Mgr, Cyber Security Engineering & Ops

BOK Financial Corporation
Tulsa, OK, United States
6 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Application Firewall Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Intrusion Detection Systems PCI Data Security Standards
+10 more
Web Application Security Security Information and Event Management Software Vulnerability Management Generative AI HybridCloud Firewalls (Computer Science) Information Technology Performance Monitor Virtual Agents CIS Benchmarks

Job description

The Manager, Cyber Security Engineering and Operations leads the engineering, availability, resilience, and operational effectiveness of enterprise cybersecurity platforms and controls across internal, cloud, SaaS, application, data, and business-to-business environments. This role translates enterprise risk strategy into sustainable technical capabilities, directs complex security initiatives, influences cybersecurity architecture and investment priorities, and provides leadership during cybersecurity incidents and other events presenting material operational, financial, regulatory, or reputational risk. As a leader within the cybersecurity organization, this position is responsible for managing security engineering and operational teams, ensuring effective delivery and support of security technologies, driving continuous improvement of cybersecurity capabilities, and maintaining the reliability, resilience, and recovery readiness of critical security systems. Team Culture

We lead with a deep commitment to cybersecurity because protecting sensitive financial and personal data is essential to earning and maintaining trust. Security is more than a responsibility, it is a mindset woven into every decision, driven by collaboration, innovation, operational excellence, and continuous learning. Our focus is on empowering individuals to grow while making a meaningful impact on the safety, resilience, and security of our digital environment. Leadership is dedicated to developing high-performing teams, fostering accountability, supporting career growth, and helping employees unlock their potential while delivering critical business outcomes. How You’ll Spend Your Time

  • You will lead the evaluation, deployment, integration, lifecycle management, resilience, and operational performance of enterprise cybersecurity technologies and services.
  • You will manage cybersecurity initiatives, balancing scope, resources, budgets, dependencies, risks, and delivery commitments to ensure successful outcomes.
  • You will direct cybersecurity engineering and operations activities during security incidents, including triage, containment, remediation, recovery, escalation, and post-incident improvements.
  • You will partner with cybersecurity architects and technology leaders to implement effective detection, prevention, and resilience capabilities across the enterprise.
  • You will evaluate emerging technologies, including AI, Generative AI, and agentic AI security controls, risks, and governance considerations.
  • You will collaborate with Audit, Compliance, Enterprise Risk Management, Legal, and business stakeholders to support examinations, sustain controls, address findings, and monitor remediation activities.
  • You will oversee cybersecurity operations, tools, vendors, managed security service providers, budgets, service roadmaps, and issue resolution efforts.
  • You will lead workforce planning, hiring, performance management, succession planning, mentoring, coaching, and development of a high-performing cybersecurity team.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Systems, Engineering, or related field; or equivalent combination of education and experience
  • 10+ years of progressively responsible cybersecurity, information security, security engineering, technology risk, or security operations experience in complex enterprise environments
  • 5+ years of leadership experience managing cybersecurity engineers, analysts, contractors, operational security teams, or cross-functional delivery teams
  • CISSP, CISM, GIAC, CCSP, CISA, CRISC, Security+, Microsoft Azure Security Engineer Associate, AWS Security Specialty, or related certification preferred
  • Demonstrated experience implementing, operating, and supporting enterprise cybersecurity technologies and day-to-day security operations
  • Experience supporting audits, regulatory examinations, compliance reviews, and remediation activities in highly regulated financial services environments preferred
  • Strong knowledge of banking systems, operational resilience, and cybersecurity risk management
  • Familiarity with regulatory and compliance requirements including OCC, FDIC, Federal Reserve, SEC, FINRA, GLBA, FFIEC, SOX, PCI DSS, and applicable regulatory notification obligations
  • Working knowledge of the NIST Cybersecurity Framework, NIST SP 800-series guidance, CIS Controls, and FFIEC cybersecurity domains
  • Ability to translate technology risk requirements and business objectives into effective technical security controls, standards, metrics, and performance reporting
  • Ability to align cybersecurity priorities and initiatives with business objectives and enterprise risk management strategies
  • Expertise leading complex cross-functional projects, managing stakeholders, and delivering large-scale cybersecurity initiatives

Skills & Knowledge

  • Expert knowledge of security architecture principles, engineering standards, governance models, and operational security practices
  • Expertise across network, endpoint, identity, application, data, cloud, and hybrid security technologies
  • Hands-on knowledge of firewalls, web application firewalls, IDS/IPS, secure web gateways, EDR/XDR, SIEM, SOAR, PAM, MFA, IGA, encryption, vulnerability management, threat monitoring, incident response, and operational recovery
  • Experience securing Azure, AWS, SaaS, and hybrid-cloud environments, including cloud security posture management and cloud-native security controls
  • Understanding of AI, Generative AI, and agentic AI risks, governance, machine identities, non-human identities, and secure AI implementation practices
  • Expertise in risk-based vulnerability and exposure management, including prioritization, remediation governance, exception management, and validation of risk reduction
  • Strong analytical, critical-thinking, and systems-thinking capabilities with the ability to assess complex technical, operational, regulatory, and business challenges
  • Executive-level verbal and written communication skills with the ability to communicate complex cybersecurity concepts to technical and non-technical audiences
  • Proven ability to build, lead, and develop high-performing teams while driving accountability, performance, and results Working Conditions & Physical Requirements Office

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

2:37 min

Tracing the evolution from early AI to generative AI

Mike Mike · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

2:14 min

Introduction to generative AI and content warnings

Cheuk Ho · World Congress 2023

Videos

See all

Related articles

See all