Sr. Cybersecurity Manager
ACCO Brands · Lake Zurich, IL · 2 days ago
HybridInformation Technology$140k–$180k/yrFull-time
Responsibilities
- Strategy, Governance & Risk
- Partner with the VP of Global Cybersecurity and Infrastructure to align security initiatives with enterprise risk posture, compliance obligations, and business objectives.
- Leverage external security benchmarking and maturity assessments to develop cybersecurity performance metrics for executive leadership.
- Represent Cybersecurity in enterprise-level initiatives and governance councils.
- Define and track key performance indicators and control metrics aligned with NIST CSF functions.
- Contribute to and enforce cybersecurity policies, standards, and procedures.
- Team Leadership & Development
- Lead, mentor, and manage a team of cybersecurity analysts and security engineers.
- Career development and goal setting.
- Security Operations & Incident Response
- Oversee daily security operations, including monitoring, triage, and incident response.
- Support the VP of Global Cybersecurity and Infrastructure during the cybersecurity incident response process.
- Manage continuous threat detection, intelligence gathering, and escalation procedures.
- Guide analysts and engineers responsible for managing tools such as Proofpoint, Cisco Umbrella, SSO/MFA platforms, and next-generation firewalls.
- Vulnerability & Threat Management
- Manage the enterprise vulnerability management lifecycle.
- Collaborate with IT and infrastructure teams to validate remediation plans.
- Ensure alignment with security strategy and best practices.
- Cloud & Application Security
- Oversee the development, implementation, and management of cloud security controls within Microsoft Azure and other cloud providers.
- Collaborate with application development teams to integrate security practices into the SDLC.
- Evaluate and enhance application security policies, secure coding practices, and code review procedures.
- Ensure secure configurations and identity management across cloud-native platforms.
- Vendor, Third-Party & Awareness Programs
- Design and roll out a Third-Party Risk Management program.
- Manage vendor relationships and evaluate security tools and technologies.
- Own the strategy and execution of the enterprise-wide security awareness program.
- Bachelor's degree in Information Security, Computer Science, or a related field, or equivalent work experience.
- 10+ years of progressive experience in cybersecurity, including at least 2 years in a leadership or supervisory capacity.
- Demonstrated experience managing security operations, incident response, and vulnerability remediation in cloud environments.
- Experience working with Managed Security Service Providers (MSSPs).
- Strong working knowledge of security tooling, including SIEM platforms, EDR, and email security gateways.
- Hands-on familiarity with Cisco Umbrella, Microsoft 365 security, SSO/MFA, NGAV/EDR, and enterprise firewall platforms.
- Solid understanding of enterprise IT, networking, identity and access management, encryption, and SIEM architecture.
- Familiarity with security frameworks such as NIST CSF, ISO 27001, or CIS Controls.
- Proven ability to manage competing priorities across multiple teams and time zones.
- Excellent verbal and written communication skills, with the ability to translate technical risk into business terms for executive audiences.
- Strong collaboration and stakeholder management skills across IT, business units, and external partners.