Information Security Lead

Senneca Holding
Springdale, United States of America
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Springdale, United States of America

Tech stack

Microsoft Windows
CompTIA Security+
Computer Security
Information Technology Operations
Microsoft Security Essentials
Azure
Phishing
Software Engineering
Software Vulnerability Management
Information Technology
Data Analytics
CIS Benchmarks

Job description

Senneca is seeking an Information Security Lead to own and mature the organization's cybersecurity program. This role is responsible for security governance, policy development, security awareness and training, risk management, compliance support, and the coordination of cybersecurity initiatives across the business. The Information Security Lead will partner closely with IT Operations, Software Engineering, Data & Analytics, business leaders, and external security providers to strengthen the company's security posture while enabling business growth and operational excellence. This is a hands-on individual contributor role with significant visibility and cross-functional influence. Reporting directly to the CIO, the Information Security Lead will play a critical role in protecting company assets, reducing organizational risk, and supporting the company's long-term cybersecurity strategy., Security Governance & Risk Develop, maintain, and communicate information security policies, standards, and procedures. Conduct periodic security risk assessments and track remediation efforts. Maintain cybersecurity metrics, risk registers, and executive reporting. Assist with customer security questionnaires, audits, and compliance activities. Security Awareness & Training Own the company security awareness program. Lead phishing simulations and user education campaigns. Promote a security-conscious culture across the organization. Develop training materials and deliver security awareness education to employees. Security Program Management Drive cybersecurity improvement initiatives and roadmap execution. Partner with IT Operations and application teams to implement security controls. Coordinate vulnerability remediation and risk mitigation activities. Evaluate and support implementation of security technologies and services. Vendor & MSSP Coordination Serve as the primary liaison to external security providers, MSSPs, and security consultants. Monitor service delivery, recommendations, investigations, and remediation efforts. Assist with incident response coordination when security events occur. Security Operations Oversight Review security alerts, reports, trends, and recommendations from security partners. Ensure timely follow-up on identified risks and vulnerabilities. Track completion of corrective actions and security projects., Cybersecurity Risk Management Security Awareness & Training Security Program Leadership Vulnerability Management Compliance & Audit Support Incident Response Coordination Cross-Functional Collaboration Vendor & MSSP Management Executive Communication & Reporting

Impact of the Role The Information Security Lead directly contributes to company profitability by reducing cybersecurity risk, minimizing the likelihood of costly security incidents, and strengthening overall business resilience. Through proactive risk management, security governance, compliance oversight, and employee awareness initiatives, this role helps prevent operational disruptions, financial losses, regulatory penalties, and reputational damage. Additionally, the position enables secure business growth by implementing scalable security practices that protect critical assets while supporting operational efficiency.

Requirements

5+ years of cybersecurity, information security, or IT risk management experience. Experience developing security policies, standards, and governance programs. Experience leading cross-functional projects and influencing stakeholders without direct authority. Strong written, verbal, and presentation skills. Working knowledge of cybersecurity frameworks such as NIST CSF, CIS Controls, or ISO 27001.

Education Bachelor's degree in Information Technology, Computer Science, Engineering, or a related field. CISSP, CISM, or other relevant security certifications preferred., CISSP, CISM, CRISC, Security+, or similar cybersecurity certification. Experience working with MSSPs or managed security providers. Experience in manufacturing, industrial, or multi-site business environments. Familiarity with Microsoft 365, Microsoft Security solutions, Microsoft Entra ID, and endpoint security technologies. Experience supporting security audits and compliance initiatives. Knowledge of vulnerability management and security awareness programs., Ability to sit, stand, and walk for extended periods. Ability to lift up to 20 pounds occasionally.

Benefits & conditions

Pulled from the full job description Tuition reimbursement Paid parental leave Parental leave Health insurance 401(k) matching Paid time off Employee discount, Company-Paid Benefits Life Insurance Short-Term Disability (STD) Long-Term Disability (LTD) 3 Weeks Paid Time Off (PTO) 9 Paid Holidays Paid Parental Leave, 401(k) with Company Match Medical, Dental, and Vision Coverage Employee Discount Programs Optional Supplemental Benefits Career Development and Tuition Assistance Diverse, Inclusive, and Welcoming Culture

Why This Opportunity This is an opportunity to make a meaningful impact on the organization's security maturity and business resilience. You will help shape cybersecurity strategy, influence company-wide security practices, partner with executive leadership, and drive initiatives that protect critical systems, data, and operations. This role offers the autonomy to build programs, improve processes, and strengthen security across a growing organization.

Apply for this position