Head of Information Security
- Location
- Not specified
- Employment
- Full-time
- Level
- Mid-level
- Category
- Security
- Posted
Description
The Defense Procurement Agency (DOT) is a state-owned enterprise responsible for procuring military equipment, ammunition, UAVs, fuel, food, clothing, and other critical supplies for the Armed Forces of Ukraine and the Defense Forces.
Our mission: Strengthening Ukraine's defense capabilities by ensuring reliable procurement and supporting the development of the national defense industry.
Our vision: To become the driving force behind a modern defense procurement ecosystem built according to NATO standards.
We are looking for a **Head of Information Security** to lead and strengthen our Information Security function across governance, engineering, and security operations. This role combines strategic leadership with hands-on technical expertise, ensuring the continuous development of our Information Security Management System (ISMS), alignment with the NIST Cybersecurity Framework, and the organization's readiness to prevent, detect, and respond to cyber threats.
What You'll Accomplish (First 6–12 Months)
Ensure continued NIST compliance for DOT Chain and define the roadmap for future security initiatives, including platforms such as Azure AI Foundry.
Strengthen the security posture of IT Enterprise by implementing and maintaining NIST security controls, establishing regular risk assessments, exception management, and vulnerability remediation processes.
Build a high-performing security organization with defined OKRs, KPIs, resource planning, and performance management.
Enhance Azure-based Security Operations by improving monitoring, incident response, vulnerability management, identity governance, and RBAC.
Lead Red Team and Purple Team exercises (including ransomware readiness and identity compromise scenarios) and translate findings into engineering improvements.
Establish vendor security governance, including security assessments, NDA/SLA/DPA requirements, and third-party security audits.
Responsibilities
Leadership & Team Management
Lead both Information Security Governance (ISMS, Risk & Compliance) and Cybersecurity Engineering & Operations.
Manage, mentor, and develop the Information Security team through structured performance management, OKRs, and individual development plans.
Collaborate closely with Engineering, IT, Product, and business stakeholders to prioritize security initiatives and protect critical services.
Governance, Risk & Compliance
Develop and maintain security policies, standards, procedures, and risk registers.
Lead internal and external security audits and coordinate remediation activities.
Drive the organization's transition toward NIST-based security practices while maintaining alignment with ISO 27001 where required.
Own Incident Response Plans (IRP), post-incident reviews, and continuous improvement.
Ensure compliance with Ukrainian legislation related to information security and personal data protection.
Security Engineering & Operations
Oversee enterprise security technologies, including:
Microsoft Sentinel
Microsoft Defender
EDR/XDR
SIEM
DLP
PAM
IAM / Microsoft Entra ID
MDM
Lead incident monitoring and response activities.
Manage vulnerability lifecycle from discovery through remediation.
Improve identity security through MFA, PIM, Least Privilege, JML processes, Key Vault, secrets management, and centralized logging.
Define and improve SOC processes, runbooks, SLAs, and operational metrics.
Application Security & Secure SDLC
Strengthen application security throughout the software development lifecycle.
Drive Threat Modeling, Security Architecture Reviews, DevSecOps practices, automated code scanning (SAST/DAST), SBOM generation, and CI/CD security.
Integrate Red/Purple Team findings into engineering roadmaps and development practices.
Vendor Security
Evaluate and audit third-party vendors integrated with DOT Chain.
Establish and maintain supplier security requirements, including NDA, SLA, DPA, and third-party security assessments.
Strategy, Reporting & Budget
Report regularly to executive leadership on security posture, KPIs, risks, vulnerability remediation, and incident readiness.
Own the Information Security budget and define a 12–18 month security roadmap with prioritized initiatives and measurable business value.
Requirements
Experience
5+ years of experience in Information Security or Cybersecurity.
3+ years leading Information Security teams and security programs.
Proven experience implementing enterprise Information Security strategies and governance.
Hands-on experience with Red Team/Purple Team exercises, attack simulations, ransomware preparedness, and identity compromise scenarios.
Strong experience implementing and maintaining NIST Cybersecurity Framework and/or ISO 27001.
Experience building or managing Security Operations (SOC/SecOps), incident response, vulnerability management, and security monitoring.
Strong Microsoft Azure security expertise, including:
Microsoft Defender for Cloud
Defender for Endpoint
Defender for Identity
Defender for Office 365
Microsoft Sentinel
Microsoft Entra ID
Azure Key Vault
Understanding of Secure SDLC, Application Security, DevSecOps, SAST/DAST, CI/CD security, Infrastructure as Code, and secret management.
Experience securing .NET and PHP application environments is an advantage.
Technical Knowledge
Strong practical knowledge of:
NIST Cybersecurity Framework (CSF 2.0)
NIST SP 800 Series
ISO/IEC 27001
Knowledge of Ukrainian regulations related to information security and personal data protection.
Leadership & Soft Skills
Strong leadership, people management, and stakeholder management skills.
Experience establishing KPIs, OKRs, and performance management frameworks.
Ability to balance strategic governance with hands-on technical leadership.
Excellent communication skills, including the ability to explain technical risks to executive stakeholders.
Strong analytical thinking and decision-making skills.
Zero tolerance for corruption.
Preferred Qualifications
CISSP
CISM
ISO 27001 Lead Implementer or Lead Auditor
Microsoft certifications such as SC-100, SC-200, SC-300, SC-400, or AZ-500.
Experience working within government organizations or other highly regulated environments.
What We Offer
Meaningful work that directly contributes to strengthening Ukraine's defense capabilities.
Official employment with competitive salary and full social benefits.
Professional development, learning opportunities, and career growth.
Structured onboarding and dedicated mentorship.
A collaborative, supportive, and mission-driven team.
Modern office near the metro with reliable internet and equipped shelter.
Opportunity to build and lead cybersecurity for one of Ukraine's most strategically important digital ecosystems.
By joining our team, you will contribute to one of Ukraine's largest digital transformation initiatives in the defense sector and help build the future of defense procurement.
Ready to make a real impact? We'd love to hear from you. Apply today!
- By submitting your CV, you consent to the processing of your personal data in accordance with applicable legislation.
- * Due to the high volume of applications, only candidates whose qualifications best match the position will be contacted.
Apply at the source
This role was published by The Defense Procurement Agency DOT and listed via Djinni. Applications are handled there, not on this site.
Original posting: https://djinni.co/jobs/835188-head-of-information-security/