Description
Advance Your Career and Safeguard Our Soldiers.At General Dynamics Land Systems-Canada, we pride ourselves on designing and producing the most advanced and dependable military vehicles fielded around the globe. Bring your expertise to a team that’s driving the future of defense technology. As the Global Cyber Security Operations and Risk Officer, you will help support the world-class Light Armoured vehicles (LAVS) that protect our troops in some of the toughest environments around the globe. Join us and take an active role in delivering innovative solutions that make a difference — for our soldiers, and for global security. Are you ready to make a meaningful difference? At General Dynamics Land Systems-Canada, you will have the unique opportunity to directly contribute to the safety and success of Canadian soldiers. This is more than just a career move – it’s a chance to grow professionally while playing a vital role in safeguarding those who protect us. Apply today!
Overview:This position will be the principal cyber lead for General Dynamics Land Systems-Canada (GDLS-C) and several international sites. The position reports to the Chief Information Security Officer at General Dynamics Land Systems located in Sterling Heights, Michigan. This position will perform the following core functions:
- Technical lead for security investigations and incidents across the enterprise with a particular focus on international operations, overseeing process improvements, and driving implementation of new capabilities in concert with Corporate HQ cyber strategy.
- Provide subject matter expertise and direction to the business to ensure compliance with the Canadian Program for Cyber Security Certification (CPCSC)
- Partner with enterprise IT Engineers to implement and improve technology and processes to enhance SOC monitoring, investigation, and response.
- Lead audit preparation, execution and remediation to ensure GDLS compliance with international cyber security regulations.
- Serve as an Alternate Company Security Officer for GDLS-C:
Primary Duties:
- Develop and manage a global cyber security team by setting clear goals and expectations, providing regular guidance, coaching, feedback, and professional development opportunities.
- Coordinate and oversee cyber security initiatives across GDLS global sites, ensuring the organization meets and is in compliance with GD Corporate IT Security Policies along with contract requirements and international cyber security requirements.
- Develop, assess, and implement disaster recovery plans, and conduct risk assessments to identify, mitigate, and manage cyber risks and vulnerabilities.
- Design, implement, and maintain robust network security measures to protect organizational assets.
- Adjust cyber security measures to address evolving cyber risks to the business.
- Prepare semi-annual cyber security briefs for the Executive Leadership Team at GDLS-C to inform on the threat landscape and recommend areas for improvement.
- Lead the development and implementation of cloud security strategies, ensuring the secure deployment and management of cloud-based services and infrastructure.
- Establish and maintain cyber governance frameworks and risk management practices.
- Conduct risk assessments for new software and SaaS solutions, actively collaborating as part of a larger team (bids, new contracts).
- Conduct investigations related to IT security incidents, assist in all investigations, and ensure compliance with auditing and documentation requirements as mandated by G.O.C. or customer requirements.
- Lead evidence/data gathering and documentation and assume responsibilities for all IT security matters that fall under the Corporate Security Office for GD Canada, and occasionally assist with COMSEC duties.
- Serve as an escalation resource and mentor for other cyber analysts.
- Assist in defining and driving strategic initiatives at HQ direction.
- Develop a thorough understanding of international cyber security policies and regulations that impact the business and enterprise network.
- Assists with Cyber Security audits by creating and reviewing compliance evidence and producing reports.
Required Qualifications:
Education and Experience:
- Bachelor of Science degree majoring in Computer Science, Information Assurance, or related discipline
- Information Security Training to maintain certification and subject matter expertise; commitment to continuous learning and professional development
- 10 years experience in a security role such as security operations, risk management and/or audit/compliance function
Knowledge, Skills, and Abilities:
- Demonstrated ability to think strategically and execute effectively to achieve short- and long-term objectives and ensure customer satisfaction within existing infrastructure
- Strong project management skills, including planning and executing security projects
- Superior organizational skills with the ability to be agile, set priorities, and multitask under pressure
- Expertise in operational security, cyber incident response, network security, and disaster recovery planning
- Demonstrated capability in conducting investigations related to IT Security
- Ability to support new business requirements with existing infrastructure and resources
- Proven success in researching, evaluating, and implementing new software solutions
- Ability to quickly learn new functionalities and assess their impact on the business
- Ability to identify opportunities for process improvements and implement optimization strategies
- Self-motivated and effective in a multi-disciplinary team, including facilitating discussions, agreement, and issue resolution
- Ability to meet the requirements to be appointed as an Alternate Company Security Officer
- Networking experience and understand the TCP/IP stack
- Experience with SIEM, NDR and/or EDR toolsets (log parsing and analysis skillset)
- Must be proficient with the NIST Cyber Risk Framework, NIST 800-171, and CPCSC.
- Should be familiar the following logging methods and formats: Windows, UNIX, Cisco devices, Palo Alto firewalls and various web applications.
- Eligible to work in Canada and ability to obtain a Secret Level Security Clearance.
Preferred Qualifications:
- Fifteen years serving as a cyber security manager
- Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA)
- Experience working with Canadian intelligence services or the Department of National Defence
- In-depth knowledge of Canadian Government Security Policy
- Experience working with an Industrial Security Program
- Experience conducting research on new IT functionalities related to new contracts and bids