> Markdown version of [/jobs/ext/1933372-manager-it-security-engineering-operations](https://www.wearedevelopers.com/jobs/ext/1933372-manager-it-security-engineering-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, IT Security Engineering & Operations - **Company:** Cooper's Hawk Winery & Restaurants - **Location:** Downers Grove, IL, United States - **Experience:** Expert - **Salary:** $150,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Application Firewall, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Information Systems, Continuous Delivery, Continuous Integration, Data Security, Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Microsoft Software, Oracle (Applications), PCI Data Security Standards, Protocol Independent Multicast, Salesforce.Com, Secure Coding, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Web Applications, IT General Controls (ITGC), Software Security, Firewalls (Computer Science), Information Technology, Data Management, Cisco - **Published:** August 5, 2026 - **Apply:** https://www.careerbuilder.com/job-details/manager-of-security-engineering-operations-downers-grove-il--9a0c1a55-f4e7-4435-85a9-70f741b019fe ## About the Role * 7+ years of experience in security engineering or security operations * Experience leading teams while remaining hands-on in technical work * Strong experience with Azure and Microsoft 365 * Experience managing SOC/MDR services * Hands-on experience with vulnerability management and incident response * Experience with application security and WAF technologies * Threat detection and incident response * Cloud security architecture and controls * Identity and access management * Endpoint and email security * Vulnerability management practices * Knowledge of PCI DSS, SOX ITGC, and NIST CSF requirements Education * Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent professional experience * Preferred Certifications * Certified Information Systems Security Professional (CISSP) * Cloud security certifications such as CCSP * Security operations or incident response certifications (e.g., GCIH) Other Skills/Abilities: * Ability to adapt quickly in a dynamic environment, evaluate new technologies, and apply them effectively as the security and technology roadmap evolves. * Strong organizational and prioritization skills, with the ability to manage multiple initiatives, deadlines, and competing requests. * Excellent analytical and problem-solving skills, with a practical, customer-focused approach to security challenges. * Ability to communicate clearly and effectively with technical and non-technical stakeholders across IT, business, and restaurant operations. * Hospitality industry experience will be a plus., Accidental Death and Dismemberment (AD&D), Analysis Skills, Application Programming Interface (API), Applications Security, Business Operations, CCSP - Cisco Certified Security Professional, CISSP - Certified Information Systems Security Professional, Cloud Applications, Cloud Architecture, Cloud Computing, Communication Skills, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Customer Relations, Dental Insurance, Email Security, Endpoint Security, Establish Priorities, Firewalls, GCIH - GIAC Certified Incident Handler, Hospitality and Tourism, Identity Data Management, Incident Management, Incident Response, Information Systems/Technology IS/IT Administration, Information Technology & Information Systems, Information/Data Security (InfoSec), Insurance, Internet Application, Leadership, Machine Tool, Management of Information Systems/Technology (MIS), Mentoring, Menu Development, Microsoft Product Family, Microsoft Windows Azure, Operations Management, Operations Security (OPSEC), Oracle, Organizational Skills, PCI-DSS, Prescription Drugs, Problem Solving Skills, Protocol Independent Multicast (PIM), Quality Management, Restaurant, Retail, Salesforce.com, Sarbanes-Oxley Act (SOX), Security Architecture, Security Information and Event Management (SIEM), Security Infrastructure, Security Monitoring, Service Level Agreement (SLA), Software Development, Software as a Service (SaaS), Team Lead/Manager, Team Player, Telemedicine, Time Management, U.S. National Institute of Standards and Technology (NIST), Vendor/Supplier Evaluation, Vision Plan ## Description The Manager, IT Security Engineering & Operations is responsible for leading and executing the organization's security engineering and security operations functions. This role owns the design, implementation, and operation of security controls across cloud, applications, endpoints, identity, and network environments. This is a hands-on leadership role that combines technical execution with team leadership. The Manager is expected to actively contribute to engineering and operational activities while leading a small team, ensuring delivery of key security initiatives and day-to-day operations This position reports to the VP of Information Security & GRC and works closely with Security & Compliance, IT Infrastructure & Operations and applications teams., * Lead the design and implementation of security controls across Azure, Microsoft 365, and SaaS platforms, including Oracle Simphony * Drive security hardening initiatives across cloud and enterprise platforms, including Microsoft 365 baseline configurations * Define and enforce secure architecture standards in partnership with Infrastructure and Application Development teams Security Operations & Incident Response * Manager security operations, including monitoring, detection, and incident response * Manage and optimize SOC/MDR services and vendor performance * Improve detection quality, reduce false positives, and strengthen response capabilities * Lead incident response and post-incident reviews Cloud & Application Security * Manage cloud security posture across Azure, Salesforce and Oracle * Lead application security initiatives including code scanning, API security, and secure development practices * Manage and optimize Web Application Firewall (WAF) capabilities * Integrate security into CI/CD pipelines and development workflows Vulnerability Management * Manage the vulnerability management program end-to-end * Ensure vulnerabilities are remediated within defined SLAs * Drive accountability across IT and application teams * Deliver clear reporting and metrics to leadership Security Platforms & Tooling * Manage and optimize core security technologies, including: * Endpoint protection (Microsoft Defender, Bitdefender) * Identity security (Entra ID, Conditional Access, PIM) * Microsoft 365 security * WAF and edge protection * SIEM/SOAR and MDR integrations * Ensure tools are properly configured and delivering measurable value Compliance & Risk Alignment * Partner with Security & GRC to support PCI DSS 4.0 and SOX ITGC requirements * Ensure controls are implemented and operating effectively * Support audits, remediation, and control validation Team Leadership & Execution * Directly manage: * Senior Information Security Engineer * IT Security Administrator * Set clear priorities, goals, and expectations * Drive accountability and execution across the team * Mentor and develop team members while remaining actively involved in delivery ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)