Manager-Information Security
Buchanan Ingersoll & Rooney PC · Pittsburgh, PA · 1 wk ago
HybridFull-time
About the role
The Manager, Information Security will join a dynamic security team responsible for continually improving the Firm’s security posture, focusing on managing and enhancing its network, system, identity, and cloud security capabilities. Reporting to the Director – IT Operations and Security, and collaborating with other IT teams and Firm leadership, this role oversees all aspects of security governance, risk, compliance, and operations.
Responsibilities
- Security governance, including policy, process, procedure, and standards.
- Risk management, including threat intelligence, risk assessment, analysis, and mitigation planning.
- Compliance management, including ISO 27001, PCI-DSS, and client assurance audit and questionnaires.
- Resource management, including budget, vendor, and managed security service providers.
- Security awareness and training, including liaising with and advising IT, Firm leadership, various departments, and practice groups regarding emerging threats, policy, controls, and best practices.
- Design and architecture review, including network, system, application, identity, collaboration, and cloud infrastructure.
- Continual monitoring, testing, and audit lifecycle management, analysis, and remediation tracking.
- Detection and response, including log aggregation, correlation, analysis, incident response, and recovery.
- Oversight of security operational functions and technology, including firewall, network segmentation, vulnerability management, privileged/remote access management, EDR/NGAV, SIEM, email security, and continuous monitoring.
- Coordination, prioritization, and delivery of projects, administrative, and continual improvement initiatives.
- Performs other work-related duties as assigned.
Requirements
- Bachelor’s degree or equivalent with at least 5 years of security-related experience.
- 10+ years of experience working in an information technology-related field.
- Strong IT operational background and related network, systems, or development experience.
- 3+ years of experience managing a team of technical security engineers.
- Strong knowledge of security threats involving systems, identities, and cloud services.
- Direct experience implementing and maintaining ISO 27001 and 27701.
- Working knowledge of security technology (e.g., firewalls, SIEM, EDR/NGAV, email security).
- Understanding of technical risk implications and ability to communicate effectively to non-technical users.
- Ability to manage concurrent activities, prioritize effectively, and adapt to a dynamic environment.
- Demonstrated ability to maintain strict confidentiality of the Firm’s internal and personnel affairs.
- Ability to work well with others, leverage varying skills and experience, and build team camaraderie.
- Highly self-motivated, directed, and able to gauge one’s strengths and limitations.
- Ability to work in a multi-office environment and willingness to travel to other offices as required.
Qualifications
- The following certifications are highly desired: CISSP, CISM, CEH, CIPP; matriculating candidates considered.
- Experience working in a law firm or professional services firm environment preferred.
Benefits
- Hybrid work schedules
- Generous Paid Time Off
- Paid Holidays, including a floating holiday
- WorkWell wellness program
- Free use of building gym
- Caregiving assistance with Bright Horizons (child, elder, and pet care)
- Access to Firm-wide emergency assistance fund
- Free full access to LinkedIn Learning
- Insurance – Medical, Dental, Vision
- 401K Program
- Retirement Savings Program