Overview
IT Security Officer Dublin 7 | Hybrid, two days onsite per week | 12-Month Contract
About the Opportunity
eir business talent is partnering with a major public sector organisation responsible for delivering nationally important transport services and infrastructure across Ireland.
We are seeking an experienced IT Security Officer to support the delivery and operational readiness of a major technology modernisation programme. This is a hands-on security role working across solution design, delivery, testing, service transition and live operations.
You will work closely with security architects, ICT teams, project managers, business analysts, suppliers and operational support teams to ensure that security requirements are embedded throughout the full technology lifecycle.
The position will suit an experienced security professional with a strong background in security operations, security assurance, cloud security, technical design reviews, vulnerability management, PCI DSS, ISO 27001, NIST, operational readiness and service transition.
The Role
As IT Security Officer, you will help define and implement the operational security approach for a complex, large-scale technology environment.
You will provide security oversight across design, build, testing, deployment, transition and operational phases, ensuring solutions align with enterprise security principles, internal policies and applicable regulatory requirements.
A significant part of the position will involve reviewing technical designs, coordinating security testing and assurance activities, monitoring security risks and supporting the development of the processes, controls and documentation required for secure live operations.
Key Responsibilities
- Support the implementation, operation and governance of security controls across a major technology programme.
- Provide security oversight and assurance throughout solution design, build, testing, deployment, transition and operational phases.
- Review and assess High-Level Designs, Low-Level Designs, technical architectures, interfaces and configuration changes.
- Ensure technical solutions comply with organisational security standards, policies and security-by-design principles.
- Support the design and implementation of an Information Security Management System for service providers and operational stakeholders.
- Develop and maintain the overall information security operations plan.
- Document security processes, workflows, responsibilities and interfaces across the operational environment.
- Coordinate vulnerability management, remediation activity, security testing and penetration testing.
- Scope, engage and support independent third-party security assessments.
- Support the achievement and ongoing validation of PCI DSS certification across relevant service and network environments.
- Develop operational security processes, monitoring capabilities, incident-management procedures and security runbooks.
- Ensure security requirements are incorporated into operational readiness, service transition, disaster recovery, business continuity and support models.
- Monitor security risks, issues, threats and compliance obligations, providing practical recommendations for remediation.
- Support audits and maintain the security evidence, policies, procedures and artefacts required for governance and compliance.
- Assist with the investigation, management and escalation of security incidents.
- Support requirements traceability and contribute to User Acceptance Testing, Operational Readiness Testing and hypercare activities.
- Work closely with vendors, service providers, ICT teams and operational support functions to ensure security controls are effective and supportable after go-live.
- Provide regular security and compliance reporting to programme and ICT stakeholders.
Technical Environment
The successful candidate will provide security guidance across a broad technology environment that may include:
- AWS and cloud-hosted servers
- API gateways and API security controls
- Firewalls and Web Application Firewalls
- Network segmentation
- Application architecture
- Identity and access controls
- Security monitoring and incident management
- IoT and connected devices
- Operational technology deployed in the field
- Payment and contactless technologies
- Mobile-enabled services
- Business continuity and disaster recovery environments
Essential Experience
We are interested in speaking with candidates who can demonstrate:
- Strong experience in an IT security, security operations, information security assurance or similar position.
- Experience working on complex ICT programmes involving multiple internal and external stakeholders.
- Practical experience reviewing technical architectures, HLDs, LLDs, interfaces and configuration changes.
- Strong understanding of security-by-design principles and the secure technology lifecycle.
- Experience coordinating vulnerability assessments, remediation activities, penetration testing and security assurance.
- Experience developing operational security processes, security runbooks, monitoring procedures and incident response plans.
- Knowledge of Information Security Management Systems and security-governance frameworks.
- Experience supporting operational readiness, service transition, UAT, ORT, go-live and hypercare.
- Experience working with third-party suppliers, managed service providers and independent security-assessment partners.
- Strong understanding of cloud security, network security, application security, API security and access controls.
- Experience maintaining security policies, procedures, audit evidence and governance documentation.
- Strong stakeholder-management and communication skills, with the ability to work effectively across project, technical and operational teams.
- The ability to work independently, manage competing priorities and provide clear security recommendations.
Security and Regulatory Knowledge
Candidates should have a good working knowledge of:
- PCI DSS v4.0.1
- NIST Cybersecurity Framework
- ISO 27001:2022
- General Data Protection Regulation
- NIS2 Directive
- EU AI Act
- Relevant security, privacy and regulatory obligations affecting large-scale ICT environments
All applicants must hold a valid EU or UK passport or a Stamp 4 visa to be considered for this contract.
If you are interested in applying for this role, please do so via the relevant link. If you would like to discuss the opportunity in confidence, please apply or contact Michael Mooney at eir business talent directly at michael(dot)mooney(at)eirbusiness(dot)ie.
Candidates must be eligible to work full time and long term in the location specified or currently hold a valid appropriate long term work Visa to apply.
eir business talent, eir business and our clients are equal opportunity employers who seeks to recruit and appoint the best available person for a job regardless of marital / civil partnership status, sex (including pregnancy), age, religion, belief, race, nationality and ethnic or national origin, colour, sexual orientation or disability. eir business talent, eir business and our clients apply all relevant Data Protection laws when processing your Personal Data.
If you choose to apply to this opportunity and share your CV or other personal information with eir business talent, eir business and our clients, these details will be held by us in accordance with our privacy policy used by our recruitment team to contact you regarding this or other relevant opportunities at eir business talent and eir business.