Manager, Cyber Security

HTS Engineering Ltd

$150K — $170K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in a cybersecurity management role.
  • Hands-on experience with EDR/XDR, SIEM, and vulnerability management tools.
  • Strong understanding of cybersecurity frameworks including NIST, ISO 27001, and CIS Controls.
  • Proficient in incident response, threat detection, and digital forensics.
  • Excellent leadership and communication skills for technical and executive audiences.

Responsibilities

  • Lead the execution of the organization's cybersecurity strategy and improvement initiatives.
  • Manage day-to-day cybersecurity operations, ensuring timely detection and response to security events.
  • Oversee incident response activities and vulnerability management processes.
  • Support compliance with frameworks such as SOC 2 and NIST by maintaining governance policies.
  • Collaborate with cross-functional teams to integrate security into technology solutions.

Benefits

  • Development of cybersecurity awareness initiatives.
  • Opportunities for professional growth and continuous improvement.
  • Involvement in innovative projects including AI governance and Secure DevOps practices.
Full Job Description
Reporting to the Head of Cyber Security, the Manager of Cyber Security is responsible for leading and managing key components of the organization's cybersecurity program, working closely with the Head of Cyber Security to execute security strategies, initiatives, and priorities. The role provides leadership across cybersecurity governance, risk management, security operations, vulnerability management, incident response, compliance, and security assurance. The Manager oversees the implementation and effectiveness of security controls, identifies and manages cyber risks, leads security improvement initiatives, and ensures alignment with regulatory requirements, industry standards, and organizational policies. The role works collaboratively with ITOps, Support Services, Business Solutions and other business stakeholders to strengthen the organization's cybersecurity posture, address emerging threats, support security awareness, and drive continuous improvement in the overall security program.

Major Responsibilities:

Cybersecurity Strategy Execution and Program Delivery
  • Partner with the Head of Cyber Security to execute the organization's cybersecurity strategy, roadmap, and security improvement initiatives.
  • Translate cybersecurity strategies and objectives into actionable programs, operational plans, and measurable outcomes.
  • Lead assigned cybersecurity projects and initiatives that improve security maturity, reduce risk, and enhance operational resilience.
  • Provide regular updates to the Head of Cyber Security on security posture, risks, challenges, initiatives, and opportunities for improvement.
  • Identify opportunities to enhance cybersecurity processes, capabilities, and services.

Security Operations Management
  • Manage day-to-day cybersecurity operations, ensuring effective monitoring, detection, response, and remediation of security events.
  • Oversee incident response activities, including investigation, containment, recovery, root cause analysis, and lessons learned.
  • Manage vulnerability management processes, including vulnerability identification, prioritization, remediation tracking, and reporting.
  • Ensure cybersecurity controls and operational processes remain effective and aligned with organizational requirements.
  • Must have hands on experience with Tools - EDR/XDR, SIEM, Forensics, Vulnerability scanners, Cloud Security, Firewalls

Cybersecurity Governance, Risk, and Compliance
  • Support the Head of Cyber Security in maintaining cybersecurity governance frameworks, policies, standards, and procedures.
  • Manage security documentation and evidence requirements for audits, assessments, and compliance activities.
  • Support ongoing compliance programs, including SOC 2, ISO 27001, NIST, and other applicable security frameworks.
  • Develop and maintain cybersecurity metrics, dashboards, and KPIs to measure security performance and improvement.
  • Assist with security risk assessments and development of risk mitigation plans.

Security Architecture and Technology Enablement
  • Provide cybersecurity guidance and recommendations for infrastructure, applications, cloud services, and technology initiatives.
  • Partner with IT Operations, Business Solutions, and development teams to integrate security into technology solutions.
  • Support Secure DevOps (DevSecOps) practices by promoting security throughout the software development lifecycle.
  • Support security reviews for emerging technologies, including artificial intelligence initiatives and AI governance requirements.

Security Service Delivery and Operational Improvement
  • Support the continued development and maturity of cybersecurity service delivery capabilities.
  • Assist in defining repeatable processes, operational procedures, and service standards that improve quality, efficiency, and scalability.
  • Partner with the Head of Cyber Security to advance cybersecurity capabilities, including Managed Security Services (MSSP) offerings where applicable.
  • Identify opportunities for automation, process optimization, and improved service delivery.

Security Awareness and Culture
  • Support the development and delivery of cybersecurity awareness initiatives.
  • Promote security best practices through training, communications, presentations, and engagement activities.
  • Encourage a culture of security awareness and shared responsibility across the organization.

Third-Party and Vendor Security
  • Support third-party security assessments and vendor risk management activities.
  • Review security requirements for external providers and technology partners.
  • Collaborate with vendors and partners to address security risks and improve security outcomes.

Cybersecurity Strategy Execution and Program Delivery
  • Partner with the Head of Cyber Security to execute the organization's cybersecurity strategy, roadmap, and security improvement initiatives.
  • Translate cybersecurity strategies and objectives into actionable programs, operational plans, and measurable outcomes.
  • Lead assigned cybersecurity projects and initiatives that improve security maturity, reduce risk, and enhance operational resilience.
  • Provide regular updates to the Head of Cyber Security on security posture, risks, challenges, initiatives, and opportunities for improvement.
  • Identify opportunities to enhance cybersecurity processes, capabilities, and services.

