Provide leadership and execution support for enterprise information security programs including Security Awareness, Security by Design, Cyber Threat Intelligence, and Vulnerability Management, ensuring alignment with company policy and industry best practices.
Design and oversee the implementation and management of enterprise security technologies and controls like data loss prevention, and vulnerability scanning and help ensure secure system integrations, effective operations, and adherence to governance and risk management requirements.
Enhance and scale automated security operations, including SIEM optimization and detection engineering to strengthen monitoring, analytics, and response capabilities across the organization.
Design and maintain advanced email security controls and authentication protocols to safeguard the enterprise from phishing, business email compromise, and other messaging-based threats.
Lead proactive threat hunting initiatives and monitor emerging threat trends, providing strategic recommendations and actionable mitigation plans to reduce organizational risk.
Develop and facilitate cybersecurity tabletop exercises to validate readiness, test incident response processes, and ensure alignment with organizational recovery objectives.
Embed security into business processes and technology initiatives, serving as an advisor on secure architecture, defense in depth strategies, and secure engineering practices.
Oversee security assessments and gap analyses, including control validation, security reviews, and penetration testing aligned organizational compliance requirements and control effectiveness.
Conduct ongoing research into emerging technologies, security methodologies, and evolving threat vectors, providing leadership with data driven recommendations to enhance the organization’s security posture.
Lead and participate in cybersecurity incident detection and response activities, including handler on duty and on call rotations, incident triage, threat analysis, and coordination of containment and remediation actions.
Mentor and develop security analysts, guiding their growth in security technologies, processes, and best practices while promoting a culture of continuous improvement.
Collaborate with cross-functional teams to support the design, implementation, and governance of technology solutions and processes to help advance organizational resilience.
Partner with technology and business leaders to implement risk based mitigation strategies to drive continuous improvement in security across the enterprise.
Build and maintain strong, collaborative relationships with internal and external stakeholders, fostering an inclusive environment and ensuring effective communication across all levels of the organization.
Support and maintain a positive safety culture by following all safety policies and procedures and actively contributing to a safe working environment.
Other duties as assigned
Requirements
Bachelor’s degree required
Experience in lieu of degree may be considered
Minimum of five years of information technology experience including two years of experience in an information security role required
Industry leading security certifications such as: Certified Information Systems Security Professional (CISSP) (or Associate), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Cybersecurity Analyst+ (CySA+), AWS Security Specialty, or Global Information Assurance Certification (GIAC) such as GSEC, GCIH, GPEN required