Cybersecurity Manager
Snoonu · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time
About the role
The Cybersecurity Manager is responsible for the day-to-day management and execution of Snoonu's cybersecurity operations, translating the strategy, policies, and priorities set by the Head of Cybersecurity into consistent, well-run security capabilities across various domains.
Responsibilities
- Translate the cybersecurity strategy and roadmap into operational plans, priorities, and day-to-day execution schedules.
- Coordinate execution across security operations, vulnerability management, application security, cloud security, and identity security workstreams.
- Track progress of security initiatives, projects, and remediation activities, and escalate delays, resourcing gaps, or emerging risks to the Head of Cybersecurity.
- Ensure security processes, runbooks, and procedures are documented, current, and consistently followed by the team.
- Support planning and reporting on cybersecurity capacity, workload, and resourcing needs.
- Manage day-to-day security monitoring and detection activities, ensuring alerts are triaged, investigated, and resolved within agreed timelines.
- Act as the operational incident commander for security incidents, coordinating containment, investigation, and remediation, and escalating significant or high-severity incidents to the Head of Cybersecurity promptly.
- Ensure incident documentation, timelines, and lessons-learned reports are completed for all incidents.
- Cook up and coordinate incident-response tabletop exercises and technical simulations.
- Manage the day-to-day vulnerability management program across applications, infrastructure, cloud, and endpoints.
- Triage, prioritize, assign, and track vulnerabilities to remediation against agreed SLAs.
- Coordinate with engineering, infrastructure, and platform teams to drive timely remediation of critical and high-risk findings.
- Monitor overdue items, recurring weaknesses, and exceptions, and escalate material or stalled risks to the Head of Cybersecurity.
- Support coordination of penetration tests, scans, and security assessments, and track resulting findings to closure.
- Oversee day-to-day implementation of application security and DevSecOps practices, including code scanning, dependency checks, and secure release gates.
- Maintain a watchful eye on cloud security posture and coordinate remediation of misconfigurations, excessive permissions, and exposed assets with infrastructure and platform teams.
- Support engineering and product teams with practical security guidance during design and development, escalating architecture-level or higher-risk decisions to the Head of Cybersecurity.
- Track adoption and effectiveness of security tooling embedded in CI/CD pipelines and development workflows.
- Oversee operational execution of access reviews, joiner/mover/leaver processes, and privileged-access controls.
- Monitor for dormant accounts, excessive privileges, and access-control weaknesses, and drive remediation with system and application owners.
- Support implementation of data-security controls, including access control, encryption, and data-loss-prevention monitoring.
- Investigate suspected data-exposure or unauthorized-access incidents.
- Support execution of the security governance framework, ensuring policies, standards, and procedures defined by the Head of Cybersecurity are implemented and followed operationally.
- Coordinate evidence collection, audits, and assessments related to ISO/IEC 27001, PCI DSS, and other applicable frameworks.
- Track findings from audits and assessments through to remediation, and maintain accurate compliance records.
- Coordinate day-to-day third-party security assessments and monitor remediation of vendor-related risks.
- Coordinate delivery of security awareness training, phishing simulations, and role-specific enablement programs.
- Track behavioral metrics and awareness-program effectiveness, and report trends to the Head of Cybersecurity.
- Prepare regular operational reporting on security metrics, KPIs, incidents, vulnerabilities, and remediation status for the Head of Cybersecurity and relevant stakeholders.
- Directly manage and coach a team of security analysts, engineers, and specialists across security operations, vulnerability management, and related functions.
- Set clear day-to-day expectations, priorities, and performance objectives for the team, aligned with direction from the Head of Cybersecurity.
- Conduct performance reviews, identify development needs, and support career growth for team members.
- Support hiring, onboarding, and knowledge continuity within the team.
- Foster a culture of ownership, technical excellence, and collaboration within the operational security team.
Requirements
- Bachelor's / Master’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent relevant professional experience.
- 4-7 years of experience in the cybersecurity field, including prior experience leading or coordinating a team or workstream.
- Hands-on experience across several security domains such as security operations, vulnerability management, incident response, application security, cloud security, or identity and access management.
- Practical experience managing security tools, processes, and day-to-day operations in a technology-driven organization.
- Working knowledge of cloud environments, modern software-development practices, CI/CD, and enterprise application architectures.
- Experience supporting security governance, audits, or compliance activities.
- Strong organizational, coordination, and problem-solving skills, with the ability to manage multiple priorities under time pressure.
- Good communication skills, with the ability to work effectively with technical teams and non-technical stakeholders.
Qualifications
- Security operations and incident response management.
- Vulnerability and exposure management.
- Application, cloud, and DevSecOps security oversight.
- Identity and privileged-access security.
- Data security and data-loss prevention.
- Security governance, audit, and compliance support (ISO 27001, PCI DSS).
- Third-party security assessment coordination.
- Security awareness program management.
- Security metrics, reporting, and KPI tracking.
- Team leadership and operational management.
Skills
- Security operations and incident response management.
- Vulnerability and exposure management.
- Application, cloud, and DevSecOps security oversight.
- Identity and privileged-access security.
- Data security and data-loss prevention.
- Security governance, audit, and compliance support (ISO 27001, PCI DSS).
- Third-party security assessment coordination.
- Security awareness program management.
- Security metrics, reporting, and KPI tracking.
- Team leadership and operational management.
Benefits
At Snoonu, we offer a range of benefits to ensure you thrive both personally and professionally. These include:
- Generous leave and wellness policies.
- A flexible work schedule.
- Scrum-based agile methodologies.
- Continuous learning and development opportunities.
- Recognition and rewards for your hard work.
- Opportunities for personal and professional growth.
Pay
Competitive compensation package tailored to individual performance and experience.
Schedule
Flexible working hours to accommodate your lifestyle and responsibilities.