Manager of Information Technology

CGT
Pittsburgh, PA, United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cyber Security Information Technology Operations Network Segmentation PCI Data Security Standards Remote Access Technology Cloud Services Security Information and Event Management Software Engineering Software Vulnerability Management Cloud Platform System Cyber Threat Analysis
+2 more
Firewalls (Computer Science) Information Technology

Job description

The Manager, Information Security is responsible for strengthening and maintaining an organization’’’’’’’’’’’’’’'’s overall information security posture. This role provides leadership across security governance, risk and compliance, and security operations while partnering with IT teams and business leadership to identify and mitigate security risks. The position will oversee security technologies, operational processes, compliance initiatives, and technical security personnel to ensure the organization maintains effective protections across its network, systems, identities, applications, and cloud environments., * Develop, maintain, and improve information security policies, procedures, standards, and governance processes.

  • Lead security risk management activities, including threat intelligence, risk assessments, risk analysis, and mitigation planning.
  • Manage security compliance programs, including ISO 27001, ISO 27701, PCI-DSS, client assessments, audits, and security questionnaires.
  • Oversee security resources, budgets, vendors, and managed security service providers.
  • Lead security awareness and training initiatives and advise IT, leadership, and business teams regarding emerging threats, policies, controls, and security best practices.
  • Review security architecture and designs for network, systems, applications, identity, collaboration, and cloud infrastructure.
  • Manage ongoing security monitoring, testing, audits, remediation activities, and compliance tracking.
  • Oversee security detection and response capabilities, including log aggregation, correlation, analysis, incident response, and recovery.
  • Provide leadership and oversight for security technologies and operational functions, including firewalls, network segmentation, vulnerability management, privileged and remote access, EDR/NGAV, SIEM, email security, and continuous monitoring.
  • Lead and prioritize security projects, administrative initiatives, and continuous improvement efforts.
  • Manage, mentor, and develop technical security engineering personnel.
  • Collaborate with IT, business leadership, and other stakeholders to identify security requirements and implement appropriate controls.
  • Maintain strict confidentiality of sensitive organizational, client, employee, and business information.

Requirements

  • Bachelor’’’’’’’’’’’’’’'’s degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent combination of education and experience.
  • Minimum of 10 years of experience in information technology, including at least 5 years of information security-related experience.
  • At least 3 years of experience managing technical security engineers or similar security-focused personnel.
  • Strong IT operations background with experience in networking, systems administration, infrastructure, software development, or related technical disciplines.
  • Demonstrated experience implementing and maintaining ISO 27001 and ISO 27701 programs.
  • Experience managing security governance, risk, compliance, and operational security functions.

Special Requirements

  • CISSP, CISM, CEH, CIPP, or comparable security certification is highly desirable.
  • Candidates currently pursuing relevant professional certifications may be considered.
  • Ability to maintain strict confidentiality and appropriately handle sensitive organizational and personnel information.
  • Willingness and ability to travel to other organizational offices or locations as required.

Knowledge, Skills, and Abilities

  • Strong knowledge of information security principles, practices, frameworks, and industry standards.
  • Thorough understanding of security threats involving systems, networks, identities, applications, and cloud services.
  • Working knowledge of security technologies, including firewalls, SIEM, EDR/NGAV, vulnerability management, network segmentation, identity and privileged access management, email security, and security monitoring tools.
  • Strong understanding of security governance, risk management, compliance, auditing, and remediation processes.
  • Ability to assess technical risks and clearly communicate their business impact to non-technical stakeholders.
  • Strong leadership, team management, coaching, and mentoring capabilities.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Ability to manage multiple concurrent projects, prioritize competing demands, and adapt to changing business and security requirements.
  • Strong written and verbal communication skills.
  • Ability to collaborate effectively with technical teams, business leaders, vendors, and other stakeholders.
  • Strong attention to detail and ability to maintain accurate security and compliance documentation.
  • Highly self-motivated, organized, and capable of working independently.
  • Ability to build positive working relationships and foster team collaboration.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all