IT Security Manager

Milbank LLP
New York, NY, United States
2 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$165,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Artificial Intelligence Antivirus Softwares Microsoft Antivirus Software System Penetration Testing Microsoft Azure Microsoft Online Services Ubuntu (Operating System) CentOS Cloud Computing Cyber Security
+47 more
Information Systems Data Security Dynamic Host Configuration Protocol DDoS Mitigation Linux Domain Name System (DNS) Identity and Access Management Information Security Management IT Management Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Kali Linux Microsoft SQL Server Windows Servers Network Forensics Network Segmentation Nmap Open Source Technology Windows PowerShell Red Hat Enterprise Linux Remote Access Technology Azure Active Directory Security Information and Event Management Software Vulnerability Management Snort (Software) Cyberark Firewalls (Computer Science) Azure Security Center Web Filtering National Institute of Standards and Technology Cybersecurity Framework Forescout Information Technology Metasploit Cybercrime Vba Programming Language Nessus Cloudflare Microsoft Sentinel Windows Security Nexpose CIS Benchmarks Encase Cisco Qualys Unified Endpoint Management Vulnerability Analysis

Job description

The IT Security Manager is responsible for managing and overseeing the Firm’s information security program, including security operations, governance, risk management, compliance initiatives, security architecture reviews, incident response activities, and third-party security services. The individual will work closely with IT leadership, business stakeholders, and external partners to ensure the confidentiality, integrity, and availability of Firm information assets.

The position requires strong leadership, project management, communication, and cybersecurity expertise. While maintaining a solid technical understanding of security technologies, the primary focus of this role is the management, oversight, and continuous improvement of the Firm’s cybersecurity program: Responsibilities Manage Intruder Detection sensors, firewalls, Anti-Virus, Web Filtering Solutions, DLP, IPS/IDS, NAC, DDOS protection, third-party remote access, application-whitelisting solutions, endpoint detection and response solutions.

  • Manage Security Incident and Event Management systems (SIEM).
  • Manager and investigate all security events until resolution.
  • Manage privilege account management systems.
  • Conduct technical security audits and perform risk assessments.
  • Conduct firewall, network and systems configuration change and audits.
  • Perform vulnerability scans on networks, servers, systems and applications.
  • Create weekly security reports including keeping track of information security metrics.
  • Work with consultants and third-party vendors as it relates to security services they provide.
  • Participate in project reviews of information security architectures associated with each initiative.
  • Research and test new security technologies.
  • Manage and maintain a good relationship with third party security vendors that support Milbank (MSSP, SOC and others).
  • This is a remote position., o Windows Security (Credentials Guard, Application Guard and others) o Authentic8 Silo and other isolating browsers o E-mail protection solutions such as Mimecast, Proofpoint, Exchange Online and others o DLP products - Exchange Online DLP, Microsoft Endpoint DLP, Microsoft Azure Information Protection o Third Party vendor remote access solution - BeyondTrust or others o Forensics analysis using Guidance Encase platform or open-source tools o Cloudflare o Forescout o Vectra AI

Requirements

  • Minimum 8-10+ years of hands-on information security experience in enterprise environments with at least 3-5 years in a leadership or management role.
  • Strong understanding of security frameworks including NIST CSF, NIST 800-53, CIS Controls, ISO 27001, and SOC 2.
  • Bachelor’s degree in computer science, Information Systems, Cybersecurity, or a related field.
  • Significant hands-on experience with Microsoft Azure and Microsoft cloud security technologies is required, including Azure security architecture, Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, Azure networking, cloud governance, identity and access management, and cloud incident response.
  • Professional cybersecurity certification is required. Acceptable certifications include CISSP, CISM, CISA, GIAC GSEC, PCNSE, Microsoft Certified: Azure Security Engineer Associate (AZ-500),
  • Candidates who do not have proven Microsoft Azure security experience and at least one relevant cybersecurity certification will not meet the minimum qualifications for this role. *

  • Extensive knowledge of security is best practices in regard to computer systems, networks, telecommunication and all associated hardware.
  • Very strong analytical approach to problem solving and solution development.
  • Must be passionate about security and strive to ensure the Firm is protected against evolving cyber threats.
  • Must be a professional with customer satisfaction-oriented mindset, creative and able to balance security with business objectives.
  • Must be able to work well in teams.
  • Must be able to think outside of the box and go beyond traditional security.
  • Must be able to work with Director of Information Security in providing accurate and timely information and closely follow his direction.
  • Ability to manage multiple projects and support functions.
  • Ability to work in a fast paced and dynamic environment.
  • Ability to travel when necessary.
  • Must be available to report for work on regularly scheduled days and off hours when required.
  • Must be available to take emergency off-hour calls during security incidents.
  • Strong analytical, communication and interpersonal skills.
  • Must be able to quickly identify root causes, especially during security incident investigation.
  • Must be able to create accurate and detailed project plans and complete them in timely manner.
  • Excellent documentation skills and capable of creating comprehensive security documents such as standard operating procedures, guidelines and architecture diagrams.
  • Able to fully perform the job function with minimum supervision.
  • Ability to be on call rotation during the weekend.
  • Experience with following technologies: o Cisco network devices o In depth experience with Palo Alto firewalls with all the features available in the product o Micro segmentation technology - Illumio or others o SIEM products such as Microsoft Sentinel or others o IDS & IPS (Vectra AI, Snort, Suricata, AlienVault, or others) o Endpoint security products - CB Application Control, ThreatLocker, Microsoft Defender for endpoint. o Vulnerability scans and penetration test using Nessus, Tenable, Rapid7 Nexpose, Cobalt Strike or others. o Open-source security tools (Kali Linux, Metasploit, Nmap, PowerShell Empire, Kerberoast, TrustedSec SET and others) and network traffic analysis o Vulnerability management with Tenable IO, Rapid7 Nexpose, Qualys or others o Windows operating systems, Active Directory, DNS, DHCP, Microsoft SQL o Linux operating systems (Ubuntu, CentOS RedHat) o Windows Servers and Workstations Security o Scripts (python, VB, Powershell and others) o Privilege Account Management Solution (CyberArk, BeyondTrust or others) o Microsoft M365 E5 security products, Microsoft Azure, Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, Azure networking, Azure governance, and related Azure security controls

  • Experience with following technologies is plus

Benefits & conditions

Compensation: -The anticipated base salary range offered for this role will be between $165,000 to $1205,000 and represents the firm’s good faith and reasonable estimate of the range of possible base compensation. Actual base compensation will be dependent upon several factors, including but not limited to the candidate’s relevant experience, performance, qualifications, degrees, and location, well as the needs of the firm.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Loading talks and stories from around this role…