- Company Name
- Chelsea Football Club
- Job Title
- Technology Security Manager
- Job Description
-
**Job Title:** Technology Security Manager
**Role Summary:**
Lead the strategic and operational direction of an organisation’s information and cyber security. Define security vision, embed governance, drive risk reduction across all business functions, and oversee day‑to‑day cyber defence. Report to the Director of Technology and advise senior leadership on risk, emerging threats, and technology opportunities.
**Expectations:**
- Deliver a resilient, compliant, and future‑ready security posture.
- Ensure adherence to PCI DSS, GDPR, and sector‑specific cyber requirements.
- Manage the SOC, incident response, and vulnerability management programmes to protect data, infrastructure, and services.
- Embed secure design, zero‑trust principles, and DevSecOps practices across development and cloud environments.
- Cultivate a security‑aware culture through training, awareness campaigns, and executive briefings.
**Key Responsibilities:**
1. **Strategic Leadership & Governance** – Define and evolve security strategy, develop policies, standards, and frameworks, lead risk management programmes, and provide insight to steering committees and executive sponsors.
2. **Risk and Compliance** – Maintain compliance with PCI DSS, GDPR, Premier League and other applicable regulations, oversee maturity assessments, and ensure remediation.
3. **Security Operations** – Supervise SOC providers, incident response, threat monitoring, vulnerability management, penetration testing, and endpoint, email, and identity security.
4. **Secure Technology & Development** – Champion secure design, identity and access management (MFA, privileged access, zero‑trust), SSDLC/DevSecOps adoption, and secure configuration of Azure, GCP, AWS, and Microsoft 365.
5. **Culture, Awareness and Training** – Design and deliver awareness programmes, phishing simulations, training, and onboarding education.
6. **Programme and Change Leadership** – Lead security oversight on major transformation projects, embed security in change management, and evaluate new tools and SaaS platforms.
**Required Skills:**
- Strategic thinking and risk‑based decision making.
- Deep knowledge of PCI DSS, GDPR, cyber governance frameworks and regulatory compliance.
- Experience managing SOC services, threat detection, incident response, and vulnerability/penetration testing programmes.
- Expertise in cloud security for Azure, GCP, AWS, and Microsoft 365; IAM, MFA, privileged access, and zero‑trust architecture.
- Proven ability to implement SSDLC/DevSecOps and secure development practices.
- Vendor and supplier risk management, including contractual security controls.
- Strong communication, stakeholder engagement, and executive‑level presentation skills.
- Leadership and change‑management acumen.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field.
- Professional certifications: CISSP, CISM, CISA, CRISC, or equivalent.
- Cloud‑security certifications (e.g., Microsoft Certified: Azure Security Engineer Associate, AWS Certified Security – Specialty, Google Professional Cloud Security Engineer) preferred.