Senior Cyber Security & Infrastructure Lead # 26-19574
US Tech Solutions · Cuyahoga Falls, OH · 2 wk ago
Information TechnologyContract
Duration: 6+ months
About Us
US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions.
Qualifications
- 10+ years of progressive information security or cybersecurity experience, including significant responsibility for enterprise security programs.
- Demonstrated experience leading cybersecurity strategy, governance, risk management, security operations, and incident response.
- Strong understanding of enterprise security architecture, network security, endpoint security, cloud security, identity and access management, and data protection.
- Experience implementing or operating cybersecurity programs aligned with the NIST Cybersecurity Framework or a comparable control framework.
- Demonstrated experience managing vulnerability remediation and cybersecurity risk across complex enterprise environments.
- Experience leading significant cybersecurity incidents and communicating effectively with both technical and executive audiences.
- Strong vendor-management and third-party risk-management capabilities.
- Demonstrated ability to operate effectively in an environment requiring both strategic leadership and hands-on problem solving.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline, or equivalent relevant experience.
Responsibilities
Cybersecurity Strategy & Leadership
- Own and execute the enterprise cybersecurity strategy and multi-year security roadmap.
- Serve as the organization's senior cybersecurity subject-matter expert and advisor to IT and business leadership.
- Translate technical cybersecurity risks into clear business impact, priorities, and investment recommendations.
- Establish measurable security objectives, key risk indicators, and executive-level reporting.
- Develop business cases and recommendations for security investments based on risk reduction, business value, and total cost of ownership.
Governance, Risk & Compliance
- Lead the continued development and maturity of the enterprise cybersecurity program using the NIST Cybersecurity Framework and other applicable standards and leading practices.
- Maintain and enforce cybersecurity policies, standards, procedures, and control frameworks.
- Own the enterprise cyber risk assessment process and maintain visibility into material cybersecurity risks and remediation plans.
- Partner with Legal, Internal Audit, technology teams, and business stakeholders to support regulatory, contractual, insurance, and audit requirements.
Security Operations & Incident Response
- Provide leadership and oversight for enterprise security monitoring, detection, investigation, containment, and response.
- Maintain and continuously improve cybersecurity incident response plans, playbooks, escalation procedures, and crisis-management processes.
- Lead the organization's response to significant cybersecurity incidents and coordinate activities across technology, leadership, Legal, communications, and third parties as necessary.
Security Architecture & Engineering
- Partner with infrastructure, cloud, network, application, and enterprise architecture teams to embed security into technology design and operations.
- Provide security review and approval for significant technology initiatives and architectural changes.
- Establish and maintain appropriate security controls across identity and access management, endpoint security, networks, cloud environments, email, data protection, and enterprise applications.
- Promote secure configuration, least privilege, segmentation, encryption, and modern identity-security practices.
- Evaluate cybersecurity technologies and recommend changes based on capability, risk, cost, and operational effectiveness.
Security Awareness & Culture
- Own the enterprise cybersecurity awareness and education program.
- Develop targeted security education for employees, technology teams, privileged users, and executives.
- Use phishing exercises, awareness metrics, incident trends, and other data to identify and address areas of human risk.
- Build a culture in which cybersecurity is viewed as a shared business responsibility rather than solely an IT function.
Vendor & Partner Management
- Provide security oversight for strategic cybersecurity vendors, managed service providers, and technology partners.
- Establish performance expectations and hold providers accountable for service quality, risk reduction, and contractual obligations.
- Participate in vendor selection, contract reviews, renewals, and security-related negotiations.
- Identify opportunities to simplify the security technology portfolio and improve value from cybersecurity investments.