The Cybersecurity Manager serves as both the operational leader of the Cybersecurity function and the organization's primary cybersecurity architect. This role is responsible for leading day-to-day cybersecurity operations, driving timelines for initiatives, executing the cybersecurity strategy set by the Director - Cybersecurity & Business Continuity, supporting the Director in developing that strategy, and implementing and maintaining security architecture standards, overseeing awareness and training programs, and ensuring security is embedded into enterprise technology decisions.
Reporting to the Director - Cybersecurity & Business Continuity, this role provides leadership to cybersecurity personnel, monitors emerging threats and industry trends, and ensures the organization maintains a strong security posture.
The Cybersecurity Manager partners closely with Information Technology, Internal Audit, Legal, Human Resources, and business leaders to execute cybersecurity strategies that align with company objectives while reducing risk and to support the Director in developing those strategies. This individual is expected to remain current on evolving threats, technologies, and regulatory requirements and translate those developments into actionable recommendations for the organization.
Key ResponsibilitiesCybersecurity Program Leadership- Lead the day-to-day operations of the Cybersecurity team.
- Provide strong timeline management for multiple competing projects.
- Develop and execute cybersecurity initiatives aligned with the organization's strategic objectives.
- Recommend and implement program goals, priorities, metrics, and performance measures.
- Provide leadership, coaching, mentoring, and performance management for cybersecurity personnel.
- Develop and maintain cybersecurity reference architectures, standards, and design for review and approval by the Director.
- Review and approve security requirements for new applications, infrastructure, cloud platforms, and technology initiatives.
- Develop and maintain security roadmaps for identity management, cloud security, endpoint protection, data protection, network security, and threat detection for review and approval by the Director.
Governance, Risk & Compliance- Maintain and enhance cybersecurity policies, standards, procedures, and governance processes.
- Partner with the Director - Cybersecurity & Business Continuity to identify, assess, and manage cybersecurity and sensitive data risks.
- Support compliance initiatives including SOX, IT General Controls (ITGC), and applicable regulatory requirements.
- Track risk mitigation efforts and ensure timely resolution of identified issues.
Security Operations & Incident Response- Oversee security monitoring, threat detection, vulnerability management, and incident response activities.
- Ensure cybersecurity controls are operating effectively and aligned with industry best practices.
- Lead investigations and response efforts related to cybersecurity events and incidents.
- Coordinate with IT teams to prioritize and remediate security vulnerabilities.
- Coordinate third-party cybersecurity assessments, audits and vendor security reviews.
Security Awareness & Training- Develop, implement, and manage the enterprise cybersecurity awareness program.
- Develop targeted awareness programs for executives, employees, contractors, and privileged users.
- Measure and report on program effectiveness through established metrics and key performance indicators.
- Promote cybersecurity awareness as a shared organizational responsibility.
Essential Competencies- People Leadership & Coaching - Demonstrated ability to supervise, develop, and motivate a technical team. Skilled at building team culture and individual accountability. Provides clear performance expectations, technical feedback, and career development support tailored to individual strengths.
- Change Management - Ability to lead a team through significant operational change - communicating vision, managing uncertainty, and bringing people along as the security environment can quickly evolve.
- Technical Credibility - Strong enough technical background to engage in incident and log analysis, evaluate solutions, and provide informed direction without taking over the work.
- Prioritization & Judgment - Comfortable managing competing demands across support and strategic work; able to make sound triage decisions under pressure and balance reactive support needs with proactive improvement initiatives.
- Resilience & Adaptability- Thrives in a fast-changing environment where tools, platforms, and priorities evolve rapidly.
- Calm & Effective Communication- Maintains a calm and communicative presence in difficult situations. Communicates effectively to multiple audiences from technical to executive.
Security Tools and Platform Experience- SIEM platforms, detect and response activities and coordinating with partners.
- Email security platforms, mail flow standards and rules, phishing simulations
- Endpoint detection and response platforms, asset inventory understanding
- Vulnerability scanning, management and mitigation through patching processes
- DNS, DHCP, content and web filtering
- Firewall and network security policy understanding
- Physical security access control and video management systems
QualificationsRequired- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.
- 8+ years of progressive cybersecurity experience.
- 3+ years of leadership or management experience.
- Strong communication, presentation, and relationship management skills.
Preferred Certifications- CISSP
- CISM
- CRISC
- CCSP
- GIAC certifications
Location:This is a Denver based hybrid role.
SM Energy offers competitive compensation and benefits programs which include, but are not limited to, variable pay, health care coverage, retirement plan, protection coverage, time off and leave programs, training and development opportunities and a range of allowances connected to specific work situations. Details are available at Careers :: SM Energy Company (SM) (sm-energy.com).
Applications will be accepted on an ongoing basis until the position is filled.