Cybersecurity Program Manager

Alaska Power and Telephone
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$109,000.0 - $125,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Software System Penetration Testing Backup Devices Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Disaster Recovery Distributed Systems Multi-Factor Authentication Supervisory Control and Data Acquisition (SCADA) Identity and Access Management
+19 more
Network Security Network Monitoring Network Administration Remote Access Technology Azure Active Directory Phishing Security Information and Event Management Software Vulnerability Management Data Logging Scripting Cyber Threat Analysis Firewalls (Computer Science) Information Technology Process Control Systems Patch Management Operational Systems Tools for Reporting CIS Benchmarks Vulnerability Analysis

Job description

We are seeking a skilled and motivated Cybersecurity Program Manager to execute, maintain, and continuously improve AP&T’s cybersecurity program. This role serves as the day-to-day owner of security operations, cyber risk management, incident response readiness, security awareness initiatives, vendor security coordination, and cybersecurity documentation., The Cybersecurity Analyst is responsible for implementing and managing cybersecurity controls, monitoring security events, coordinating risk mitigation efforts, and ensuring compliance with cybersecurity policies and industry best practices. This position plays a key role in protecting AP&T’s information systems, telecommunications infrastructure, operational technology (OT), and critical business services., Security Program Management

  • Maintain, administer, and continuously improve AP&T’s cybersecurity program.
  • Develop, update, and maintain cybersecurity policies, procedures, standards, and supporting documentation.
  • Track cybersecurity initiatives, remediation efforts, and program objectives.
  • Support alignment with recognized frameworks and best practices, including NIST Cybersecurity Framework (CSF), CIS Controls, and CISA Cybersecurity Performance Goals.
  • Prepare reports, metrics, and risk summaries for leadership., * Monitor security alerts, events, and system activity across the organization’s technology environment.
  • Investigate and respond to cybersecurity incidents and suspicious activity.
  • Maintain secure configurations and cybersecurity tools.
  • Coordinate with internal teams and external vendors to address identified security concerns.
  • Support endpoint, network, email, and cloud security initiatives.

Vulnerability and Patch Management

  • Conduct and coordinate vulnerability scanning activities.
  • Analyze findings and prioritize remediation based on business risk.
  • Track corrective actions through completion.
  • Monitor patch management and system hardening efforts.
  • Participate in external security assessments, penetration testing, and remediation planning.

Identity and Access Security

  • Administer and oversee access control processes.
  • Support privileged access management and least-privilege security practices.
  • Manage multifactor authentication (MFA) and identity security controls.
  • Conduct user access reviews and ensure appropriate account management practices.

Incident Response and Recovery

  • Maintain incident response plans, procedures, and supporting documentation.
  • Coordinate cybersecurity event response activities.
  • Facilitate incident response exercises and tabletop simulations.
  • Support disaster recovery, business continuity, and backup validation activities.
  • Assist in post-incident reviews and corrective action planning.

Risk, Compliance, and Vendor Security

  • Identify, assess, document, and track cybersecurity risks.
  • Support audits, compliance reviews, and cybersecurity assessments.
  • Review third-party and vendor cybersecurity practices.
  • Assist with cyber insurance submissions, questionnaires, and related requirements.
  • Maintain evidence and documentation supporting compliance activities.

IT, OT, and Critical Infrastructure Security

  • Support cybersecurity practices across information technology, telecommunications, and operational technology environments.
  • Assist in securing distributed systems supporting utility and broadband operations.
  • Coordinate security efforts involving critical infrastructure and field operations technologies.
  • Support cybersecurity requirements for remote and rural operational environments.

