Head of Information Security

The Defense Procurement Agency DOT

Location
Not specified
Employment
Full-time
Level
Mid-level
Category
Security
Posted

Description

The Defense Procurement Agency (DOT) is a state-owned enterprise responsible for procuring military equipment, ammunition, UAVs, fuel, food, clothing, and other critical supplies for the Armed Forces of Ukraine and the Defense Forces.

Our mission: Strengthening Ukraine's defense capabilities by ensuring reliable procurement and supporting the development of the national defense industry.

Our vision: To become the driving force behind a modern defense procurement ecosystem built according to NATO standards.

We are looking for a **Head of Information Security** to lead and strengthen our Information Security function across governance, engineering, and security operations. This role combines strategic leadership with hands-on technical expertise, ensuring the continuous development of our Information Security Management System (ISMS), alignment with the NIST Cybersecurity Framework, and the organization's readiness to prevent, detect, and respond to cyber threats.

What You'll Accomplish (First 6–12 Months)

Ensure continued NIST compliance for DOT Chain and define the roadmap for future security initiatives, including platforms such as Azure AI Foundry.

Strengthen the security posture of IT Enterprise by implementing and maintaining NIST security controls, establishing regular risk assessments, exception management, and vulnerability remediation processes.

Build a high-performing security organization with defined OKRs, KPIs, resource planning, and performance management.

Enhance Azure-based Security Operations by improving monitoring, incident response, vulnerability management, identity governance, and RBAC.

Lead Red Team and Purple Team exercises (including ransomware readiness and identity compromise scenarios) and translate findings into engineering improvements.

Establish vendor security governance, including security assessments, NDA/SLA/DPA requirements, and third-party security audits.

Responsibilities

Leadership & Team Management

Lead both Information Security Governance (ISMS, Risk & Compliance) and Cybersecurity Engineering & Operations.

Manage, mentor, and develop the Information Security team through structured performance management, OKRs, and individual development plans.

Collaborate closely with Engineering, IT, Product, and business stakeholders to prioritize security initiatives and protect critical services.

Governance, Risk & Compliance

Develop and maintain security policies, standards, procedures, and risk registers.

Lead internal and external security audits and coordinate remediation activities.

Drive the organization's transition toward NIST-based security practices while maintaining alignment with ISO 27001 where required.

Own Incident Response Plans (IRP), post-incident reviews, and continuous improvement.

Ensure compliance with Ukrainian legislation related to information security and personal data protection.

Security Engineering & Operations

Oversee enterprise security technologies, including:

Microsoft Sentinel

Microsoft Defender

EDR/XDR

SIEM

DLP

PAM

IAM / Microsoft Entra ID

MDM

Lead incident monitoring and response activities.

Manage vulnerability lifecycle from discovery through remediation.

Improve identity security through MFA, PIM, Least Privilege, JML processes, Key Vault, secrets management, and centralized logging.

Define and improve SOC processes, runbooks, SLAs, and operational metrics.

Application Security & Secure SDLC

Strengthen application security throughout the software development lifecycle.

Drive Threat Modeling, Security Architecture Reviews, DevSecOps practices, automated code scanning (SAST/DAST), SBOM generation, and CI/CD security.

Integrate Red/Purple Team findings into engineering roadmaps and development practices.

Vendor Security

Evaluate and audit third-party vendors integrated with DOT Chain.

Establish and maintain supplier security requirements, including NDA, SLA, DPA, and third-party security assessments.

Strategy, Reporting & Budget

Report regularly to executive leadership on security posture, KPIs, risks, vulnerability remediation, and incident readiness.

Own the Information Security budget and define a 12–18 month security roadmap with prioritized initiatives and measurable business value.

Requirements

Experience

5+ years of experience in Information Security or Cybersecurity.

3+ years leading Information Security teams and security programs.

Proven experience implementing enterprise Information Security strategies and governance.

Hands-on experience with Red Team/Purple Team exercises, attack simulations, ransomware preparedness, and identity compromise scenarios.

Strong experience implementing and maintaining NIST Cybersecurity Framework and/or ISO 27001.

Experience building or managing Security Operations (SOC/SecOps), incident response, vulnerability management, and security monitoring.

Strong Microsoft Azure security expertise, including:

Microsoft Defender for Cloud

Defender for Endpoint

Defender for Identity

Defender for Office 365

Microsoft Sentinel

Microsoft Entra ID

Azure Key Vault

Understanding of Secure SDLC, Application Security, DevSecOps, SAST/DAST, CI/CD security, Infrastructure as Code, and secret management.

Experience securing .NET and PHP application environments is an advantage.

Technical Knowledge

Strong practical knowledge of:

NIST Cybersecurity Framework (CSF 2.0)

NIST SP 800 Series

ISO/IEC 27001

Knowledge of Ukrainian regulations related to information security and personal data protection.

Leadership & Soft Skills

Strong leadership, people management, and stakeholder management skills.

Experience establishing KPIs, OKRs, and performance management frameworks.

Ability to balance strategic governance with hands-on technical leadership.

Excellent communication skills, including the ability to explain technical risks to executive stakeholders.

Strong analytical thinking and decision-making skills.

Zero tolerance for corruption.

Preferred Qualifications

CISSP

CISM

ISO 27001 Lead Implementer or Lead Auditor

Microsoft certifications such as SC-100, SC-200, SC-300, SC-400, or AZ-500.

Experience working within government organizations or other highly regulated environments.

What We Offer

Meaningful work that directly contributes to strengthening Ukraine's defense capabilities.

Official employment with competitive salary and full social benefits.

Professional development, learning opportunities, and career growth.

Structured onboarding and dedicated mentorship.

A collaborative, supportive, and mission-driven team.

Modern office near the metro with reliable internet and equipped shelter.

Opportunity to build and lead cybersecurity for one of Ukraine's most strategically important digital ecosystems.

By joining our team, you will contribute to one of Ukraine's largest digital transformation initiatives in the defense sector and help build the future of defense procurement.

Ready to make a real impact? We'd love to hear from you. Apply today!

  • By submitting your CV, you consent to the processing of your personal data in accordance with applicable legislation.
  • * Due to the high volume of applications, only candidates whose qualifications best match the position will be contacted.

Apply at the source

This role was published by The Defense Procurement Agency DOT and listed via Djinni. Applications are handled there, not on this site.

View & apply on djinni.co ↗