Manager, Cybersecurity
About the role
Join the Smoothie King team as Manager, Cybersecurity and lead the day-to-day execution of our cybersecurity program and security operations. This role independently assesses risk, establishes priorities, recommends action, and drives security issues through remediation and closure. You will need sufficient technical depth to evaluate security findings, telemetry, vulnerabilities, architecture, and control gaps; provide informed direction to technical teams and vendors; and balance immediate risk reduction with longer-term program maturity.
You will own the identification, prioritization, remediation, validation, and closure of cybersecurity risks and findings, execute and continuously improve cybersecurity strategy, standards, policies, and procedures, and provide technical and operational security leadership across Azure, identity, endpoint, network, infrastructure, vulnerability management, and security monitoring.
Responsibilities
- Own the identification, prioritization, remediation, validation, and closure of cybersecurity risks and findings, prioritizing immediate risk reduction while maintaining disciplined scope.
- Execute and continuously improve cybersecurity strategy, standards, policies, and procedures in alignment with business objectives and established risk tolerance.
- Provide technical and operational security leadership across Azure, identity, endpoint, network, infrastructure, vulnerability management, and security monitoring.
- Evaluate cybersecurity risk, determine appropriate courses of action, and escalate material risks with clear recommendations.
- Lead cybersecurity incident response and oversee SOC and managed security partners through investigation, containment, remediation, recovery, and corrective action.
- Lead cybersecurity compliance and assurance activities, including PCI DSS, security assessments, penetration testing, and remediation of identified gaps.
- Partner with technology and business teams to integrate appropriate security controls without unnecessarily impeding delivery.
- Manage cybersecurity vendors, third-party risk activities, and assigned budgets, holding partners accountable for performance and outcomes.
- Develop and communicate cybersecurity KPIs, risk metrics, material risks, and recommendations to leadership.
- Lead cybersecurity awareness initiatives and drive security projects to measurable outcomes with clear ownership and timelines.
- Stay current on emerging threats and technologies and translate relevant developments into practical security improvements.
Requirements
- Strong understanding of cybersecurity frameworks and risk management practices, including NIST, CIS Controls, ISO 27001, and PCI DSS.
- Strong technical knowledge across Azure/Entra ID, identity, endpoint, network, vulnerability management, logging, monitoring, and threat detection.
- Ability to independently assess security findings, telemetry, attack paths, vulnerabilities, and control gaps.
- Strong risk-based judgment and bias for action, including the ability to make timely decisions under ambiguity, prioritize remediation, and escalate material risks with clear recommendations.
- Demonstrated experience leading incident response, vulnerability remediation, security assessments, penetration testing, and audit activities through closure.
- Experience managing cybersecurity vendors, SOC providers, third-party risk, budgets, and resources.
- Strong people leadership, execution discipline, and ability to drive multiple initiatives to measurable outcomes.
- Strong written and verbal communication skills with the ability to translate technical issues into clear business risk and recommendations.
- Ability to constructively challenge technical teams, vendors, and assumptions while maintaining effective cross-functional relationships.
- Proactive, accountable mindset focused on measurable risk reduction and operational execution.
Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
- Seven or more years of progressive cybersecurity experience, including at least three years leading security operations, programs, significant initiatives, or teams.
- Demonstrated experience across security operations, incident response, vulnerability management, identity, endpoint, network and cloud security, security monitoring, and compliance.
- Experience working with SOC/MSSP providers, security vendors, auditors, penetration testing firms, and cross-functional technology teams.
- Experience in retail, restaurant, franchise, or another distributed multi-location environment is preferred.
- Relevant certifications such as CISSP, CISM, CCSP, Microsoft Security, or GIAC are preferred.
Benefits
- Great benefits package
- Free smoothies
- Flexible work schedules
- Office lunches and parties
- Monthly fitness challenges
- Free gym access
- Fun activities to make Smoothie King a happy and healthy place to work
About us
Smoothie King is the pioneer of the nutritional smoothie and the largest nutritional smoothie bar in the nation, with over 1300 stores. We inspire people to live a healthy and active lifestyle through our clean ingredients and passionate approach to guest health and wellness. Our culture is built on core values—We Are Better Together, We Keep Evolving, We Live Our Mission, We Do the Right Thing, and We Focus and Finish—fostering collaboration, passion, and a no-limits mindset.
We champion a diverse and inclusive workforce that reflects the guests we serve, blending unique talents to grow better together and "Rule the Day." Our mission is to inspire people to live a healthy and active lifestyle, and our vision is to make the world a better place by nourishing healthy habits.