Manager, Cybersecurity
Carey International Group, LLC · Orlando, FL · 6 days ago
OTHRFull-time
About the Role
The Manager, Cybersecurity owns the enterprise-wide cybersecurity strategy and execution across diverse business lines, including manufacturing, airline, hotels, financial services, and solar field construction. This leader is accountable for risk management, security operations, engineering of cyber capabilities, identity access management, governance, regulatory compliance, and advising the CSO on cyber risk posture.
Responsibilities
- Define and maintain the enterprise cybersecurity strategy, policies, and roadmap aligned to NIST CSF and applicable regulations (e.g., PCI-DSS, GDPR, sector-specific rules).
- Lead security operations, including threat monitoring, incident response, vulnerability management, and security engineering, in partnership with internal teams and MSSPs.
- Establish and oversee risk assessment, security audit, and compliance programs across all business units.
- Own security architecture standards for cloud, network, identity, and endpoints.
- Develop and report cybersecurity KPIs and risk metrics to senior leadership and the board.
- Drive enterprise-wide security awareness and training programs, including phishing simulations and targeted campaigns.
- Manage the cybersecurity budget, tooling strategy, and vendor relationships.
Requirements
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field; advanced degree preferred, or equivalent experience.
- 5+ years of progressive experience in information security, including leadership of multi-disciplinary teams.
- Proven experience leading incident response, security operations, and risk/compliance programs in complex enterprises.
- Strong customer-centric mindset balanced with operational rigor.
- Relevant certifications such as CISSP, CISM, or CISA.
Preferred Qualifications & Skills
- Experience designing and governing security for hybrid cloud environments (AWS, Azure, GCP).
- Demonstrated ability to communicate complex security topics to executive and non-technical audiences.
- Strong vendor management, budgeting, and stakeholder engagement capabilities.