IT Cybersecurity & Compliance Manager

Baker-Electric

$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in cybersecurity, compliance, or IT risk management.
  • Practical experience with at least one cybersecurity framework like NIST or ISO.
  • Experience coordinating audits and security program initiatives.
  • Familiarity with cybersecurity tools and managed service providers.
  • Working knowledge of identity and access management and cloud security concepts.
  • Strong written and verbal communication skills.
  • Excellent organizational and multitasking abilities.

Responsibilities

  • Coordinate daily execution of the cybersecurity and compliance programs with IT leadership.
  • Maintain and update cybersecurity plans, policies, and compliance artifacts.
  • Track and report progress on security initiatives, audit findings, and remediation activities.
  • Support the implementation of compliance frameworks such as NIST or CMMC.
  • Coordinate third-party audits and maintain audit readiness materials.
  • Partner with internal IT teams to ensure effective security operations and incident responses.
  • Develop and deliver cybersecurity education and awareness training for employees.

Benefits

  • Health insurance coverage.
  • Employee wellness program.
  • Life and disability insurance.
  • Retirement savings plan.
  • Employee-Owned Program (ESOP).
  • Paid holidays and paid time off (PTO).
Full Job Description
SUMMARY: The Manager of Cybersecurity and Compliance helps operate and mature Baker Electric's cybersecurity, risk, and compliance programs. This role is responsible for coordinating day-to-day program execution, maintaining core controls and evidence, supporting cybersecurity and compliance initiatives, and partnering with internal IT teams, business stakeholders, vendors, and consultants to reduce risk while enabling business operations.

This is a hands-on manager role for an early-to-mid level cybersecurity and compliance leader. The role does not have direct reports, but will manage vendor and consultant relationships, coordinate cross-functional work, and mentor aspiring cybersecurity and compliance talent within the IT Operations team through a dotted-line partnership.

ESSENTIAL DUTIES & RESPONSIBILITIES:

Cybersecurity and Compliance Program Operations
  • Coordinate day-to-day execution of Baker Electric's cybersecurity, risk, and compliance activities in partnership with the Director of IT Operations.
  • Maintain cybersecurity and compliance plans, policies, standards, procedures, evidence repositories, and recurring program artifacts.
  • Track progress on security and compliance initiatives, risks, exceptions, audit findings, and remediation activities.
  • Prepare regular updates, metrics, and status reporting for IT leadership and appropriate business stakeholders.


Governance, Risk, and Compliance
  • Support implementation and ongoing improvement of compliance programs such as NIST Cybersecurity Framework, NIST SP 800-171, CMMC Level 2, CIS Controls, or equivalent frameworks.
  • Maintain and update System Security Plans, Plans of Action and Milestones, control evidence, assessment records, and audit-readiness materials.
  • Coordinate internal reviews, external assessments, third-party audits, and follow-up actions with vendors, consultants, and internal teams.
  • Translate compliance requirements into practical action plans for IT Operations, Service Desk, Infrastructure, Applications, and business teams.


Security Operations Coordination
  • Coordinate vulnerability management, endpoint protection, identity and access management, security monitoring, logging, incident response readiness, and remediation activities.
  • Partner with internal IT teams and external service providers to ensure security tools, alerts, tickets, and remediation work are followed through to completion.
  • Support incident response planning, tabletop exercises, post-incident documentation, and continuous improvement actions.
  • Manage third-party security reviews and vendor risk follow-up for technology providers and critical business systems.


Vendor, Consultant, and Cross-Functional Leadership
  • Manage day-to-day working relationships with cybersecurity and compliance vendors, consultants, assessors, managed service providers, and other external partners.
  • Clarify deliverables, timelines, responsibilities, and communication expectations for external partners and internal contributors.
  • Coordinate work across teams without relying on formal reporting authority, holding stakeholders accountable to agreed-upon actions and deadlines.
  • Escalate risks, resource needs, and prioritization conflicts to the Director of IT Operations with clear options and recommendations.


Cybersecurity Awareness and Team Baker Education
  • Develop practical cybersecurity and compliance education for Team Baker, including recurring awareness content, targeted communications, and training materials.
  • Partner with IT, HR, Safety, Operations, and other business leaders to make cybersecurity expectations clear, relevant, and actionable.
  • Promote a culture of shared ownership, accountability, and care for others through simple, consistent security practices.
  • Measure and improve awareness program effectiveness using available training metrics, incident trends, simulated phishing results, or other relevant indicators.


Mentorship and Dotted-Line Talent Development
  • Mentor IT Operations team members who are developing cybersecurity and compliance skills.
  • Provide coaching, learning assignments, and guidance on security operations and compliance fundamentals in partnership with the Service Desk Manager.
  • Help identify opportunities for IT Operations team members to contribute to security-related tickets, evidence gathering, and process improvements.
  • Model Baker's TRAC values and OneBaker leadership through collaboration, follow-through, accountability, and care for others.


EXPERIENCE, EDUCATION:

Required Qualifications
  • At least 3 to 5 years of experience in cybersecurity, information security, compliance, IT risk management, security operations, or a closely related IT discipline.
  • Practical experience supporting at least one cybersecurity or compliance framework, such as NIST Cybersecurity Framework, NIST SP 800-171, CMMC, CIS Controls, ISO 27001, or equivalent.
  • Experience coordinating audits, assessments, evidence collection, control testing, vulnerability remediation, or security program initiatives.
  • Experience working with cybersecurity tools, managed security providers, consultants, or external assessors.
  • Working knowledge of identity and access management, endpoint security, vulnerability management, security monitoring, incident response, Microsoft 365 security, Entra ID, and cloud security concepts.
  • Strong written and verbal communication skills, including the ability to explain security and compliance topics to technical and non-technical audiences.
  • Strong organization, follow-through, judgment, discretion, and ability to manage competing priorities.


Preferred Qualifications
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • Relevant certifications such as Security+, CySA+, SSCP, GSEC, CISM, CISSP, CRISC, Certified CMMC Professional, Certified CMMC Assessor, or equivalent.
  • Experience with Microsoft Defender, Purview, Sentinel, Intune, Azure security services, or similar platforms.
  • Experience developing cybersecurity awareness communications, training content, dashboards, scorecards, or leadership reporting.
  • Experience in construction, engineering, manufacturing, government contracting, or other distributed operations environments.


PAY TRANSPARENCY:
The starting salary for this opportunity range is listed. Other rewards may include annual bonus eligibility based on company and individual performance, short- and long-term incentives, and program-specific awards. Baker provides a variety of benefits to employees, including health insurance coverage, an employee wellness program, life and disability insurance, a retirement savings plan, an Employee-Owned Program (ESOP), paid holidays, and paid time off (PTO). A candidate's salary history will not be used in compensation decisions. Please note that the compensation information is a good-faith estimate for this position. It assumes a rate based on location and experience.

We thank all applicants in advance for their interest in this position; however, only those selected for an interview will be contacted. If you are selected for an interview, a Baker Recruiter will contact you directly from our organization with a [redacted]-electric.com email.

Similar Jobs

More Jobs at Baker-Electric

More Information Technology Jobs

Find similar IT Cybersecurity & Compliance Manager jobs: