Information Security Manager responsible for ensuring security of data, systems, and networks at Cayuse. Leading development and monitoring of security policies, practices, and controls.
Responsibilities
Develop, implement, and continuously improve organizational information security policies, standards, and procedures.
Ensure alignment of security policies with organizational goals, regulatory requirements, and industry best practices (e.g., NIST, ISO 27001).
Monitor and enforce compliance with security standards for staff and third-party vendors.
Conduct regular audits, gap analyses, and performance assessments of security policies and controls, addressing deficiencies and making recommendations.
Conduct periodic risk assessments for IT systems, infrastructure, and vendors to identify vulnerabilities, threats, and weaknesses.
Work with internal teams to mitigate known vulnerabilities and prioritize remediation strategies.
Utilize vulnerability scanning tools and methodologies to proactively safeguard systems.
Supervise the management and monitoring of security information and event management (SIEM) systems to promptly detect and respond to security breaches.
Direct security incident response efforts, including managing containment, analysis, and remediation actions, and leading post-incident investigations.
Analyze root causes of security violations and design proactive measures to prevent recurrence.
Collaborate with cybersecurity teams, IT departments, and third-party vendors in supporting a robust incident response process.
Oversee configuration, management, and monitoring of security systems, such as firewalls, intrusion detection/prevention systems, encryption protocols, and antivirus software.
Safeguard sensitive data by managing access controls and permissions, ensuring compliance with data protection regulations such as GDPR, HIPAA, and CCPA.
Implement and enforce secure protocols for data at rest, in transit, and during processing.
Develop and deliver ongoing cybersecurity awareness and training programs to all organizational employees.
Advocate for a security-first culture by providing guidance and resources to non-technical teams.
Conduct phishing simulations and other exercises to assess and improve employee preparedness.
Ensure compliance with relevant laws, regulations, and standards, such as SOC 2, PCI DSS, FISMA, or other industry-specific requirements.
Maintain detailed documentation and prepare reports for stakeholders, auditors, and regulatory organizations.
Requirements
1-3 years of experience in the field for Level 1
4-7 years of experience in the field for Level 2
8 or more years of experience for Level 3
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field (desired)
Minimum of 5 years of experience in information security, cybersecurity, or IT risk management (desired)
At least 2 years in a leadership or managerial role in information security (desired)
Benefits
Medical, Dental and Vision Insurance
Wellness Program
Flexible Spending Accounts (Healthcare, Dependent Care, Commuter)
Short-Term and Long-Term Disability options
Basic Life and AD&D Insurance (Company Provided)
Voluntary Life and AD&D options
401(k) Retirement Savings Plan with matching after one year
Sounding and Security Watch responsible for Navy asset security at NSF Diego Garcia. Conducting checks and ensuring safety during designated watch hours with strong situational awareness.
Sales Enablement Manager creating technical content for Upwind Security. Collaborating across teams to translate cloud security concepts into clear narratives for engineers and security leaders.
Security Engineer designing and implementing security measures to protect Snap Inc.'s infrastructure. Collaborating across teams while focusing on threat detection and response strategies.
IT Security & Compliance Head at Lonza leading security strategy and managing global risk. Collaboration with senior leadership to enhance information security across Capsules & Health Ingredients business.
Senior Security Manager leading security for Sanofi meetings and events across North America. Ensuring compliance with global meeting policies and managing event security operations in high - stake environments.
Security Officer maintaining safety protocols at Aloft New Orleans. Responsible for patrolling, monitoring security systems, and assisting guests with safety - related concerns.
Security Detection Specialist responsible for detecting cybersecurity incidents using advanced security technologies. Analyzing data feeds and leveraging security tools for incident detection and reporting.
Senior Incident Response Engineer at Walmart focusing on security threat campaigns to enhance detection and response capabilities. Collaborating with SOC and engineering teams to improve security posture.
Head of Infrastructure & Security at Kinatico, a RegTech leader, focused on cloud infrastructure and security governance. Leading a technically deep team of cloud engineers and security specialists in a hybrid environment.
Security Shift Manager overseeing security operations at WarHorse Gaming Omaha. Responsible for team safety, compliance with regulations, and staffing in the security department.