|
The Senior Cyber Security Manager will lead the enterprise cybersecurity program, overseeing the design, implementation, and continuous improvement of security controls, threat detection, and incident response capabilities. This includes managing a team of security professionals, ensuring compliance with applicable regulatory and industry standards, and partnering with IT and business leaders to protect the organization's systems, data, and reputation from evolving cyber threats. ESSENTIAL JOB DUTIES:
- Develop, implement, and maintain the enterprise cybersecurity strategy, policies, and standards in alignment with business objectives and risk tolerance.
- Lead day-to-day security operations, including threat monitoring, vulnerability management, and incident detection and response.
- Manage, mentor, and develop a team of cybersecurity analysts and engineers, including performance management and professional development planning.
- Oversee the selection, configuration, and management of security technologies such as SIEM, EDR/XDR, firewalls, IDS/IPS, and data loss prevention tools.
- Lead or coordinate risk assessments, security audits, and penetration testing, and drive remediation of identified findings.
- Own the enterprise incident response plan; lead investigation, containment, and remediation of security incidents and breaches.
- Ensure compliance with applicable regulatory and industry frameworks (e.g., NIST CSF, ISO 27001, PCI DSS, HIPAA, SOC 2) and support internal/external audit activities.
- Partner with IT, application, and cloud teams to embed security requirements into infrastructure, software development, and cloud environments.
- Manage relationships with security vendors and managed security service providers, including contract and performance oversight.
- Develop and deliver security awareness training and phishing simulation programs for employees.
- Report on the organization's security posture, key risks, and metrics to executive leadership and relevant governance committees.
- Manage the cybersecurity budget, including forecasting and prioritizing investments in tools, staffing, and training.
- Other duties may be assigned.
QUALIFICATIONS: The qualifications listed below are representative of the elements required to perform the job successfully, however in some cases, an equivalent combination of Education, Training, Certifications and Experience may meet the job qualifications. Education, Training, Certifications:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field required; equivalent experience considered in lieu of degree.
- Relevant certifications such as CISSP, CISM, CISA, or GIAC/GSEC strongly preferred.
Experience, Knowledge, Skill Requirements:
- 8+ years of progressive experience in information/cybersecurity roles, including at least 3 years in a supervisory or management capacity.
- Demonstrated experience building and leading security operations, incident response, and vulnerability management programs.
- Working knowledge of security frameworks and standards, including NIST CSF, ISO 27001, and CIS Controls.
- Experience securing cloud environments (AWS, Azure, or Google Cloud) and hybrid infrastructure.
- Strong understanding of network security, identity and access management, and endpoint protection principles.
- Experience managing security budgets, vendor contracts, and cross-functional projects.
Communication Skills:
- Must have the ability to effectively read, write and communicate in English with employees and customers.
- Ability to translate complex technical security concepts into clear guidance for non-technical stakeholders and executive leadership.
Systems and Software Skills:
- Expertise with SIEM platforms such as Splunk, QRadar, or Microsoft Sentinel.
- Experience with EDR/XDR tools such as CrowdStrike, SentinelOne, or Microsoft Defender.
- Familiarity with vulnerability management platforms such as Tenable or Qualys.
- Working knowledge of firewalls, IAM/PAM solutions, and cloud-native security tools.
Other Qualifications:
- Must be able to comply with Summit Companies' Drug and Alcohol policy and Background screening requirements, which may also include customer-specific requirements based on contractual agreement.
- Occasional travel required, up to 10%.
- Ability to participate in an on-call rotation for security incident response.
PHYSICAL & WORK ENVIRONMENT REQUIREMENTS: Reasonable accommodations may be made to enable individuals with disabilities to perform Essential Job Duties. Physical Requirements: While performing the duties of this job, the employee is required to sit for long periods. Employee will occasionally be required to bend, kneel, balance, lift <20lb, walk, stand, ascend/descend stairs, drive, twist, and reach above and below shoulders. Work Environment: Employee will consistently be required to work indoors in an office setting, work alone and with others. Office settings are mild to moderate temperatures. We are fully committed to equal opportunities for employment to all individuals regardless of race, national origin, gender, religion, sexual orientation, disability, familial status, and any other classification protected under the law. We are an Equal Opportunity, Affirmative Action employer. While this job description is intended to be an accurate reflection of the position, management reserves the right to modify, add, or remove duties and to assign other duties as necessary.
|