Jobs · New Jersey

Director, Cybersecurity and Infrastructure

Talent Groups · Parsippany, NJ · 3 wk ago
HybridFull-time

About the role

This role is pivotal in leading the Cybersecurity Program to protect the organization’s critical information assets through the NIST Cybersecurity Framework and practices, ensure regulatory compliance, and help the organization become more proactive in addressing vulnerabilities and risks. The Director, Cybersecurity reports to the Chief Information Officer with a dotted line to the Chief Compliance Officer and has overall accountability for establishing, monitoring, managing, and maintaining the technologies and processes used to secure company information systems, networks, and data.

This position collaborates with key internal and external stakeholders, including IT, Regulatory Compliance, Risk Management, and executive leadership, to respond to and manage all security events and incidents, ensuring the protection of company and client assets across the business.

Responsibilities

  • Lead the delivery of cybersecurity initiatives through collaboration with internal IT and external managed services partners.
  • Oversee the development and execution of the Incident Response Plan (IRP), ensuring swift and effective response to security events and incidents.
  • Coordinate with internal stakeholders and external partners during forensic investigations.
  • Manage endpoint and network security environments, including overall health, policy modifications, troubleshooting, resolving issues, and producing monthly health metrics for workstations, servers, and identities.
  • Analyze and resolve security events and alerts, including:
    • Monitoring and management of the SIEM platform.
    • Managing the logging health of various log sources (e.g., Windows and Linux systems, cloud infrastructure and services, and network and security infrastructure).
  • Collaborate with Risk Management, Regulatory Compliance, and IT on reviewing and updating Cybersecurity policies, controls, and procedures that support NIST compliance, and provide monthly Cybersecurity Dashboard updates.
  • Manage vendor-led penetration testing for external network infrastructure, web applications, and API endpoints.
  • Support and manage vulnerability management platforms for infrastructure and application scanning, including:
    • Development and maintenance of scanning policies.
    • Onboarding assets.
    • Reporting, validation, and false positive research.
    • Remediation tracking and process improvement.
  • Support PCI, SOC1/2, HIPAA, and client security assessments by gathering, uploading, and reviewing evidence.

Requirements

  • Bachelor’s degree with at least 10 years of industry experience in Information Security and Cybersecurity, and a minimum of 5 years in a leadership role.
  • Strong understanding of cybersecurity frameworks, standards, and best practices.
  • Minimum working knowledge of:
    • Incident response.
    • Penetration testing.
    • Vulnerability management.
    • SIEM/log analysis.
    • Network security.
    • Endpoint security.
    • Active Directory.
    • Windows/Linux security.
    • Email security.
    • DLP concepts.
  • Familiarity with the NIST Cybersecurity Framework and mapping of internal controls to support NIST compliance.
  • Familiarity with endpoint security products and concepts (e.g., malware protection, network protection, forensics, DLP, EDR/MDR/SOC).
  • Exposure to adjacent technology domains such as cloud, network infrastructure, audit & compliance, and DevSecOps.

Skills

  • Strong knowledge of Information Security/Cybersecurity-related technologies, processes, and tools.
  • Working knowledge of Office 365 security concepts, policies, settings, alerting, audit logging, Security & Compliance Center, and Cloud App Security.
  • Staying up to date on recent threats (e.g., OWASP Top 10), security tools, and concepts.
  • Experience with network security concepts and products (e.g., Cisco/Barracuda firewalls, Intrusion Prevention Systems, email security, and Web Application Firewall (WAF)); working knowledge of Akamai/Cloudflare is a plus.
  • Familiarity with security monitoring (SIEM), analysis, and resolution of security events/alarms (working knowledge of Google Chronicle is a plus).
  • Familiarity with identity and access management concepts (e.g., Azure Active Directory, OKTA MFA, SSO).
  • Familiarity with SOC1/2, PCI, HIPAA, CCPA/GDPR, or related security frameworks.
  • Familiarity with application-level security frameworks and hands-on experience mitigating application vulnerabilities and threats, such as SQL injection and cross-site scripting.
  • Strong analytical and problem-solving skills.
  • Strong Windows Active Directory and networking experience is a plus.
  • Security-focused degree and/or certifications are a plus (e.g., CISSP, CISM, CISA).

Schedule

Hybrid role based in Parsippany, NJ. Duration: 6 months to start, with potential for conversion.

Similar jobs

Director, Cybersecurity

FTI ConsultingNew York, NY· 2 days ago
OTHR$145k/yrapply on fticonsulting.wd108.myworkdayjobs.com

Director, Cybersecurity

FTI ConsultingChicago, IL· 2 days ago
OTHR$145k/yrapply on fticonsulting.wd108.myworkdayjobs.com

Director, Cybersecurity

Ensemble Health PartnersUnited States· 1 mo ago
RemoteOTHR$148k–$268k/yrapply on ensemblehp.wd5.myworkdayjobs.com