Security Operations Management
  • Manage day-to-day cybersecurity operations, ensuring effective monitoring, detection, response, and remediation of security events.
  • Oversee incident response activities, including investigation, containment, recovery, root cause analysis, and lessons learned.
  • Manage vulnerability management processes, including vulnerability identification, prioritization, remediation tracking, and reporting.
  • Ensure cybersecurity controls and operational processes remain effective and aligned with organizational requirements.
  • Must have hands on experience with Tools - EDR/XDR, SIEM, Forensics, Vulnerability scanners, Cloud Security, Firewalls

Cybersecurity Governance, Risk, and Compliance
  • Support the Head of Cyber Security in maintaining cybersecurity governance frameworks, policies, standards, and procedures.
  • Manage security documentation and evidence requirements for audits, assessments, and compliance activities.
  • Support ongoing compliance programs, including SOC 2, ISO 27001, NIST, and other applicable security frameworks.
  • Develop and maintain cybersecurity metrics, dashboards, and KPIs to measure security performance and improvement.
  • Assist with security risk assessments and development of risk mitigation plans.

Security Architecture and Technology Enablement
  • Provide cybersecurity guidance and recommendations for infrastructure, applications, cloud services, and technology initiatives.
  • Partner with IT Operations, Business Solutions, and development teams to integrate security into technology solutions.
  • Support Secure DevOps (DevSecOps) practices by promoting security throughout the software development lifecycle.
  • Support security reviews for emerging technologies, including artificial intelligence initiatives and AI governance requirements.

Security Service Delivery and Operational Improvement
  • Support the continued development and maturity of cybersecurity service delivery capabilities.
  • Assist in defining repeatable processes, operational procedures, and service standards that improve quality, efficiency, and scalability.
  • Partner with the Head of Cyber Security to advance cybersecurity capabilities, including Managed Security Services (MSSP) offerings where applicable.
  • Identify opportunities for automation, process optimization, and improved service delivery.

Security Awareness and Culture
  • Support the development and delivery of cybersecurity awareness initiatives.
  • Promote security best practices through training, communications, presentations, and engagement activities.
  • Encourage a culture of security awareness and shared responsibility across the organization.

Third-Party and Vendor Security
  • Support third-party security assessments and vendor risk management activities.
  • Review security requirements for external providers and technology partners.
  • Collaborate with vendors and partners to address security risks and improve security outcomes.

Leadership and Collaboration
  • Provide leadership, coaching, and guidance to cybersecurity team members.
  • Foster collaboration across Cyber Security, IT Operations, Business Solutions, Help Desk, and business teams.
  • Build strong relationships with stakeholders to ensure security requirements are understood and effectively implemented.
  • Demonstrate accountability, ownership, and continuous improvement in all cybersecurity activities.

Strategy & Planning:
  • Develop and execute the organization's cybersecurity strategy, roadmap, and priorities.
  • Align cybersecurity initiatives with business objectives, risk tolerance, and regulatory requirements.
  • Lead cybersecurity risk assessments and establish priorities for risk reduction.
  • Define cybersecurity goals, performance metrics, and security maturity targets.
  • Develop and manage the cybersecurity program roadmap, budget, resources, and priorities.
  • Evaluate emerging threats, technologies, and industry trends to inform security strategy.
  • Establish and maintain cybersecurity governance, policies, standards, and frameworks.
  • Lead strategic planning for security operations, incident response, vulnerability management, compliance, and risk management.
  • Identify security gaps and develop remediation and continuous-improvement plans.
  • Partner with IT and business leadership to integrate security into technology and business initiatives.
  • Provide cybersecurity risk, performance, and investment recommendations to senior leadership.
  • Ensure cybersecurity strategies support business continuity, resilience, and organizational objectives.


Working Conditions:
  • Work Environment: Work environment consisting of 5 days in the office.
  • Fast-Paced Environment: Fast-paced environment with tight deadlines.
  • Transportation: Reliable access to personal transportation is a requirement.
  • Knowledge of incident response, threat detection, threat hunting, and digital forensics.
  • Experience developing and maintaining security controls, policies, standards, and technical baselines.
  • Strong understanding of cybersecurity frameworks including NIST CSF, NIST 800-53, ISO 27001, CIS Controls, and MITRE ATT&CK.
  • Experience with security assessments, vulnerability management, penetration testing, and remediation programs.
  • Ability to analyze security metrics, logs, dashboards, risk reports, and threat intelligence.
  • Knowledge of security architecture and secure technology design principles.
  • Experience managing security tools, configurations, integrations, and technology lifecycles.
  • Familiarity with automation, scripting, APIs, and security orchestration to improve operational efficiency.
  • Ability to evaluate cybersecurity technologies, conduct technical reviews, and make security investment recommendations.
  • Experience developing security KPIs/KRIs, dashboards, and executive-level reporting.
  • Strong understanding of business continuity, disaster recovery, and cybersecurity resilience.

Skills:
  • Strong leadership and people-management skills.
  • Excellent strategic thinking and decision-making abilities.
  • Strong communication and presentation skills with technical and executive audiences.
  • Ability to translate complex cybersecurity risks into business impacts.
  • Strong problem-solving, analytical, and critical-thinking skills.
  • Ability to prioritize competing risks, projects, and operational demands.
  • Strong stakeholder management and cross-functional collaboration skills.
  • Ability to build effective relationships with IT, business, risk, audit, legal, and executive teams.
  • Strong project and program management skills.
  • Ability to manage and resolve security incidents and high-pressure situations effectively.
  • Strong negotiation, influencing, and conflict-resolution skills.
  • High level of accountability, integrity, and professional judgment.
  • Ability to mentor, coach, and develop cybersecurity staff.
  • Adaptability and willingness to stay current with emerging threats, technologies, and regulatory requirements.

Salary: $150K-$170K

Similar Jobs

More Jobs at HTS Engineering Ltd

More Information Technology Jobs

Find similar Manager, Cyber Security jobs: