> Markdown version of [/jobs/ext/1309944-cybersecurity-program-manager](https://www.wearedevelopers.com/jobs/ext/1309944-cybersecurity-program-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Program Manager - **Company:** Alaska Power and Telephone - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $109,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Backup Devices, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Disaster Recovery, Distributed Systems, Multi-Factor Authentication, Supervisory Control and Data Acquisition (SCADA), Identity and Access Management, Network Security, Network Monitoring, Network Administration, Remote Access Technology, Azure Active Directory, Phishing, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Process Control Systems, Patch Management, Operational Systems, Tools for Reporting, CIS Benchmarks, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cfa32e1afc5c8f8f ## About the Role The ideal candidate combines strong technical cybersecurity knowledge with excellent communication, documentation, and problem-solving skills., * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; or * Equivalent combination of education, training, certifications, and relevant professional experience., * Minimum of five (5) years of hands-on experience in information technology, systems administration, network administration, infrastructure management, cybersecurity, or related technical disciplines. * Minimum of three (3) years of cybersecurity-related experience. * Experience with: + Security operations + Network security + System administration + Endpoint protection and endpoint detection and response (EDR) + Identity and access management (IAM) + Vulnerability management + Backup and recovery solutions + Incident response and investigations * Experience developing policies, procedures, incident reports, risk assessments, and technical documentation. * Ability to communicate effectively with both technical and non-technical stakeholders. * Ability to manage sensitive and confidential information with discretion and sound judgment. * Proven ability to coordinate remediation efforts and drive issues to resolution., Current cybersecurity certification preferred, including but not limited to: * CompTIA Security+ * CompTIA CySA+ * ISC2 SSCP * ISC2 CISSP * ISACA CISM * GIAC GSEC * GIAC GCIH * GIAC GICSP * ISA/IEC 62443 Certification * Equivalent industry-recognized cybersecurity certification Candidates with significant relevant experience who do not currently hold a certification may be considered but will be expected to obtain an approved certification within 6-12 months of hire., * NIST Cybersecurity Framework (NIST CSF) * CIS Critical Security Controls * CISA Cybersecurity Performance Goals (CPGs) * Security Operations Center (SOC) practices * Incident response lifecycle * Vulnerability management * Least privilege and access control * Multifactor authentication (MFA) * Endpoint security * Email security * Security logging and monitoring * Backup and disaster recovery best practices, * Experience within a utility, telecommunications, broadband, energy, critical infrastructure, or highly regulated environment. * Experience supporting operational technology (OT), industrial control systems (ICS), SCADA environments, telecommunications networks, or field operations. * Experience with: + Microsoft Entra ID (Azure AD) + Microsoft Defender + Microsoft 365 Security + ESET + SIEM and log management platforms + Firewalls and VPN technologies + EDR/XDR solutions + Vulnerability scanning platforms + Backup and recovery systems + Network monitoring tools * Experience with vendor risk management and third-party security reviews. * Experience supporting audits, cybersecurity assessments, cyber insurance reviews, and regulatory compliance activities. * Experience developing security metrics, dashboards, reporting solutions, scripting, or automation tools., * Cybersecurity Operations * Risk Management * Incident Response * Vulnerability Management * Identity and Access Management (IAM) * Security Governance * Critical Infrastructure Protection * Analytical Thinking * Problem Solving * Technical Documentation * Communication Skills * Vendor Management * Project Coordination * Continuous Improvement ## Description We are seeking a skilled and motivated Cybersecurity Program Manager to execute, maintain, and continuously improve AP&T's cybersecurity program. This role serves as the day-to-day owner of security operations, cyber risk management, incident response readiness, security awareness initiatives, vendor security coordination, and cybersecurity documentation., The Cybersecurity Analyst is responsible for implementing and managing cybersecurity controls, monitoring security events, coordinating risk mitigation efforts, and ensuring compliance with cybersecurity policies and industry best practices. This position plays a key role in protecting AP&T's information systems, telecommunications infrastructure, operational technology (OT), and critical business services., Security Program Management * Maintain, administer, and continuously improve AP&T's cybersecurity program. * Develop, update, and maintain cybersecurity policies, procedures, standards, and supporting documentation. * Track cybersecurity initiatives, remediation efforts, and program objectives. * Support alignment with recognized frameworks and best practices, including NIST Cybersecurity Framework (CSF), CIS Controls, and CISA Cybersecurity Performance Goals. * Prepare reports, metrics, and risk summaries for leadership., * Monitor security alerts, events, and system activity across the organization's technology environment. * Investigate and respond to cybersecurity incidents and suspicious activity. * Maintain secure configurations and cybersecurity tools. * Coordinate with internal teams and external vendors to address identified security concerns. * Support endpoint, network, email, and cloud security initiatives. Vulnerability and Patch Management * Conduct and coordinate vulnerability scanning activities. * Analyze findings and prioritize remediation based on business risk. * Track corrective actions through completion. * Monitor patch management and system hardening efforts. * Participate in external security assessments, penetration testing, and remediation planning. Identity and Access Security * Administer and oversee access control processes. * Support privileged access management and least-privilege security practices. * Manage multifactor authentication (MFA) and identity security controls. * Conduct user access reviews and ensure appropriate account management practices. Incident Response and Recovery * Maintain incident response plans, procedures, and supporting documentation. * Coordinate cybersecurity event response activities. * Facilitate incident response exercises and tabletop simulations. * Support disaster recovery, business continuity, and backup validation activities. * Assist in post-incident reviews and corrective action planning. Risk, Compliance, and Vendor Security * Identify, assess, document, and track cybersecurity risks. * Support audits, compliance reviews, and cybersecurity assessments. * Review third-party and vendor cybersecurity practices. * Assist with cyber insurance submissions, questionnaires, and related requirements. * Maintain evidence and documentation supporting compliance activities. IT, OT, and Critical Infrastructure Security * Support cybersecurity practices across information technology, telecommunications, and operational technology environments. * Assist in securing distributed systems supporting utility and broadband operations. * Coordinate security efforts involving critical infrastructure and field operations technologies. * Support cybersecurity requirements for remote and rural operational environments. Security Awareness and Culture * Lead employee cybersecurity awareness and education efforts. * Coordinate phishing awareness campaigns and training activities. * Promote cybersecurity best practices throughout the organization. * Foster a culture of shared responsibility for information security., The physical demands described below are representative of those that must be met to successfully perform the essential functions of this position. Reasonable accommodations may be made for qualified individuals with disabilities. * Maintain a constant state of mental alertness. * Regularly sit, speak, hear, and use hands and fingers to operate computers, keyboards, mobile devices, and telephones. * Frequently perform work in a sedentary office environment with opportunities to move about. * Occasionally stand, walk, bend, stoop, reach, and lift or move items weighing up to 50 pounds. * Requires close vision, distance vision, peripheral vision, and the ability to adjust focus. * Occasional local and overnight travel by automobile or commercial aircraft may be required. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)