Jobs · Engineering · Indiana

Manager of Cyber Security I

Bed Bath & Beyond, Inc. · Center, IN · 1 wk ago
EngineeringFull-time

About the role

Responsible for safeguarding enterprise and customer-facing technology environments by identifying, mitigating, and remediating cybersecurity risks. This role leads security operations, incident response coordination, security tooling administration, vulnerability management, vendor/MSSP engagement, and continuous improvement of security controls across the organization.

The Manager of Cybersecurity directly improves the company’s ability to detect, investigate, contain, and recover from cybersecurity threats. This role keeps security operations aligned with business priorities, reduces operational and customer-facing risk, improves the effectiveness of security tools, and ensures the organization is prepared to respond to security events with speed, discipline, and appropriate documentation.

Responsibilities

  • Lead daily security operations, including alert triage, investigation, escalation, containment, remediation coordination, documentation, and post-incident follow-up.
  • Serve as an operational leader for incident response, ensuring events are validated, classified, escalated, tracked, and managed through appropriate ticketing and incident management processes.
  • Maintain and improve security runbooks, response procedures, investigation workflows, evidence handling, technical timelines, and post-incident review practices.
  • Operate and mature detection, response, threat monitoring, threat hunting, and suspicious activity review capabilities.
  • Partner with Fraud Prevention and Application Security on account takeover, bot, abuse, credential attack, and other adversarial activity affecting customer or commerce platforms.
  • Own administration, integration, performance, documentation, lifecycle planning, SME coverage, and support expectations for core security operations tools.
  • Improve tooling effectiveness to reduce risk, improve visibility, or reduce operational complexity.
  • Own or coordinate vulnerability management workflows, including intake, prioritization, remediation tracking, exception handling, validation, assessments, penetration tests, assumed breach exercises, and reporting.
  • Partner with Application Security, Infrastructure, Cloud, and Technology teams to drive timely remediation of vulnerabilities and control gaps.
  • Manage WAF, bot mitigation, API protection, and related edge security changes while balancing risk reduction with customer and platform availability.
  • Manage day-to-day relationships with security vendors, VARs, and consulting partners.
  • Support cybersecurity standards, audit evidence, PCI/SOX-related controls, incident response readiness, and privacy/compliance requirements where security operations evidence or technical support is needed.
  • Lead, coach, and develop cybersecurity operations team members while establishing priorities, ownership, operating rhythms, on-call expectations, escalation paths, and accountability.
  • Perform other duties as required, including leading special projects assigned by leadership.

Requirements

  • Graduation from an accredited institution with a bachelor’s degree in a technical discipline, Information Systems, Cybersecurity, Computer Science, Computer Engineering, or a related field; or any equivalent combination of education, certification, and/or practical experience.

Skills

  • Security Operations and Incident Response
  • Security Information and Event Management (SIEM) and log analytics
  • Endpoint Detection and Response (EDR/XDR)
  • Digital Forensics and Incident Response (DFIR)
  • Threat Hunting and Detection Engineering
  • Threat and Vulnerability Management
  • Penetration Testing, Assumed Breach Assessments, and Remediation Validation
  • Web Application Firewall (WAF), Bot Mitigation, API Protection, and Edge Security
  • Public Cloud Security
  • Network Security, Identity Security, Email Security, DLP/CASB, and Endpoint Hardening
  • Security Architecture and Secure Design Collaboration
  • Security Automation, Tool Integration, Dashboards, and Operational Metrics
  • Vendor, VAR, Licensing, Renewal, and Service Management
  • PCI DSS, SOX, NIST, Incident Response Standards, and security/privacy control environments

Qualifications

  • CERTIFICATIONS (any of the following are acceptable):
    • SANS/GIAC (GSEC, GCIH, GCIA, etc.)
    • Public Cloud Security or DevOps certifications
    • CEH, CHFI, OSCP, CISSP, CISM
    • Relevant network or coding certifications

Benefits

  • 401k (6% match)
  • Flexible Schedules
  • Tuition Reimbursement, Leadership Development Program, & Mentorship Program
  • Employee Resource Groups (LatinX, Black Employee Network, LGBTQIA+, Women’s Network, Women In Tech)
  • And More… (Benefits vary based on position, tenure, location, and employee election)

Physical Requirements

This position requires the incumbent to sit, stand and perform general office functions. The incumbent may also be required to lift 25 pounds or more occasionally. Bending, stooping and reaching are also frequently required.

Similar jobs