Nauchsoft is an international IT consulting and software development company. We have been in the IT business for 37 years and continue growing.
We are looking for Head of Cybersecurity Practice. This role is prospective and has been created in line with the company’s planned team expansion.
Head of Cybersecurity Practice is responsible for three key areas:
- Penetration Testing / Offensive Security
- Defensive Security
- Security Monitoring & SIEM
The primary mission of the role is to develop these areas into strong Cybersecurity capabilities within the company: define the strategy and roadmap, build and grow teams, increase technical maturity, introduce modern security practices, and ensure high-quality delivery of Cybersecurity services.
This role combines strategy, technical leadership, team management, and development of Cybersecurity services for clients.
Key Responsibilities
Cybersecurity Strategy & Capability Development
- Define the Cybersecurity strategy and roadmap for Penetration Testing, Defensive Security, and Security Monitoring & SIEM.
- Set goals, priorities, and key development areas for each practice.
- Align Cybersecurity capability development with current and future business and client needs.
- Develop technical expertise and the overall Cybersecurity competency portfolio within the company.
- Define required technologies, tools, methodologies, and engineering standards.
- Establish consistent technical approaches across Cybersecurity practices.
- Ensure high quality of delivery and technical solutions across all Cybersecurity services.
- Build effective collaboration between Cybersecurity and Engineering, Infrastructure, DevOps, Cloud, and other technical teams.
- Track Cybersecurity market trends, emerging threats, technologies, and practices, and introduce relevant approaches within the company.
- Define measurable goals and drive execution of the Cybersecurity roadmap.
Team Leadership
- Lead the heads/leads and teams across Penetration Testing, Defensive Security, and Security Monitoring & SIEM.
- Evolve the team structure in line with business growth and project demand.
- Participate in hiring key specialists and building strong teams.
- Develop technical leaders and strengthen expertise within each area.
- Define clear ownership, collaboration processes, and performance expectations.
- Create an environment that supports professional growth, knowledge sharing, and competency development across Cybersecurity teams.
- Set team development priorities and ensure sufficient capacity for current and future projects.
- Mentor technical leads and support them in complex technical and organizational decisions.
Penetration Testing / Offensive Security
- Develop the Penetration Testing and Offensive Security practice.
- Ensure a high technical standard across Web, API, Infrastructure, Cloud, and other types of security assessments.
- Develop and improve penetration testing methodologies and standards.
- Ensure the quality of assessment results, reporting, and client recommendations.
- Strengthen team expertise in modern attack techniques, vulnerabilities, and exploitation approaches.
- Oversee the technical quality of complex and critical security assessments.
Defensive Security
- Develop the company’s Defensive Security capabilities.
- Define and improve approaches to protecting cloud environments, infrastructure, endpoints, and corporate systems.
- Increase the security maturity of technical environments and client solutions.
- Develop security architecture and security controls within the Defensive Security practice.
- Build effective collaboration between the Defensive Security team and Engineering, DevOps, Cloud, and Infrastructure teams.
- Ensure the adoption of modern defensive security practices, hardening approaches, and vulnerability management.
Security Monitoring & SIEM
- Develop the Security Monitoring & SIEM practice.
- Define and improve approaches to monitoring, detection, and analysis of security events.
- Increase automation within Security Operations.
- Improve detection capabilities and incident analysis processes.
- Ensure effective collaboration between SIEM, Defensive Security, and Penetration Testing teams in threat detection, analysis, and prevention.
- Develop approaches to Incident Detection & Response and coordination with technical teams.
Client Engagement & Presales
- Participate in Cybersecurity presales activities and in the development of the company’s Cybersecurity service offering.
- Join discovery sessions and technical meetings with prospective and existing clients.
- Help define scope, delivery approach, team composition, and technical solutions for Cybersecurity engagements.
- Contribute to technical proposals, estimates, and solution descriptions.
- Represent the company’s Cybersecurity expertise in meetings with enterprise clients.
- Advise clients on architecture, security, and capability-related topics.
- Help shape new Cybersecurity services and offerings based on market and client needs.
What We Expect
- Strong technical background in Cybersecurity / Information Security.
- Experience leading Cybersecurity teams and/or multiple technical Security areas.
- Experience managing through technical leads would be a strong advantage.
- Good understanding of both Offensive Security and Defensive Security.
- Practical understanding of SIEM, SOC, Security Monitoring, and Incident Response.
- Experience with cloud environments and modern IT infrastructure.
- Strong understanding of modern attack techniques, vulnerabilities, and security controls.
- Experience building and developing Cybersecurity processes, methodologies, and technical standards.
- Ability to evaluate the quality of technical solutions and provide direction on complex security topics.
- Ability to operate effectively at both strategic and technical levels.
- Experience developing technical teams and leaders.
- Ability to define priorities and translate strategy into a clear roadmap and measurable results.
- Strong leadership, communication, and stakeholder management skills.
- Ability to work with clients and technical teams at senior management / technical leadership level.
- English level sufficient for working with international teams and clients.
Nice to Have
- Experience in IT outsourcing / IT services / consulting.
- Experience working with enterprise clients.
- Experience in Cybersecurity presales and shaping Cybersecurity solutions around client needs.
- Experience developing a Cybersecurity practice, competency center, or service line.
- Understanding of IT outsourcing economics, including utilization, capacity planning, project profitability, and resource management.
- Experience developing and launching new Cybersecurity services.
- Certifications such as OSCP, CISSP, CISM, GIAC, or similar.
Role Specifics
This is not a traditional CISO / GRC role. The main focus is on developing technical Cybersecurity capabilities, teams, and client-facing services.
Head of Cybersecurity Practice is not expected to be deeply hands-on in day-to-day delivery. However, the role requires sufficient technical depth to review and challenge technical decisions, participate in complex cases, set technical direction, and maintain a high level of expertise across the teams.
We offer:
- Opportunity for professional self-realization and growth.
- Friendly team.
- 25-days of paid vacation.
- Medical insurance and 100% payment for sick leave.
- Professional training and obtaining certificates at the company's expense.
- Foreign language courses and other corporate programs.
- A variety of corporate events.
- Bonuses in case of wedding or a child’s birth.
- The possibility of remote work from any location.

