HCLTech – Hungary

Tower Lead - NESSUS, Compliance Remediation

HCLTech – Hungary  •  Onsite  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Summary

Service Delivery & Operations • Own end-to-end delivery of security services (vulnerability assessment and penetration testing, threat management, identity and access management, SOC/monitoring ,GRC services) against defined SLAs, KPIs, and quality benchmarks. • Establish and mature the security delivery function, including staffing, onboarding, training, shift management, audit readiness, and governance cadences. • Supervise and coordinate response to high-severity security incidents across regions, ensuring service availability with minimal delay and business impact, and driving post-incident reviews and corrective actions. • Drive continuous improvement of delivery processes covering risk management, access control, change management, log management, backup and restoration, and SLA management. Client & Stakeholder Management • Act as the primary escalation point for clients and internal business stakeholders on security service matters. • Chair periodic service reviews and executive meetings to present security posture, open risks, incident trends, and progress on key initiatives. • Manage contract and scope discussions, support RFP responses, solutioning, effort and cost estimation, and transition planning for new engagements. • Own P&L or budget accountability for the delivery portfolio, identifying opportunities to grow revenue and optimize cost of delivery. Technical & Advisory Leadership • Provide technical direction to security architects, SOC analysts, penetration testers, and engineers; review complex security solutions and designs. • Ensure delivery aligns with security frameworks and regulatory requirements such as ISO 27001, PCI-DSS, NIST CSF, CIS Controls, and GDPR/data-privacy obligations. • Guide adoption of secure practices across on-premises and cloud environments (AWS/Azure/OCI), including cloud security posture, identity, and workload protection. • Contribute to the development and upkeep of security policies, standards, SOPs, and business continuity/disaster recovery plans. People Leadership • Build, mentor, and retain high-performing security teams; define career paths, certification roadmaps, and skills development plans. • Scale teams rapidly for new engagements while maintaining quality — including hiring, training, and knowledge management. • Foster a culture of ownership, continuous learning, and operational excellence. Required Qualifications & Experience • Bachelor's degree in Computer Science, IT, or related field (Master's degree preferred). • 12+ years of overall experience in IT/Information Security, including 5+ years managing security service delivery, SOC operations, or managed security services. • Demonstrated technical exposure across multiple cybersecurity domains: security operations and incident management, vulnerability assessment and penetration testing, infrastructure/network security, cloud security, identity and access management, and GRC. • Working knowledge of security standards and regulations: ISO 27001, PCI-DSS, CIS Controls, NIST, GDPR. • Proven experience managing large, multi-skilled teams (security architects, analysts, testers) and delivering against SLAs in a client-facing or shared-services model. • Strong commercial acumen: experience with SLAs, service reviews, effort estimation, RFPs, and budget/P&L management. • Excellent communication skills with the ability to engage both engineers and C-level executives. Preferred Certifications • One or more of: CISSP, CISM, CCSP/CCSK, CISA, ISO 27001 Lead Auditor/Implementer. • Technical certifications such as CEH, cloud security certifications (AWS/Azure/OCI security), or ITIL for service management are an advantage.

