Jobs · Information Technology · New York

Manager, Information Security

Building Service 32BJ Benefit Funds · New York, NY · 1 wk ago
Information TechnologyFull-time

About the role

The Manager, Information Security will lead and manage the IT Security Operations team, providing critical oversight of security operations, developing and maintaining policies and frameworks, and mentoring members of the Information Security team.

Responsibilities

  • Lead and manage the IT Security Operations team, including Information Security Analysts, Engineers, and Incident Responders.
  • Provides guidance and expertise in the field of risk management regarding the protection and security of digital assets in the cloud and on-premises.
  • Designs and develops Information Security architectures to prevent unauthorized access to our system, networks, data, and information.
  • Maintains and enhances information security policies and procedures, including the Information Security Policy Manual, Incident Response plans, playbooks, runbooks, and the Business Continuity Plan documents on a regular basis as changes occur.
  • Collaborates with the SOC provider to review threat alerts, reports, and ensures the team follows up on all actionable information.
  • Manages, maintains, and monitors security technologies such as vulnerability scanning solutions, IDS/IPS, anti-virus technologies, DLP capabilities, SIEM technologies, EDR, host forensics and malware analysis, core and web application firewalls, network security groups, threat intel platforms, and proxy solutions.
  • Coordinates and performs business continuity planning and incident response exercises on an annual basis within IT and with business champions.
  • Coordinates and leads response efforts during security incidents.
  • Monitors internal control systems to ensure appropriate access levels are maintained, protects against unauthorized system access, modification and destruction.
  • Reviews security related reports, logs and occurrences; escalates issues and initiates security response procedures.
  • Creates and reviews vulnerability reports, tracks compliance with vulnerability management policies, and escalates.
  • Researches and evaluates emerging technologies, latest cybersecurity threats, trends, tools, and best practices in support of security technology enhancements applicable to the organization’s environment, proposes technical solutions to management, to address security weaknesses, and coordinates with relevant stakeholders to implement.
  • Tests security controls and manages the associated remediation of any deficiencies as needed.
  • Assesses security information, triaging and responding to security events, identifying false positives, and conducts correlation analysis across numerous internal and external data sources while prioritizing information security incidents.
  • Performs project management tasks for security initiatives and projects.
  • Manages incident-handling processes, which include implementation of containment, protection, and remediation activities.
  • Supports information security training and awareness by providing ideas and content and collaborates with the Training and Development department with updates to employee security awareness education and training.
  • Manages multiple priorities and deadlines concurrently.
  • Supports after hours, on weekends, and through on-call rotation.

Qualifications

  • 7+ years in Information Security, or IT Operations management and systems administration with at least 5 years specific to IT Security and at least 2 years managing IT Security staff.
  • Strong knowledge of Information Security design, principles, and processes; Experience in writing and maintaining information security policies, standards, and guidelines.
  • Incident response experience is required; in-depth knowledge of Windows/Unix operating system forensics, event logging systems, authentication methods, remote and local web application security, and penetration testing.
  • Advanced experience in networking (TCP/IP) protocols, DNS, LDAP, AD, DHCP, HTTP, web browsers, firewalls, and other computer/network and application security and system administration.
  • Demonstrated ability to monitor and audit network security systems such as Firewalls, IPS, SIEM, DLP, web proxy, NAC, and Vulnerability Scanners.
  • Hands on experience with mitigating security controls (i.e., IAM, RBACs, anti-virus, IPS/IDS, DLP, web and network proxies, URL content filtering, multi-factor authentication, SSL VPNs).
  • Familiar with regulatory compliance regulations (PCI, PII, HIPAA, GDPR, etc.).
  • Strong knowledge of common security frameworks (ISO, NIST, etc.).
  • Experience in risk assessments and vulnerability management.
  • General knowledge of Endpoint protection solutions.
  • Knowledge of mainstream operating systems (Microsoft Windows, Linux, IOS) and a wide range of security technologies.
  • Microsoft Azure DevOps Security design implementation, automation is a plus.
  • General knowledge of Database technologies and queries (Microsoft SQL, MySQL, Oracle, etc.) is a plus.
  • Ability to independently identify, research and resolve issues with minimal amount of supervision, and ability to work with peers in a team effort.
  • Interpersonal Skills: Detail oriented with excellent communication, organization and analytical skills.
  • Ability to plan, take initiatives to accomplish objectives in a timely fashion, and work independently.
  • Ability to prioritize work and meet deadlines.
  • Ability to establish and maintain effective working relationships with project team members, supervisors, and other employees.

Similar jobs

Manager, Information Security

StellarusCalifornia, United States· 1 wk ago
Information Technology$123k–$185k/yrapply on ecge.fa.us2.oraclecloud.com