CybersecurityJobs.io
← Back to all jobs

Job Description

Asset Living is seeking a cybersecurity leader to drive enterprise strategy, governance, and day-to-day security operations in a serverless, cloud-first Microsoft 365 environment. This role standardizes the cybersecurity program, builds a scalable security operating model, and delivers a multi-year roadmap aligned to NIST CSF 2.0 and CIS Controls v8.1.

Responsibilities

  • Lead the development, maintenance, and continuous improvement of enterprise threat detection and incident response playbooks and runbooks, covering detection, containment, mitigation, remediation, recovery, and post-incident lessons learned across the organization.
  • Drive enterprise cyber-attack preparedness and crisis readiness by aligning people, processes, technologies, and testing programs to minimize operational risk and business impact.
  • Develop, maintain, and operationalize enterprise incident response and crisis management, including response plans, tabletop exercises, recovery testing, and stakeholder communications to support rapid containment and effective decision-making.
  • Implement and optimize security awareness training using industry best practices and measurable performance metrics to reduce human risk and provide leadership visibility into awareness, engagement, and effectiveness of risk mitigation.
  • Continuously improve outsourced cybersecurity services by maturing security monitoring, threat detection and response, vulnerability management, cloud security, threat intelligence, and security validation programs to strengthen security posture.
  • Own and optimize enterprise security monitoring and protection capabilities, including EDR, ITDR, MDR, SIEM, vulnerability management, and cloud posture.
  • Oversee continuous threat exposure management through network vulnerability scanning, external penetration testing, and dark web scans.
  • Maintain visibility and control over the organization’s cloud application portfolio through continuous discovery, classification, risk evaluation, and security oversight.
  • Oversee enterprise identity and access management, driving adoption of Entra ID SSO, SCIM-based automated provisioning, and centralized identity governance across connected applications.
  • Oversee enterprise identity and access governance for both Entra-integrated and non-SSO applications, ensuring secure authentication and authorization, user lifecycle management, and periodic access reviews.
  • Develop, maintain, and annually update security policies and procedures while conducting regular tabletop exercises to validate incident response readiness, including DR, IR, and BC.
  • Oversee management and optimization of email firewalls including DMARC policy, and network firewalls with IDS/IPS.
  • Provide monthly executive reporting.
  • Build and manage clear internal cybersecurity team roles, responsibilities, and operating processes aligned with strategic MSSP partnerships.
  • Leverage deep Microsoft 365 Defender and Azure expertise to maximize security telemetry, visibility, and threat response through strategic integration of Microsoft with third-party security platforms.
  • Establish clearly defined roles, responsibilities, escalation paths, and accountability across internal teams and MSSP partners to ensure effective security operations, service delivery, continuous improvement, and organizational maturity.

Requirements

  • Relevant education in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field is preferred; equivalent professional experience will be considered.
  • 8+ years of progressive IT and cybersecurity experience.
  • 3+ years in a cybersecurity leadership role.
  • Experience leading cybersecurity transformation initiatives aligned to NIST CSF 2.0 and CIS Controls.

Technologies

  • Microsoft 365, Microsoft 365 Defender, Azure, Entra ID, Defender, Intune, Purview, SCIM
  • MSSPs, EDR, ITDR, MDR, SIEM, Vulnerability Management, Cloud Posture
  • DMARC, IDS/IPS
  • NIST CSF 2.0, CIS Controls v8.1
  • Tabletop exercises, dark web scans, external penetration testing, network vulnerability scanning
  • DR, IR, BC, security validation programs, threat intelligence

Similar Jobs