructure and application designs from a security perspective before deployment.
Operational Technology (OT) & Manufacturing Security :
- Lead cybersecurity initiatives for manufacturing plants, laboratory systems, and industrial control environments.
- Secure SCADA, PLCs, DCS, MES, historians, and other OT assets against cyber threats.
- Ensure secure IT-OT convergence while maintaining operational continuity.
- Collaborate with Engineering and Manufacturing teams to implement cybersecurity controls without affecting production efficiency.
- Conduct OT security assessments and vulnerability management programs.
Threat Detection, Monitoring & Incident Response :
- Establish enterprise-wide Security Operations Center (SOC) capabilities.
- Oversee SIEM, SOAR, EDR/XDR, IDS/IPS, email security, and endpoint protection platforms.
- Lead threat hunting, malware analysis, and advanced cyber threat intelligence initiatives.
- Develop incident response plans and cyber crisis management procedures.
- Lead forensic investigations and root cause analysis following security incidents.
- Conduct regular cyberattack simulations and tabletop exercises.
Vulnerability & Risk Management :
- Build enterprise vulnerability management programs covering infrastructure, applications, cloud environments, and OT systems.
- Conduct regular vulnerability assessments and penetration testing.
- Prioritize remediation based on business impact and risk exposure.
- Implement continuous security risk assessment methodologies.
- Develop enterprise cyber risk registers and mitigation plans.
- Identity & Access Management (IAM) :
- Establish enterprise Identity and Access Management policies.
- Implement least-privilege access controls and Role-Based Access Control (RBAC).
- Manage Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Single Sign-On (SSO) solutions.
- Conduct periodic user access reviews and certification exercises.
Cloud Security :
- Lead security governance across Microsoft Azure, Microsoft 365, AWS, and SaaS applications.
- Define cloud security architecture, workload protection, and secure configuration baselines.
- Ensure secure DevOps practices and cloud compliance standards.
- Monitor cloud environments for misconfigurations and unauthorized activities.
Regulatory Compliance & Audit :
- Ensure compliance with pharmaceutical regulatory requirements, data integrity standards, and global cybersecurity frameworks.
- Lead cybersecurity audits and support external regulatory inspections.
- Drive implementation and maintenance of standards including :
i. ISO 27001
ii. GAMP
iii. Data Integrity Guidelines
iv. NIST Cybersecurity Framework
v. CIS Controls
vi. GDPR (where applicable)
- Coordinate with Internal Audit, Quality Assurance, and Compliance teams to address audit findings.
Third-Party & Vendor Security :
- Establish third-party cybersecurity risk assessment programs.
- Evaluate vendors, suppliers, cloud providers, and technology partners for security compliance.
- Define cybersecurity requirements within procurement and vendor onboarding processes.
- Conduct periodic supplier security reviews.
Business Continuity & Disaster Recovery :
- Develop cybersecurity components of Business Continuity Planning (BCP) and Disaster Recovery (DR).
- Ensure resilience against ransomware, cyberattacks, and operational disruptions.
- Conduct periodic DR drills and cyber recovery exercises.
Security Awareness & Organizational Culture :
- Build a cybersecurity-first culture across the organization.
- Design enterprise security awareness programs for employees, contractors, and third-party users.
- Conduct phishing simulations and security training programs.
- Promote secure digital practices across business functions.
Leadership & Stakeholder Management :
- Lead and mentor high-performing cybersecurity teams.
- Manage relationships with technology vendors, cybersecurity consultants, and regulatory bodies.
- Collaborate with business leaders to integrate cybersecurity into strategic initiatives.
- Manage cybersecurity budgets, investments, and resource planning.
Qualifications :
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline.
- Master's degree (preferred) in Information Security, Technology Management, or Business Administration.
Preferred Certifications :
- Candidates holding one or more of the following certifications will be preferred :
i. CISSP
ii. CISM
iii. CRISC
iv. CISA
v. ISO 27001 Lead Implementer / Lead Auditor
vi. CCSP
vii. Microsoft Azure Security Engineer
viii. Certified Ethical Hacker (CEH)
ix. GIAC certifications (desirable)
Experience :
- Minimum 3 to 5 years in a leadership role managing enterprise cybersecurity functions.
- Experience within Pharmaceutical, Life Sciences, Medical Devices, Biotechnology, or highly regulated manufacturing organizations is mandatory.
- Hands-on experience securing manufacturing and Operational Technology (OT) environments.
- Proven experience managing enterprise security programs across multi-site operations.
Did you find something suspicious?
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1649319