Key Responsibilities

Service Delivery & Operations • Own end-to-end delivery of security services (vulnerability assessment and penetration testing, threat management, identity and access management, SOC/monitoring ,GRC services) against defined SLAs, KPIs, and quality benchmarks. • Establish and mature the security delivery function, including staffing, onboarding, training, shift management, audit readiness, and governance cadences. • Supervise and coordinate response to high-severity security incidents across regions, ensuring service availability with minimal delay and business impact, and driving post-incident reviews and corrective actions. • Drive continuous improvement of delivery processes covering risk management, access control, change management, log management, backup and restoration, and SLA management. Client & Stakeholder Management • Act as the primary escalation point for clients and internal business stakeholders on security service matters. • Chair periodic service reviews and executive meetings to present security posture, open risks, incident trends, and progress on key initiatives. • Manage contract and scope discussions, support RFP responses, solutioning, effort and cost estimation, and transition planning for new engagements. • Own P&L or budget accountability for the delivery portfolio, identifying opportunities to grow revenue and optimize cost of delivery. Technical & Advisory Leadership • Provide technical direction to security architects, SOC analysts, penetration testers, and engineers; review complex security solutions and designs. • Ensure delivery aligns with security frameworks and regulatory requirements such as ISO 27001, PCI-DSS, NIST CSF, CIS Controls, and GDPR/data-privacy obligations. • Guide adoption of secure practices across on-premises and cloud environments (AWS/Azure/OCI), including cloud security posture, identity, and workload protection. • Contribute to the development and upkeep of security policies, standards, SOPs, and business continuity/disaster recovery plans. People Leadership • Build, mentor, and retain high-performing security teams; define career paths, certification roadmaps, and skills development plans. • Scale teams rapidly for new engagements while maintaining quality — including hiring, training, and knowledge management. • Foster a culture of ownership, continuous learning, and operational excellence. Required Qualifications & Experience • Bachelor's degree in Computer Science, IT, or related field (Master's degree preferred). • 12+ years of overall experience in IT/Information Security, including 5+ years managing security service delivery, SOC operations, or managed security services. • Demonstrated technical exposure across multiple cybersecurity domains: security operations and incident management, vulnerability assessment and penetration testing, infrastructure/network security, cloud security, identity and access management, and GRC. • Working knowledge of security standards and regulations: ISO 27001, PCI-DSS, CIS Controls, NIST, GDPR. • Proven experience managing large, multi-skilled teams (security architects, analysts, testers) and delivering against SLAs in a client-facing or shared-services model. • Strong commercial acumen: experience with SLAs, service reviews, effort estimation, RFPs, and budget/P&L management. • Excellent communication skills with the ability to engage both engineers and C-level executives. Preferred Certifications • One or more of: CISSP, CISM, CCSP/CCSK, CISA, ISO 27001 Lead Auditor/Implementer. • Technical certifications such as CEH, cloud security certifications (AWS/Azure/OCI security), or ITIL for service management are an advantage.

Skill Requirements

Service Delivery & Operations • Own end-to-end delivery of security services (vulnerability assessment and penetration testing, threat management, identity and access management, SOC/monitoring ,GRC services) against defined SLAs, KPIs, and quality benchmarks. • Establish and mature the security delivery function, including staffing, onboarding, training, shift management, audit readiness, and governance cadences. • Supervise and coordinate response to high-severity security incidents across regions, ensuring service availability with minimal delay and business impact, and driving post-incident reviews and corrective actions. • Drive continuous improvement of delivery processes covering risk management, access control, change management, log management, backup and restoration, and SLA management. Client & Stakeholder Management • Act as the primary escalation point for clients and internal business stakeholders on security service matters. • Chair periodic service reviews and executive meetings to present security posture, open risks, incident trends, and progress on key initiatives. • Manage contract and scope discussions, support RFP responses, solutioning, effort and cost estimation, and transition planning for new engagements. • Own P&L or budget accountability for the delivery portfolio, identifying opportunities to grow revenue and optimize cost of delivery. Technical & Advisory Leadership • Provide technical direction to security architects, SOC analysts, penetration testers, and engineers; review complex security solutions and designs. • Ensure delivery aligns with security frameworks and regulatory requirements such as ISO 27001, PCI-DSS, NIST CSF, CIS Controls, and GDPR/data-privacy obligations. • Guide adoption of secure practices across on-premises and cloud environments (AWS/Azure/OCI), including cloud security posture, identity, and workload protection. • Contribute to the development and upkeep of security policies, standards, SOPs, and business continuity/disaster recovery plans. People Leadership • Build, mentor, and retain high-performing security teams; define career paths, certification roadmaps, and skills development plans. • Scale teams rapidly for new engagements while maintaining quality — including hiring, training, and knowledge management. • Foster a culture of ownership, continuous learning, and operational excellence. Required Qualifications & Experience • Bachelor's degree in Computer Science, IT, or related field (Master's degree preferred). • 12+ years of overall experience in IT/Information Security, including 5+ years managing security service delivery, SOC operations, or managed security services. • Demonstrated technical exposure across multiple cybersecurity domains: security operations and incident management, vulnerability assessment and penetration testing, infrastructure/network security, cloud security, identity and access management, and GRC. • Working knowledge of security standards and regulations: ISO 27001, PCI-DSS, CIS Controls, NIST, GDPR. • Proven experience managing large, multi-skilled teams (security architects, analysts, testers) and delivering against SLAs in a client-facing or shared-services model. • Strong commercial acumen: experience with SLAs, service reviews, effort estimation, RFPs, and budget/P&L management. • Excellent communication skills with the ability to engage both engineers and C-level executives. Preferred Certifications • One or more of: CISSP, CISM, CCSP/CCSK, CISA, ISO 27001 Lead Auditor/Implementer. • Technical certifications such as CEH, cloud security certifications (AWS/Azure/OCI security), or ITIL for service management are an advantage.

