Information Security Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Leads Spartanburg County’s information security program and establishes governance, risk management, security operations, incident readiness, security awareness, data protection coordination, and executive reporting. The position serves as the County’s internal cybersecurity owner while coordinating 24x7 managed SOC/MDR services and collaborating with County Risk Management, Legal, Internal Audit, Human Resources, public safety, elected offices, and technology vendors., * Develops, implements, and maintains the County’s information security strategy, roadmap, policies, standards, procedures, risk register, and performance measures.
- Leads the Cybersecurity Stabilization & Resilience Program’s security workstreams and translates technical findings into prioritized executive decisions.
- Supervises, coaches, and evaluates assigned information security staff; establishes operating cadence, duty coverage, professional development, and performance expectations.
- Oversees MDR/SOC, incident-response, vulnerability-management, security-assessment, and other cybersecurity vendors; defines service levels, escalation paths, reporting, and accountability.
- Coordinates preparation for and response to cybersecurity incidents, including triage, executive notification, evidence preservation, vendor coordination, after-action review, and remediation tracking.
- Establishes and governs vulnerability management, privileged access, identity security, logging/SIEM, endpoint security, cloud security, network security, and third-party access practices.
- Coordinates risk assessments for critical systems, departments, elected offices, vendors, and technology projects; documents residual risk and escalates material risks.
- Partners with the County Risk Management Director on enterprise risk matters while retaining responsibility for information-technology security risk.
- Develops executive dashboards and delivers regular cybersecurity status, risk, incident, remediation, and investment reports.
- Leads security awareness, phishing simulation, role-based training, tabletop exercises, and cybersecurity communications.
- Participates in procurement, contract review, cyber-insurance support, audit response, regulatory/legal coordination, and business continuity planning.
- Maintains professional relationships with law enforcement, state and federal partners, peer governments, and information-sharing organizations.
- Works collaboratively with County Administration, department heads, elected officials, IT staff, vendors, and external partners.
- Communicates professionally, respectfully, and clearly with technical and nontechnical stakeholders.
- Protects confidential, security-sensitive, personnel, legal, and operational information.
- Supports a customer-service culture focused on partnership, accountability, timely communication, documentation, and continuous improvement.
KNOWLEDGE, SKILLS AND ABILITIES
- Cybersecurity governance, risk management, incident response, security architecture, identity/access management, vulnerability management, data protection, and third-party risk.
- Leadership, staff development, vendor governance, policy development, budget planning, and executive communication.
- Ability to remain composed during incidents, make risk-based decisions with incomplete information, and maintain confidentiality.
Requirements
- Bachelor’s degree in cybersecurity, information systems, computer science, business, public administration, or a related field.
- Seven years of progressively responsible information security, infrastructure security, risk, audit, or security-operations experience, including at least two years of lead, supervisory, program-management, or vendor-management responsibility.
- Equivalent combinations of education, training, certifications, and directly relevant experience may be considered.
- Experience leading cybersecurity in local government, public safety, courts, public utilities, healthcare, finance, or another regulated/mission-critical environment.
- CISSP, CISM, CRISC, CISA, GIAC, or comparable certification.
- Experience with NIST Cybersecurity Framework, incident command, managed SOC/MDR, vulnerability management, Microsoft security, Fortinet, SentinelOne or comparable EDR/XDR, SIEM, PAM, and disaster recovery.
- Demonstrated ability to communicate risk effectively to executives, elected officials, auditors, attorneys, and nontechnical department leaders.
LICENSE, CERTIFICATIONS, AND OTHER REQUIREMENTS
All regular full-time and part-time employees of Spartanburg County are required by state law to participate in the South Carolina Retirement System.
Possession of a valid driver’s license issued in the state of South Carolina., * Bachelor’s (Required)
Experience:
- info/infrastructure security, risk, audit, security ops: 7 years (Required)
- lead, supervisory, program management, or vendor-management: 2 years (Required)
License/Certification:
- CISSP, CISM, CRISC, CISA, GIAC or comparable cert. (Required)
Ability to Commute:
- Spartanburg, SC 29303 (Required)
Benefits & conditions
Pulled from the full job description 401(k) Health insurance Retirement plan Paid time off Employee discount Vision insurance Health savings account, * 401(k)
- Dental insurance
- Employee assistance program
- Employee discount
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Frontend Developer Salary in South Africa
9 Ways to Make Money Hacking
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks