Manager, Cybersecurity

Smoothie King

$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
  • Seven or more years of progressive cybersecurity experience, including at least three years in a leadership role.
  • Demonstrated expertise in security operations, incident response, and vulnerability management across various platforms.
  • Experience collaborating with SOC/MSSP, security vendors, auditors, and penetration testing firms.
  • Preferred experience in retail, restaurant, or franchise environments that cover multiple locations.
  • Relevant cybersecurity certifications such as CISSP, CISM, CCSP, Microsoft Security, or GIAC are preferred.

Responsibilities

  • Own the identification, prioritization, and remediation of cybersecurity risks.
  • Execute and enhance the cybersecurity strategy in line with business objectives.
  • Provide operational security leadership across various IT domains including Azure and network infrastructure.
  • Evaluate and escalate cybersecurity risks with actionable recommendations.
  • Lead incident response initiatives and manage relationships with external security partners.
  • Oversee cybersecurity compliance activities, including assessments and remediation efforts.
  • Communicate cybersecurity metrics and proposed actions to leadership.

Benefits

  • Flexible work schedules to promote work-life balance.
  • Free smoothies and periodic office lunches to foster a fun work culture.
  • Monthly fitness challenges and free gym access to support employee health.
  • A collaborative and upbeat team atmosphere that values core principles for team engagement.
  • Engagement in community and fun activities that enhance employee satisfaction and team spirit.
Full Job Description
Overview

The Manager, Cybersecurity is responsible for the day-to-day leadership and execution of Smoothie King's cybersecurity program and security operations. This role independently assesses risk, establishes priorities, recommends appropriate courses of action, and drives security issues through remediation and closure.

The role requires sufficient technical depth to evaluate security findings, telemetry, vulnerabilities, architecture, and control gaps; provide informed direction to technical teams and vendors; and balance immediate risk reduction with longer-term program maturity.

  • Own the identification, prioritization, remediation, validation, and closure of cybersecurity risks and findings, prioritizing immediate risk reduction while maintaining disciplined scope.
  • Execute and continuously improve cybersecurity strategy, standards, policies, and procedures in alignment with business objectives and established risk tolerance.
  • Provide technical and operational security leadership across Azure, identity, endpoint, network, infrastructure, vulnerability management, and security monitoring.
  • Evaluate cybersecurity risk, determine appropriate courses of action, and escalate material risks with clear recommendations.
  • Lead cybersecurity incident response and oversee SOC and managed security partners through investigation, containment, remediation, recovery, and corrective action.
  • Lead cybersecurity compliance and assurance activities, including PCI DSS, security assessments, penetration testing, and remediation of identified gaps.
  • Partner with technology and business teams to integrate appropriate security controls without unnecessarily impeding delivery.
  • Manage cybersecurity vendors, third-party risk activities, and assigned budgets, holding partners accountable for performance and outcomes.
  • Develop and communicate cybersecurity KPIs, risk metrics, material risks, and recommendations to leadership.
  • Lead cybersecurity awareness initiatives and drive security projects to measurable outcomes with clear ownership and timelines.
  • Stay current on emerging threats and technologies and translate relevant developments into practical security improvements.

Responsibilities

  • Strong understanding of cybersecurity frameworks and risk management practices, including NIST, CIS Controls, ISO 27001, and PCI DSS.
  • Strong technical knowledge across Azure/Entra ID, identity, endpoint, network, vulnerability management, logging, monitoring, and threat detection.
  • Ability to independently assess security findings, telemetry, attack paths, vulnerabilities, and control gaps.
  • Strong risk-based judgment and bias for action, including the ability to make timely decisions under ambiguity, prioritize remediation, and escalate material risks with clear recommendations.
  • Demonstrated experience leading incident response, vulnerability remediation, security assessments, penetration testing, and audit activities through closure.
  • