Security Lead / Security Engineer
Job description
About the role
This position combines strategic oversight with hands-on implementation to advance information security maturity. You will define priorities, manage security operations, and collaborate with technology and business functions. The role requires senior judgment grounded in technical detail.
Key facts
What you'll do
Defining and owning information security processes, including risk assessment, control implementation, and continuous improvement across the organization.
Maintaining and evolving the ISO/IEC 27001:2022 Information Security Management System, conducting internal audits, risk assessments, and supporting certification activities.
Updating security policies, standards, and procedures to align with ISO 27001, GDPR, NIST CSF, and NIS2 requirements.
Managing security tools and monitoring capabilities to ensure visibility into endpoints, identities, cloud services, and user activity.
Reviewing and tuning security alerts to reduce noise, improve detection accuracy, and strengthen the security monitoring posture.
Maintaining centralized logging, evidence collection, and tracking of security events to support investigations and compliance.
Partnering with technology and business teams to integrate security controls into infrastructure, SaaS platforms, and endpoint environments.
Leading investigations into phishing, data leakage, unauthorized access, and endpoint compromise, and collecting digital evidence from relevant systems.
Developing, maintaining, and improving incident response playbooks, escalation paths, and communication procedures.
Producing clear post-incident reports that document root cause, impact, timeline, remediation, and preventive measures.
Driving security awareness and a security-first mindset by explaining risks and controls to non-technical stakeholders in clear, actionable terms.
Requirements
6 or more years of hands-on experience in information security, security engineering, incident response, or security operations.
Demonstrated experience with security tooling including SIEM, EDR, MDM, DLP, IAM, SSO, MFA, and access management platforms.
Practical background in incident response and security investigations, including evidence handling, analysis, documentation, and remediation.
Strong understanding of ISO/IEC 27001, GDPR, NIST CSF, and NIS2 principles and their application in real-world environments.
Proven ability to own or enhance security controls, policies, processes, and strategic roadmaps.
Self-directed work style with the ability to prioritize tasks, make sound security decisions, and operate effectively in a fast-paced environment.
Responsibilities specifics
Security Ownership & Roadmap
- Own and continuously refine Playson's information security processes, controls, and roadmap.
- Identify security gaps, define priorities, and drive practical improvements across the organization.
- Collaborate with CTO, Head of IT, DevOps, HR, Legal, and IT teams on security initiatives.
- Translate complex security risks into clear business language, priorities, and measurable actions.
- Define and monitor security KPIs to provide leadership with actionable visibility.
- Promote and reinforce a security-first culture throughout the organization.
Information Security & Compliance
- Maintain and advance the ISO/IEC 27001:2022 ISMS, including internal audits, risk assessments, gap analyses, and certification support.
- Update policies, procedures, and controls in line with ISO 27001, GDPR, NIST CSF, and NIS2.
- Document risks, incidents, corrective actions, and control improvements to ensure ongoing compliance.
- Support Data Loss Prevention initiatives and maintain central tracking of security events.
- Ensure security processes are practical, clearly documented, and embedded into everyday operations.
Security Operations, SIEM & Tooling
- Manage integrations, alerting, and monitoring for platforms such as Datadog SIEM, CrowdStrike, Cloudflare, and Google Workspace.
- Enhance visibility across endpoints, access controls, cloud and SaaS tools, and user activity.
- Refine security alerts to reduce noise and strengthen detection quality.
- Maintain central logging and ensure reliable security event tracking and evidence collection.
- Collaborate with DevOps and IT to strengthen security across infrastructure, endpoints, and SaaS environments.
Incident Response & Investigations
- Lead investigations into security incidents such as phishing, data leakage, suspicious user activity, and endpoint compromise.
- Collect, analyze, and document digital evidence using systems such as CrowdStrike, Cloudflare, Google Workspace, Slack, and internal tools.
- Maintain and improve incident response playbooks, escalation paths, and communication workflows.
- Coordinate with HR, Legal, IT, and relevant business teams during internal investigations.
- Produce detailed post-incident reports with root cause, impact, timeline, remediation, and prevention recommendations.
Endpoint, Identity & Access Security
- Manage MDM systems such as Zoho MDM and Endpoint Central with a focus on macOS endpoint compliance.
- Maintain CrowdStrike Falcon configurations and improve endpoint security posture.
- Oversee SSO, MFA, and 2FA enforcement across services including Google SSO, DUO Mobile, and 1Password.
- Implement and refine Just-in-Time privilege elevation, privileged access controls, and admin access reviews.
- Conduct regular access management reviews and maintain a consistent access audit trail.
- Improve access governance, onboarding and offboarding security, and SaaS access controls.
Nice to have
Significant experience improving security controls, policies, and processes relevant to organizational operations and maturity.
Skills and tools
ISO/IEC 27001; GDPR; NIST CSF; NIS2; Datadog SIEM; CrowdStrike; Cloudflare; Google Workspace; 1Password; DUO Mobile; Zoho MDM.