Security Awareness and Culture

  • Lead employee cybersecurity awareness and education efforts.
  • Coordinate phishing awareness campaigns and training activities.
  • Promote cybersecurity best practices throughout the organization.
  • Foster a culture of shared responsibility for information security., The physical demands described below are representative of those that must be met to successfully perform the essential functions of this position. Reasonable accommodations may be made for qualified individuals with disabilities.
  • Maintain a constant state of mental alertness.
  • Regularly sit, speak, hear, and use hands and fingers to operate computers, keyboards, mobile devices, and telephones.
  • Frequently perform work in a sedentary office environment with opportunities to move about.
  • Occasionally stand, walk, bend, stoop, reach, and lift or move items weighing up to 50 pounds.
  • Requires close vision, distance vision, peripheral vision, and the ability to adjust focus.
  • Occasional local and overnight travel by automobile or commercial aircraft may be required.

Requirements

The ideal candidate combines strong technical cybersecurity knowledge with excellent communication, documentation, and problem-solving skills., * Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; or

  • Equivalent combination of education, training, certifications, and relevant professional experience., * Minimum of five (5) years of hands-on experience in information technology, systems administration, network administration, infrastructure management, cybersecurity, or related technical disciplines.
  • Minimum of three (3) years of cybersecurity-related experience.
  • Experience with:
  • Security operations
  • Network security
  • System administration
  • Endpoint protection and endpoint detection and response (EDR)
  • Identity and access management (IAM)
  • Vulnerability management
  • Backup and recovery solutions
  • Incident response and investigations
  • Experience developing policies, procedures, incident reports, risk assessments, and technical documentation.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Ability to manage sensitive and confidential information with discretion and sound judgment.
  • Proven ability to coordinate remediation efforts and drive issues to resolution., Current cybersecurity certification preferred, including but not limited to:
  • CompTIA Security+
  • CompTIA CySA+
  • ISC2 SSCP
  • ISC2 CISSP
  • ISACA CISM
  • GIAC GSEC
  • GIAC GCIH
  • GIAC GICSP
  • ISA/IEC 62443 Certification
  • Equivalent industry-recognized cybersecurity certification

Candidates with significant relevant experience who do not currently hold a certification may be considered but will be expected to obtain an approved certification within 6-12 months of hire., * NIST Cybersecurity Framework (NIST CSF)

  • CIS Critical Security Controls
  • CISA Cybersecurity Performance Goals (CPGs)
  • Security Operations Center (SOC) practices
  • Incident response lifecycle
  • Vulnerability management
  • Least privilege and access control
  • Multifactor authentication (MFA)
  • Endpoint security
  • Email security
  • Security logging and monitoring
  • Backup and disaster recovery best practices, * Experience within a utility, telecommunications, broadband, energy, critical infrastructure, or highly regulated environment.
  • Experience supporting operational technology (OT), industrial control systems (ICS), SCADA environments, telecommunications networks, or field operations.
  • Experience with:
  • Microsoft Entra ID (Azure AD)
  • Microsoft Defender
  • Microsoft 365 Security
  • ESET
  • SIEM and log management platforms
  • Firewalls and VPN technologies
  • EDR/XDR solutions
  • Vulnerability scanning platforms
  • Backup and recovery systems
  • Network monitoring tools
  • Experience with vendor risk management and third-party security reviews.
  • Experience supporting audits, cybersecurity assessments, cyber insurance reviews, and regulatory compliance activities.
  • Experience developing security metrics, dashboards, reporting solutions, scripting, or automation tools., * Cybersecurity Operations
  • Risk Management
  • Incident Response
  • Vulnerability Management
  • Identity and Access Management (IAM)
  • Security Governance
  • Critical Infrastructure Protection
  • Analytical Thinking
  • Problem Solving
  • Technical Documentation
  • Communication Skills
  • Vendor Management
  • Project Coordination
  • Continuous Improvement

Benefits & conditions

  • Employee-owned company through our ESOP program
  • Opportunity to secure critical infrastructure serving Alaska communities
  • Collaborative and mission-driven culture
  • Professional development and certification support
  • Competitive compensation and comprehensive benefits
  • Meaningful work with visible impact

About the company

Alaska Power & Telephone (AP&T) is an employee-owned utility dedicated to serving more than 40 Alaskan communities with reliable electric, broadband, and telephone services. As a provider of critical infrastructure, cybersecurity is essential to maintaining the trust, reliability, and safety our customers depend on every day.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all