Security Lead – AWS, SaaS, GRC, Incident Response, SOC – Europe - €80,000 - €110,000 - Remote
We are working with a phenomenal digital entertainment and technology organisation to find an experienced Security Lead to strengthen its information security framework, enhance security culture, and ensure systems, data, and people remain secure, compliant, and resilient.
You will the “go-to” person for all things security and be working directly with the CTO to help shape and drive Security Excellence throughout the organisation,. They work on an AWS platform so experience in this is essential, and you must still be able to deal with Major Security Incidents and be able to lead and remediate in a timely fashion.
This organisation has ISO27001 and CE and you will be working with the wider business to ensure that all the relevant process are adhere to, to retain these as well as looking at the strategy with the CTO to improve the all-round security within the organisation.
You will be expected to execute hands on engineering duties and incident response, the bulk of the security alerts will be manged by the help desk and a DevSecOps engineer. , you will only be called upon when there is major breach.
Key Skills
Proven experience working in an AWS environment
Experience working within a Security environment for multiple years.
Strong understanding of ISO 27001, GDPR, NIST CSF and/or NIS2.
Experience delivering security awareness programs and phishing simulations.
Have clear ideas how to improve SOC operations
Be able to communicate with multiple levels of audience from Helpdesk to CEO.
Strong understanding of ISO 27001, GDPR, NIST CSF and/or NIS2.
Experience delivering security awareness programs and phishing simulations.
Fluent in Russian
Strong English proficiency
Key Responsibilities
Partner with technology and infrastructure leadership teams to strengthen security controls.
Conduct internal audits, risk assessments and support renewals of certification.
Support DLP initiatives and maintain security-event monitoring processes.
Lead investigations into phishing, data leakage and unauthorised access incidents.
Collect and analyse digital evidence across enterprise platforms and security tools.
Collaborate with HR, Legal and IT teams during investigations.
Produce post-incident reports and remediation recommendations.
Manage MDM platforms and endpoint compliance.
Implement Just-in-Time privilege elevation and access reviews.
Maintain robust audit trails for access management.