IT Manager
Posted
Job Description
Overseeing and managing IT Security & Infrastructure department, including but not limited to:
IT Security & Data Protection
- Keep up-to-date with the latest cybersecurity threats and developments;
- Manage and investigate all cybersecurity alerts and notifications from cyber surveillance and threat intelligence to identify root cause and impact for effective containment, mitigation and future improvements;
- Lead, develop and drive cyber security strategies and governance to protect the IT interests of the Law Society;
- Develop, implement, maintain and peridocially review cybersecurity policies and processes;
- Conduct periodic security reviews of existing systems on their ability to provide adequate defence against the latest security threats;
- Conduct periodic vulnerability assessments and penetration tests for all critical IT systems;
- Work with external experts to implement cybersecurity solutions, and work with vendors to monitor, detect and contain cybersecurity incidents to minimise impact to the organisation;
- Work closely with system owners, system administrators, the IT team and vendors to ensure the IT security policies are strictly complied with;
- Work with IT vendors, providers and developers to ensure that IT systems acquired by or developed for the Law Society meet with the Law Society’s cybersecurity requirements;
- Work with subject matter experts and stakeholders in the development, implementation, and continued maintenance of data protection policies, practices, procedures and processes, and employee training and education;
- Work with subject matter experts to help monitor compliance with relevant data protection laws and regulations, including checking data protection policies, practices, procedures and processes, conducting audits, and notifying on any data breaches;
- Drive and conduct IT Security awareness and training like security talks, phishing simulation and incident response exercises;
- Educate and train users of the Law Society’s IT systems of the cybersecurity policies that affects their use of the IT systems;
- Investigate possible cybersecurity incidents and breaches;
- Enhance compliance processes based on ongoing evaluations of any gaps between our operations and data protection requirements;
- Interface and liaise with regulators and external parties on cybersecurity and data protection matters;
- Advise on data protection laws, regulations, guidelines and contractual obligations (alongside the Legal team)
IT Infrastructure
- Design and implement short- and long-term strategic plans to make certain network capacity meets existing and future requirements;
- Develop, implement, and maintain policies, procedures, and associated training plans for network resource administration and appropriate use;
- Coordinate training and orientation for new technology users and helps them become familiar with equipment and networks;
- Manage department budget and operational costs by conducting near and long-term financial forecasts for expanded functionality/ user base;
- Develop and maintain emergency plans to address equipment, power, or security failure to ensure preservation of technology and data;
- Identify, plan, organise and define timeline for projects and providing post implementation support;
- Work with the developers and vendors to deliver solutions on time and working with internal departments on project feasibility and budgets;
Other Duties
- Manage and develop the team through provision of leadership and support;
- Provide oversight and guidance to the team and ensure adherence to the organisation's policies and procedures;
- Coach, mentor and motivate the team members to thrive in their roles by optimising their strengths and skills; and
- Performing such duties as may designated to the Employee by the Executive Director and Chief Financial Officer from time to time.
Job Requirements
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related discipline.
- Professional certifications such as CISSP, CISM, CISA, CEH, CompTIA Security+, ISO 27001 Lead Implementer/Auditor, or equivalent will be highly advantageous.
- Minimum 8-10 years of IT experience, with at least 3-5 years in a managerial or leadership capacity overseeing IT Security and Infrastructure functions.
- Proven experience in developing and implementing cybersecurity strategies, governance frameworks, policies, and controls.
- Hands-on experience managing cybersecurity incidents, threat monitoring, vulnerability assessments, penetration testing, and risk mitigation initiatives.
- Strong understanding of cybersecurity frameworks, best practices, and security operations.
- Knowledge of network architecture, systems administration, cloud technologies, and infrastructure security.
- Familiarity with data protection requirements, compliance audits, and information security risk assessments
- Experience developing business continuity, disaster recovery, and emergency response plans.
- Strong understanding of IT governance, risk management, and compliance requirements.