Head of Cybersecurity Operations
The Head of Cybersecurity Operations is responsible for leading and continuously improving the business group's cybersecurity operations and core security capabilities. The role ensures that cybersecurity controls are effectively operated and monitored with particular responsibility for the Security Operations Center (SOC) and Identity and Access Management (IAM) functions.
The role works closely with the Head of Infrastructure Security, Head of Application Security, SRE & Incident Management, and other technology and business functions to ensure that cybersecurity risks are identified, detected, contained, and addressed in a coordinated manner.
- Define and continuously improve the cybersecurity operating model, processes, responsibilities, and operational standards.
- Ensure effective coordination between SOC, IAM, Infrastructure Security, Application Security, SRE, and other relevant teams.
- Establish clear ownership and escalation paths for security events, incidents, vulnerabilities, and access-related risks.
- Define cybersecurity-specific escalation procedures and ensure appropriate stakeholders are involved.
- Ensure cybersecurity operations are aligned with the organisation's security strategy, risk appetite, regulatory obligations, and business priorities.
- Ensure that operational cybersecurity requirements are clearly communicated to relevant teams and translated into actionable technical and organisational requirements.
- Build a scalable cybersecurity operational model capable of supporting a growing portfolio of products, platforms, business domains, and geographical locations.
- Continuously improve the efficiency, scalability, and maturity of cybersecurity operations.
- Define the SOC operating model, including monitoring, alert triage, investigation, escalation, incident handling, and reporting.
- Ensure effective monitoring of relevant infrastructure, systems, identities, endpoints, cloud environments, and security events.
- Ensure appropriate security telemetry is collected, retained, and available for investigation.
- Ensure security events are properly investigated, documented, prioritised, escalated, and resolved.
- Ensure security incidents are properly classified based on severity, impact, scope, and risk.
- Define and continuously improve detection rules, use cases, alerting logic, and threat detection capabilities.
- Drive threat hunting and proactive identification of suspicious activity and security weaknesses.
- Ensure emerging threats and relevant threat intelligence are incorporated into security monitoring and detection activities where appropriate.
- Ensure lessons learned from security incidents are translated into improvements in detection, controls, processes, and architecture.
- Track remediation activities resulting from cybersecurity incidents and ensure appropriate ownership and follow-through.
- Define and maintain the organisation's access management principles, processes, and operational standards.
- Ensure appropriate identity lifecycle management, including onboarding, role changes, access modification, and offboarding.
- Establish and maintain effective processes for access provisioning, approval, review, and revocation.
- Ensure the principle of least privilege is applied across corporate systems, infrastructure, cloud environments, and relevant platforms.
- Oversee privileged access management and controls for administrative, production, and other high-risk access.
- Drive regular access reviews and recertification processes for critical systems and privileged accounts.
- Identify and address excessive, unnecessary, orphaned, shared, or otherwise risky access.
- Drive automation and standardisation of IAM processes where appropriate.
- Drive automation of repetitive security operations and access management activities.
- Lead and develop the SOC and IAM teams.
- Define team structure, roles, career paths, and competency development.
- Hire, mentor, and retain high-performing security engineers and leaders.
- Build the capabilities required to support a mature and scalable cybersecurity operation.
- Establish team objectives, KPIs, and performance metrics.
- Establish clear goals, performance expectations, and development plans for team members.
- Proven experience building, transforming, or significantly improving cybersecurity operational capabilities and processes. (required)
- Experience implementing or improving a centralised IAM or PAM solution. (required)
- Experience building or maturing a SOC function from an early-stage or fragmented operating model. (required)
- Experience working in complex technology environments with cloud, hybrid, and distributed infrastructure. (required)
- Experience operating cybersecurity functions in a fast-growing, technology-driven, or multi-product organisation. (required)
- Ability to translate high-level cybersecurity objectives into practical, measurable operational initiatives. (required)
- Experience designing and implementing operational processes, escalation models, KPIs, SLAs, and performance metrics. (required)
- Strong practical understanding of SOC operating models, including monitoring, alert triage, investigation, escalation, incident handling, and reporting; SIEM platforms, security event correlation, detection engineering, and security analytics. (required)
- Proven results in threat hunting and the application of threat intelligence to operational security (security logging, telemetry collection, retention, and investigation requirements). (required)
- Pragmatic approach to cybersecurity, with the ability to balance security, operational efficiency, and business needs. (required)
- Structured and analytical approach to complex security and operational problems. (required)
- Experience defining team structures, responsibilities, operating models, and areas of ownership, as well as setting objectives, KPIs, and measurable performance expectations for teams. (required)
- Bachelor’s / Master’s degree in Computer Science, Software Engineering, or Management. (required)
- 7+ years of experience in cybersecurity, information security, or related technical security roles. (required)
- 3+ years of experience leading cybersecurity, security operations, SOC, IAM, incident response, or other security engineering teams. (required)
- Experience in iGaming, fintech, or other regulated environments. (preferred)
- Relevant certifications are a plus. (nice-to-have)
- Strong decision-making skills, particularly during security incidents and high-risk situations. (required)
- Strong ownership and accountability for outcomes. (required)
- Ability to prioritise effectively in a high-volume and rapidly changing environment. (required)
- Exceptional communication skills with ability to lead under pressure. (required)
- Strategic thinker able to balance business needs with risk management. (required)
- Strong communication and mentoring skills; ability to lead, motivate, and mentor a team. (required)
- An exciting and challenging job in a fast-growing business group.
- The opportunity to be part of a multicultural team of top professionals in Development, Architecture, Management, Operations, Marketing, Legal, Finance and more.
- Great working atmosphere with passionate experts and leaders, sharing a friendly culture and a success-driven mindset.
- Beautiful offices in Warsaw, Limassol, Yerevan - work remotely or on-site with comfort and enjoy the opportunity to build a network of connections with professionals day by day.
- Modern corporate equipment based on macOS or Windows and additional equipment are provided.
- Paid vacations, sick leave, personal events days, days off.
- Corporate health insurance program for your well-being.
- Referral program - enjoy cooperation with your colleagues and get the bonus.
- Educational programs: regular internal training sessions, compensation for external education, attendance of specialized global conferences.
- Rewards program for mentoring and coaching colleagues.
- Sport benefit.
- In-house Travel Service.
- Multiple internal activities: online platform for employees with quests, gamification, presents and news, RedCore clubs for movie / book / pets lovers, special office days dedicated to holidays.
- Company events, team buildings.
PIN-UP Global is an international holding company that develops technologies, B2B solutions and products for the iGaming industry. Headquartered in Warsaw, the group brings together businesses spanning product development, technology and marketing services for online gaming. It supports a portfolio of companies and brands operating across multiple markets. PIN-UP Global focuses on building advanced technology and products for the gambling sector.