The Role
The Cyber Security Lead is responsible for leading the design, implementation, and ongoing operation of Ascend SC’s cyber security program. This role provides hands-on technical expertise while also setting security strategy, policies, and standards in alignment with Sumitomo Corporation requirements and global best practices. You will be part of the IT Shared Services team. (A team of 13 covering all aspects of Technology for Ascend SC.) The position works closely with Infrastructure, Systems Operations, Applications, Compliance, and business stakeholders to protect enterprise systems, data, and digital supply chain solutions from cyber threats. The role is also responsible for supporting the finance team with budget tracking and stewardship for several areas.
This role serves as the senior technical authority for cyber security at Ascend SC and acts as the primary escalation point for incident response, risk assessments, identity and access governance, and security architecture decisions. This position reports to the Director of IT Shared Services and maintains relationships across the company as well as key vendors and customers.
Responsibilities
- Lead the development, implementation, and maintenance of enterprise cyber security architecture, standards, and controls.
- Serve as the primary security subject matter expert across infrastructure, cloud, application, and operational technology environments.
- Design and oversee security controls across networks, endpoints, servers, identity platforms and cloud services.
- Own the lead security incident response process, including detection, investigation, containment, remediation, and post-incident reviews.
- Conduct and oversee vulnerability management, penetration testing coordination, and enterprise risk assessments.
- Define and maintain security policies, procedures, and technical standards aligned with corporate and regulatory requirements, including JSOX and ITGC controls.
- Partner with Infrastructure, Systems Engineering, Development, and SCM solution teams to embed security-by-design into systems and digital tools.
- Oversee security monitoring, logging, reporting and alerting capabilities (SIEM/EDR); continuously improving detection and response maturity.
- Manage third-party security assessments, vendor risk reviews, and customer security questionnaires.
- Support internal and external audits and compliance activities working with our parent organization and related entities (e.g., ISO 27001, SOC, JSOX, customer security assessments).
- Lead the cyber security roadmap and budget planning in partnership with IT leadership.
- Support Financial Operations (FinOps) and coordinate with the manager of Systems Engineering to manage the Shared Services FinOps work.
- Provide guidance, mentorship, and technical leadership to other IT and infrastructure team members.
- Stay current on emerging threats, vulnerabilities, and security technologies, recommending and driving improvements as needed.
- Maintain vendor relationships and ensure Ascend SC receives the deliverables and value from the vendors.
- Provides administrative support to the finance team, including billing and budget-related activities, requiring approximately 4–8 hours per week.
Qualifications
Basic Qualifications (Must-Have)
- Bachelor’s degree in information security, Computer Science, Information Technology, or equivalent experience.
- 8+ years of progressive experience in cyber security, including hands-on technical roles.
- Hold one or more cyber security industry certifications such as CISSP, CISM, CCSP, or GIAC.
- Experience supporting global or multi-entity organizations.
- Strong experience with security architecture across on-premises, cloud (Azure or AWS or Oracle), and hybrid environments.
- Deep knowledge of network security, identity and access management, endpoint protection, and vulnerability management.
- Proven experience leading incident response and security investigations.
- Strong understanding of security frameworks and standards (e.g., NIST, ISO 27001, CIS).
- Ability to translate security risks into clear business impact for non-technical stakeholders.
- Excellent written and verbal communication skills.
- Experience with security tooling such as SIEM, EDR/XDR, IAM platforms, and cloud security posture management (CSPM).
Preferred Qualifications (Nice-to-Have)
- Familiarity with supply chain, manufacturing, or energy-sector environments.
- Prior experience contributing to or leading security strategy and roadmap development.
- Experience operating in a SAFe Agile environment using tools such as Jira.
- JSOX audit and assessment experience
Physical Requirements
- Prolonged periods of sitting or standing at a desk and working on a computer.
- Must be able to lift 20 pounds at times.
Pay: From $115,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Employee assistance program
- Health savings account
- Life insurance
- Paid time off
- Parental leave
- Retirement plan
- Tuition reimbursement
- Vision insurance
Work Location: Hybrid remote in Houston, TX 77056