Jobs · Information Technology · Tennessee

Cyber Defense Engineering Manager

Regions Bank · Nashville, TN · 1 mo ago
On-siteInformation Technology$141k/yrFull-time

About the Role

The Cyber Security Manager at Regions leads a diverse team of engineers and analysts responsible for the daily operations of enforcing, monitoring, and managing cyber security controls to protect the assets of the bank, customers, and associates. This role oversees security controls including malware defense, network security, Internet security, security analytics, threat intelligence, cybercrime, data protection, vulnerability management, and customer authentication.

Responsibilities

  • Develops cyber security architecture/designs, controls, processes, standards, and strategies to ensure alignment with Information Security standards, emerging threats, and overall Information Security strategy.
  • Develops and implements incident response protocols for ongoing threats and attacks.
  • Communicates status of current threat environment, incidents, and projected threats to senior management and executives.
  • Manages the evaluation and testing of hardware, firmware, and software for possible impact on systems security.
  • Coordinates with other managers to integrate Information Security project components with other projects including application development, network, server, and mainframe.
  • Partners across Technology, Operations, Digital, and Data (TODD) to ensure controls are designed, implemented, and monitored to strengthen risk management, compliance, and cyber security, effectively mitigating risk to levels within the company’s risk appetite.
  • Ensures disciplined change management by evaluating risk and control impacts when designing or implementing changes to processes, systems, products, and/or services.

Requirements

  • Bachelor's degree in a related field and six (6) years of related experience, or High School Diploma or GED and ten (10) years of related experience.
  • Two (2) years of lead or supervisory/managerial experience (preferred).
  • Experience managing Information Technology and/or Information Security projects (preferred).
  • Experience with security operations and incident response/handling (preferred).

Skills and Competencies

  • Ability to prioritize assignments while working on multiple projects.
  • Demonstrated ability to effectively engage project teams and leadership within a corporate setting.
  • Excellent writing and oral communication skills.
  • Strong ability to predict and plan for unknown threats.
  • Strong ability to work well with others and place a premium on the group’s success.
  • Strong technical aptitude skills.
  • Understanding of and ability to interpret applicable rules, regulations, and industry guidance.

Preferred Qualifications

  • Cybersecurity leadership experience within a financial institution or other highly regulated industry.
  • Proven expertise in regulatory compliance, audit response, and issue remediation management.
  • Strong working knowledge of financial services cybersecurity regulations and supervisory expectations.
  • Demonstrated ability to author, update, and enforce cybersecurity policies, standards, and control frameworks.
  • Experience managing complex, cross-functional remediation efforts with executive and regulator visibility.
  • Prior experience with EDR tools and deployment, Application Allow-listing, and experience working with and supporting multiple operating systems (Windows, macOS, Linux, Containers).
  • Familiarity with AWS/Azure.
  • Experience with Incident Response, Malware Analysis, Custom EDR Rule Development.
  • Strong knowledge of MITRE ATT&CK framework.
  • Experience leading platform resilience, change, and incident communications, including outage response, change approvals, rollback strategies, and coordination with network, identity, and endpoint teams.
  • Experience owning and operating a cloud-based secure access / network security platform, including responsibility for architecture decisions, policy governance, vendor engagement, and service lifecycle management.
  • Strong understanding of Zero Trust networking principles, including secure internet access, private application access, identity-aware routing, and integration with IAM, EDR, and endpoint posture signals.
  • Proven ability to translate network and endpoint security telemetry into risk-based insights, supporting threat hunting, incident response, regulatory reporting, and executive-level decision making.
  • Experience with Purple Team Engagements and/or Atomic Testing (a plus).

Schedule

This position is intended to be onsite, with regular work hours including full days in the office three or more days a week. The manager will set the work schedule for this position, including in-office expectations.

Pay

Pay ranges are job-specific and based on the Metropolitan Statistical Area Market Range for the position's location and level. The target minimum for this role is $140,670.75 USD, with a median target of $184,390.00 USD.

Incentive Pay Plans

  • Eligible to participate in the annual discretionary incentive plan, with awards based on individual, business, and/or company performance.
  • Opportunity to participate in the Long Term Incentive Plan.

Benefits

  • Paid Vacation/Sick Time
  • 401K with Company Match
  • Medical, Dental, and Vision Benefits
  • Disability Benefits
  • Health Savings Account
  • Flexible Spending Account
  • Life Insurance
  • Parental Leave
  • Employee Assistance Program
  • Associate Volunteer Program

This position is exempt from timekeeping requirements under the Fair Labor Standards Act and is not eligible for overtime pay. Regions will not provide relocation assistance, sponsor work visas, or consider applicants who are not currently authorized to work in the United States on a full-time basis. Available locations for this role are Birmingham, AL; Nashville, TN; Charlotte, NC; or Atlanta, GA.

Similar jobs