Other Requirements

Service Delivery & Operations • Own end-to-end delivery of security services (vulnerability assessment and penetration testing, threat management, identity and access management, SOC/monitoring ,GRC services) against defined SLAs, KPIs, and quality benchmarks. • Establish and mature the security delivery function, including staffing, onboarding, training, shift management, audit readiness, and governance cadences. • Supervise and coordinate response to high-severity security incidents across regions, ensuring service availability with minimal delay and business impact, and driving post-incident reviews and corrective actions. • Drive continuous improvement of delivery processes covering risk management, access control, change management, log management, backup and restoration, and SLA management. Client & Stakeholder Management • Act as the primary escalation point for clients and internal business stakeholders on security service matters. • Chair periodic service reviews and executive meetings to present security posture, open risks, incident trends, and progress on key initiatives. • Manage contract and scope discussions, support RFP responses, solutioning, effort and cost estimation, and transition planning for new engagements. • Own P&L or budget accountability for the delivery portfolio, identifying opportunities to grow revenue and optimize cost of delivery. Technical & Advisory Leadership • Provide technical direction to security architects, SOC analysts, penetration testers, and engineers; review complex security solutions and designs. • Ensure delivery aligns with security frameworks and regulatory requirements such as ISO 27001, PCI-DSS, NIST CSF, CIS Controls, and GDPR/data-privacy obligations. • Guide adoption of secure practices across on-premises and cloud environments (AWS/Azure/OCI), including cloud security posture, identity, and workload protection. • Contribute to the development and upkeep of security policies, standards, SOPs, and business continuity/disaster recovery plans. People Leadership • Build, mentor, and retain high-performing security teams; define career paths, certification roadmaps, and skills development plans. • Scale teams rapidly for new engagements while maintaining quality — including hiring, training, and knowledge management. • Foster a culture of ownership, continuous learning, and operational excellence. Required Qualifications & Experience • Bachelor's degree in Computer Science, IT, or related field (Master's degree preferred). • 12+ years of overall experience in IT/Information Security, including 5+ years managing security service delivery, SOC operations, or managed security services. • Demonstrated technical exposure across multiple cybersecurity domains: security operations and incident management, vulnerability assessment and penetration testing, infrastructure/network security, cloud security, identity and access management, and GRC. • Working knowledge of security standards and regulations: ISO 27001, PCI-DSS, CIS Controls, NIST, GDPR. • Proven experience managing large, multi-skilled teams (security architects, analysts, testers) and delivering against SLAs in a client-facing or shared-services model. • Strong commercial acumen: experience with SLAs, service reviews, effort estimation, RFPs, and budget/P&L management. • Excellent communication skills with the ability to engage both engineers and C-level executives. Preferred Certifications • One or more of: CISSP, CISM, CCSP/CCSK, CISA, ISO 27001 Lead Auditor/Implementer. • Technical certifications such as CEH, cloud security certifications (AWS/Azure/OCI security), or ITIL for service management are an advantage.

HCLTech – Hungary

About HCLTech – Hungary

HCLTech is a global technology company, home to more than 226,600 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending September 2025 totaled $14.2 billion. To learn how we can supercharge progress for you, visit hcltech.com.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
Budapest, HU
Year Founded
2006
Social Media