Jobs · Information Technology · Washington

Security Operations Manager

HybridInformation Technology$62.59–$93.9/hrFull-time

About the role

The City of Seattle is seeking a Security Operations Manager (IT Professional A) to lead the Security Operations team and drive excellence in cybersecurity processes and technologies.

Responsibilities

  • Manage and lead ongoing improvements in Seattle IT's citywide incident detection and response program.
  • Coordinate detection engineering, SIEM/SOAR operations, EDR/XDR/NDR telemetry, forensic investigations, threat intelligence gathering and sharing, enterprise event log collection, and threat hunting activities.
  • Regularly validate the effectiveness of cybersecurity defenses and incident response readiness through measurable metrics, tabletop exercises, red/purple/blue teaming, and other approaches.
  • Lead Security Operations' contribution to the City’s vulnerability management program in partnership with peer technical managers and compliance partners, providing operational metrics as needed and supporting a risk-based approach to prioritization of vulnerability remediation.
  • Proactively adapt Security Operations cyber defense capabilities in anticipation of City projects and programs, strategic direction, and industry shifts.
  • Maintain and grow strong operational relationships and processes between Security Operations and security partners across the City’s public safety, utility, transportation, and operational technology environments.
  • Assume incident command or other designated roles in cybersecurity incidents as defined by the relevant incident response plan.
  • Negotiate vendor contracts for a strengthened security posture at an advantageous cost.
  • Develop cybersecurity strategic roadmaps that are aligned with larger Seattle IT and City strategic goals and initiatives.
  • Provide overall management and coaching of the security operations staff, including developing training programs, setting team objectives and individual expectations, aligning team members for individual and team success, assessing performance, and meeting key performance indicators.
  • Establish and cultivate strong strategic partnerships with City peers and collaborators in cybersecurity risk, privacy, infrastructure, endpoint, identity, applications, operational technology, and other relevant domains.
  • Ensure alignment on security objectives, incident readiness, and roadmaps.
  • Continually evaluate our security vendor and managed service relationships, including managed service providers, for value, service performance, incident coordination, and alignment with strategic roadmaps and industry direction.
  • Maintain awareness of industry trends and developments in cybersecurity and adjacent domains that may impact our environment, and work with the Security Leadership to adjust approaches and roadmaps as needed.
  • Communicate effectively and professionally with all levels of the organization.
  • Lead executive briefings and incident command communications during cybersecurity events, exercises, and readiness reviews, translating technical risk into operational and policy decisions for senior City leadership.
  • Periodically support and advise sister agencies in their cybersecurity practices, protocols, and incident response.
  • Engage in strategic leadership, partnership, and mutual support with the S&I divisional leadership team and Seattle IT-wide leadership/management bodies and actively represent our leadership values daily.
  • Manage the Security Operations team’s annual budget, including forecasting, tracking of actuals, and identification of cost savings and efficiencies.

Qualifications

  • Education: Bachelor’s degree or equivalent experience in a technology-related field.
  • Experience: Seven years’ combined experience in information technology, with a significant portion of that time in cybersecurity roles. Five years of managerial experience leading, mentoring, and developing a technical team, with a significant portion of that time being with a cybersecurity-related team.
  • General Knowledge, Skills And Experience: Advanced knowledge of the various attack tactics, techniques, and practices used by threat actors, as well as networking technologies, protocols, and common security tools. Demonstrated ability to develop, improve, and exercise incident response plans and procedures. Significant experience with cyber incident response.
  • Additional Requirements: Ability to pass Criminal Justice Information Services (CJIS) background check within six months of hire.
  • Desired Qualifications: Knowledge of a breadth of technical domains, including one or more of servers, identity, cloud, database, and applications. Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification. Experience with red/purple/blue teaming, penetration testing, tabletop exercises, and other forms of assurance of cyber defenses and response readiness. Understanding of federal, state, and regulatory compliance drivers and requirements relevant to municipal governments and utility organizations. Experience leading union-represented staff. Experience successfully handling vendor relationships.

Similar jobs

Operations Manager

Allied UniversalMenomonee Falls, WI· 3 wk ago
Managementapply on diversifiedm-aus.icims.com

Operations Manager

Morgan Advanced MaterialsElkhart, IN· 1 mo ago
Managementapply on careers-morganplc.icims.com

Operations Manager

BrightView LandscapesBluffton, SC· 1 mo ago
Managementapply on brightviewcareers.com

OPERATIONS MANAGER

City Electric SupplyRockville, MD· 3 mo ago
Managementapply on paycomonline.net