Manager Information Security (TVM) (E6162)
IEEE · Piscataway, NJ · 2 days ago
Information TechnologyFull-time
Job Summary
As the Manager, Information Security (Threat & Vulnerability Management), you will serve in a highly technical "player-coach" leadership role, requiring a blend of hands-on engineering and project/people management. Reporting directly to the Director of Cyber & Information Security, you will lead the specialized Threat & Vulnerability Management functional pillar within the department.
Key Responsibilities
Threat Management:
- Provides operational oversight of all Threat and Vulnerability Management systems, technologies, processes, and reporting.
- Manages and tunes Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platforms.
- Led the coordination of technical data and evidence collection during moderate-to-severe security incidents, supporting the Director who serves as the overarching Incident Commander.
- Integrates global threat intelligence feeds and analyzes Indicators of Compromise (IoCs) to proactively fortify network and endpoint defenses.
- Develops, maintains, and automates technical Incident Response playbooks utilizing Security Orchestration, Automation, and Response (SOAR) concepts to accelerate threat containment.
- Leads the threat modeling and security posture management of enterprise Artificial Intelligence (AI) and Machine Learning (ML) systems, defending against adversarial threats (e.g., prompt injection, model poisoning), while leveraging AI-driven analytics to accelerate threat detection and streamline vulnerability prioritization.
Vulnerability Management:
- Drives enterprise vulnerability scanning and coordinates internal or external penetration testing exercises, prioritizing risks and leading cross-functional remediation efforts.
- Collaborates with system owners to evaluate the technical risk of identified vulnerabilities and architects compensating controls when immediate patching is not possible.
- Documents and communicates technical security risks to peer IT leaders.
Documentation & Stakeholder Communication:
- Leads efforts to create, document, and continuously maintain Standard Operating Procedures (SOPs) for technical TVM workflows and departmental processes.
- Translates complex technical security risks into clear operational impacts for peer IT leaders.
Customer & Project Support:
- Partners closely with other IT departments (Infrastructure, Networking, Software Development) to integrate security controls into their respective business projects without disrupting velocity.
- Executes the technical rollout of new threat and vulnerability vendor products from proof-of-concept to full enterprise deployment.
- Leads, tracks, and executes security-focused projects from inception to completion, ensuring milestones, Service Level Agreements (SLAs), and Mean Time to Resolve (MTTR) metrics are met for the TVM pillar.
- Manages relationships with critical security vendors, ensuring platforms are properly deployed, maintained, and delivering maximum ROI.
Continuous Improvement & Operations:
- Manages, mentors, and develops a high-performing team of technical Cybersecurity Engineers.
- Handles all core HR responsibilities, including performance evaluations, hiring, goal setting, and guiding career ladder progression.
- Researches new security processes and emerging TVM technologies, evaluating their efficacy and presenting formal recommendations for changes to department leadership.
- Drives the department’s cross-domain training goals, ensuring team members build proficiency outside their primary operational focus to maintain a well-rounded, agile workforce.
Identity & Access Management (IAM):
- Partners closely with the IAM pillar to correlate identity-based threats, investigate authentication anomalies, and enforce automated access revocations during active security incidents.
Education
- Bachelor's degree or equivalent experience in a computer-related field such as Computer Science, Mathematics, or Engineering.
- Master's or other advanced degree is preferred.
Req Work Experience
- 10-15 years of progressive, hands-on experience within the Information Security or Cybersecurity field.
- Readiness for first-tier management of direct people and project management experience.
Skills And Requirements
Technical Skills & Concepts:
- Deep, proven engineering experience operating at a Senior or Lead level strictly within Threat Management and Vulnerability Management.
- Strong willingness and ability to remain hands-on-keyboard (60% allocation), executing complex technical tasks alongside the engineering team.
- Advanced expertise in modern threat detection/response toolsets, network security, and enterprise vulnerability lifecycles.
- Expert knowledge of security technologies including advanced encryption algorithms, enterprise network security, complex firewall architecture, PKI, and cloud-native security paradims.
- Mastery of Artificial Intelligence (AI) tools to automate and assist with complex cybersecurity tasks, threat hunting, and operational workflows.
- Advanced understanding of application development life cycle (SDLC) models and modern DevSecOps testing tools.
- Intimate knowledge of highly complex operating system environments, hybrid cloud directory synchronization, and advanced networking protocols.
Soft Skills:
- Demonstrated ability to manage TVM operations and pivot seamlessly between deep technical troubleshooting, project tracking, and high-level team management.
- Exceptional communication and presentation skills, with the ability to clearly articulate complex risks to senior executives and technical staff.
- Strong technical leadership, mentorship, and work direction skills with a proven ability to elevate the capabilities of the engineering team.
- Strong decision-making capabilities, able to operate authoritatively in high-stress, real-time crisis scenarios.
- Able to effectively prioritize competing projects and operational incidents in a fast-paced environment.