Cyber Security Manager

City of Charlotte

$132K — $190K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Cybersecurity, Computer Science, or related field.
  • 6 years of experience in cybersecurity or information security roles.
  • Proven experience managing or leading security initiatives.
  • Professional cybersecurity certifications are preferred, such as CISSP or CISM.
  • Experience in securing operational technology environments.

Responsibilities

  • Develop and maintain cybersecurity operational practices.
  • Establish security priorities that align with organizational risk tolerance.
  • Lead the creation of cybersecurity policies, procedures, and standards.
  • Oversee monitoring for security threats and vulnerabilities.
  • Coordinate investigations and responses to cybersecurity incidents.
  • Conduct risk assessments across technology environments.
  • Serve as a cybersecurity advisor to Technology leadership.

Benefits

  • Comprehensive benefits package for eligible employees.
  • Potential for professional development opportunities.
  • Supportive working environment prioritizing security and operational continuity.
Full Job Description
Department: Charlotte Area Transit System Department

Salary: $132,310.00 - $190,195.04 Commensurate with Experience

SUMMARY
The Cyber Security Manager is responsible for development, implementation, and oversight of cybersecurity operations and risk management practices for the Charlotte Area Transit System (CATS). This position leads efforts to protect enterprise, operational, and infrastructure technology environments from cybersecurity threats while supporting reliable technology operations within a 24/7 transit environment.

The role establishes security practices, coordinates incident response activities, and ensures technology systems align with organizational security standards and regulatory expectations. The Cyber Security Manager works collaboratively across Infrastructure & Operations, Applications & Development, and Strategy & Quality teams to integrate security into system design, operations, and governance processes.

Working under limited direction, this position exercises independent judgment in identifying risks, prioritizing security initiatives, and guiding organizational cybersecurity maturity as CATS transitions toward increased operational independence.

Major Duties and Responsibilities:

The following duties are standard for this position. The omission of specific statements of duties does not exclude them from the classification if the work is similar, related, or a logical assignment for this classification.

Cybersecurity Program Leadership
  • Develop and maintain cybersecurity operational practices protecting infrastructure, applications, and operational technology systems.
  • Establish security priorities aligned with organizational risk tolerance.
  • Lead development of cybersecurity policies, procedures, and standards.
  • Promote security awareness across the organization.
  • Guide adoption of security-by-design principles.


Security Operations and Monitoring
  • Oversee monitoring of technology environments for security threats and vulnerabilities.
  • Coordinate investigation and response to cybersecurity incidents.
  • Direct containment, mitigation, and recovery activities.
  • Support implementation of monitoring and detection technologies.
  • Maintain incident response readiness.


Risk Management and Compliance
  • Conduct risk assessments across enterprise and operational technology environments.
  • Identify vulnerabilities and recommend mitigation strategies.
  • Support compliance with applicable regulatory and organizational requirements.
  • Maintain security documentation and risk registers.
  • Coordinate security audits and assessments.


Infrastructure and Application Security Coordination
  • Partner with Network Infrastructure Manager and Solutions Architect to ensure secure system design.
  • Support secure configuration and hardening practices.
  • Review technology implementations for security alignment.
  • Promote least-privilege and identity governance practices.
  • Support secure integration of operational technology systems.


Vendor and Third-Party Security Oversight
  • Evaluate cybersecurity posture of vendors and technology providers.
  • Support procurement reviews involving security considerations.
  • Monitor vendor compliance with security expectations.
  • Coordinate remediation of identified risks.


Organizational Collaboration and Advisory
  • Serve as cybersecurity advisor to Technology leadership.
  • Support business units in understanding security risks and responsibilities.
  • Provide guidance during technology projects and system implementations.
  • Communicate risk posture and security priorities to leadership.


Continuous Improvement and Security Maturity
  • Develop cybersecurity improvement roadmaps.
  • Track emerging threats and evolving best practices.
  • Recommend enhancements strengthening organizational resilience.
  • Support development of long-term cybersecurity capabilities.


Core Competencies:

The position requires demonstrated competency in the following areas

Cybersecurity Leadership and Governance

Ability to establish and guide organizational cybersecurity practices balancing protection with operational needs.
  • Defines practical security controls.
  • Aligns security with organizational risk tolerance.
  • Promotes accountability across technology domains.


Risk Evaluation and Decision Making

Ability to assess technical and operational risk in complex environments.
  • Identifies systemic vulnerabilities.
  • Prioritizes mitigation efforts.
  • Makes defensible risk-based recommendations.


Collaborative Technical Influence

Ability to integrate security into diverse technology environments through partnership and expertise rather than direct authority.
  • Builds trust across teams.
  • Influences system design decisions.
  • Encourages shared ownership of security outcomes.


Incident Leadership and Resilience

Ability to guide effective response during security events.
  • Maintains composure during incidents.
  • Coordinates cross-functional response.
  • Drives post-incident learning and improvement.


Supervision Given to:
  • Security Analyst(s)
  • Compliance and Risk Specialist


Minimum Qualifications:
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field; or equivalent combination of education and experience.
  • Six (6) years progressively responsible experience in cybersecurity or information security roles.
  • Experience managing or leading security initiatives or programs.

Preferred Qualifications:
  • Experience securing operational or infrastructure technology environments.
  • Experience supporting public-sector or transportation organizations.
  • Professional cybersecurity certifications (e.g., CISSP, CISM, Security+).
  • Experience developing cybersecurity programs or governance frameworks.


Knowledge, Skills and Abilities:

Knowledge of:
  • Cybersecurity frameworks and best practices.
  • Threat detection and incident response methodologies.
  • Identity and access management concepts.
  • Infrastructure and network security principles.
  • Vulnerability management and risk assessment practices.
  • Security considerations for operational technology environments.
  • Regulatory and compliance concepts affecting public-sector technology systems.


Skill in:
  • Evaluating cybersecurity risks and controls.
  • Leading incident response coordination.
  • Communicating technical risk to non-technical stakeholders.
  • Developing policies and operational procedures.
  • Analyzing security events and trends.
  • Facilitating cross-functional collaboration.


Ability to:
  • Exercise independent professional judgment in risk-based decision making.
  • Balance operational continuity with security protections.
  • Influence organizational behavior without direct authority.
  • Anticipate emerging threats and adapt strategies accordingly.
  • Build organizational awareness and shared responsibility for cybersecurity.


Working Environment and Physical Demands:
  • Work performed primarily in office environments with occasional visits to operational facilities.
  • Participation in cybersecurity incident response outside normal business hours may be required.
  • Requires prolonged computer use and analytical work.
  • Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.


HOW TO APPLY

Apply online.

You are welcome to visit the City of Charlotte Human Resources Department lobby, where self-service application kiosks are available. They are located in our office at 700 East 4th Street, Suite 200, Charlotte, NC 28202. We are open Monday through Friday, from 9:30 a.m. to 3:30 p.m. (EST), excluding official City holidays.

For questions about your application or the hiring process, please email [email protected]

BENEFITS

The City of Charlotte provides a comprehensive benefits package to eligible employees.

Click here to learn more about the City of Charlotte's benefits.

The City of Charlotte is a drug and alcohol-free workplace.

Similar Jobs

More Jobs at City of Charlotte

More Information Technology Jobs

Find similar Cyber Security Manager jobs: