Cybersecurity & Privacy Manager
Diversified USA · Portland, ME · 1 mo ago
HybridFull-time
About the role
The Cybersecurity and Privacy Manager role is based in our Portland, ME office on a hybrid schedule with 2 days per week on-site. For candidates not located within a commutable distance to our office, Diversified may choose to consider remote work options.
Responsibilities
- Develop and manage the enterprise information security strategy, framework, and roadmap — including controls, policies, standards, and procedures across on-premises, cloud, and hybrid environments.
- Lead incident response efforts and keep disaster recovery and business continuity plans current; coordinate with third-party vendors, forensic investigators, and internal stakeholders when it matters most.
- Oversee vulnerability assessments, penetration testing, risk assessments, and security audits; monitor the evolving threat landscape and present regular program efficacy reports to senior leadership.
- Build and maintain the organization's privacy controls, policies, and procedures; manage data subject access requests and privacy incidents; and stay ahead of changes in regulations like GDPR, HIPAA, and applicable state privacy laws.
- Manage relationships with security and privacy vendors, negotiate contracts and SLAs, and steward the program budget — identifying cost-saving opportunities without compromising protection.
- Oversee and optimize the security technology stack, including firewalls, IDS/IPS, SIEM, and endpoint protection platforms.
- Directly manage and mentor the IT Security and Privacy Analyst, set clear objectives, support professional development, and build security awareness training programs that resonate with employees across the organization.
Requirements
- Experience & Leadership: 5+ years of progressive information security or cybersecurity experience, including at least 2 years in a supervisory or leadership role, with a track record of building and maturing security programs.
- Technical Depth: Advanced knowledge of Microsoft Azure and Microsoft 365, identity and access management, network security principles, SIEM, IDS/IPS, endpoint protection, and vulnerability assessment and penetration testing tools.
- Cloud & Modern Security Practices: Familiarity with multi-cloud environments, Cloud Security Posture Management (CSPM) tools, DevSecOps practices, secure SDLC principles, and AI/ML security concepts including prompt injection risks.
- Privacy & Compliance Knowledge: Intermediate-to-advanced understanding of privacy legislation and regulatory frameworks — including GDPR, HIPAA, and state privacy laws — with experience evaluating vendor contracts and managing data subject requests.
- Frameworks & Certifications: Familiarity with one or more frameworks like NIST CSF, ISO 27001, and CIS Controls; certifications such as CISSP, CISM, CIPP, or CRISC are preferred.
- Communication & Influence: Strong written and verbal communication skills, with a proven ability to translate complex security topics for non-technical audiences and present confidently to senior leadership.
- Judgment & Confidentiality: Sound analytical and problem-solving instincts, the ability to manage competing priorities, and the discretion to handle sensitive issues with appropriate care.
Skills
- Experience with Microsoft Azure and Microsoft 365
- Advanced knowledge of identity and access management, network security principles, SIEM, IDS/IPS, endpoint protection, and vulnerability assessment and penetration testing tools
- Familiarity with multi-cloud environments, Cloud Security Posture Management (CSPM) tools, DevSecOps practices, secure SDLC principles, and AI/ML security concepts including prompt injection risks
- Intermediate-to-advanced understanding of privacy legislation and regulatory frameworks — including GDPR, HIPAA, and state privacy laws
- Familiarity with one or more frameworks like NIST CSF, ISO 27001, and CIS Controls; certifications such as CISSP, CISM, CIPP, or CRISC are preferred
- Strong written and verbal communication skills, with a proven ability to translate complex security topics for non-technical audiences and present confidently to senior leadership
- Sound analytical and problem-solving instincts, the ability to manage competing priorities, and the discretion to handle sensitive issues with appropriate care
Benefits
- Generous paid time off programs including vacation, sick leave and paid family and medical leave
- Inclusive benefits beyond traditional healthcare coverage, including no-cost-to-you services. Free access to all employees and their families to a national network of licensed clinical psychologists, interactive self-paced programs, life coaches and 24/7 support
- Wellness benefits: Employees can earn credit towards their health insurance premiums by engaging in our Wellness Program which supports physical, mental, and emotional well-being through offering fitness challenges, webinars, and nutrition education
Pay
Compensation is commensurate with experience.
Schedule
This role includes occasional travel to support on-site technology needs at Diversified events and other business opportunities.
Why Diversified?
- Flexible work environment: We offer the flexibility to work fully remote or enjoy a hybrid work schedule.
- Work-life balance: Generous paid time off programs including vacation, sick leave and paid family and medical leave.
- Training & Development: From training conferences to professional development seminars, we invest in resources, including LinkedIn Learning for all staff, that empower employees to excel in their careers.
- Comprehensive Healthcare: Inclusive benefits beyond traditional healthcare coverage, including no-cost-to-you services. Free access to all employees and their families to a national network of licensed clinical psychologists, interactive self-paced programs, life coaches and 24/7 support.
- Wellness Benefits: Employees can earn credit towards their health insurance premiums by engaging in our Wellness Program which supports physical, mental, and emotional well-being through offering fitness challenges, webinars, and nutrition education.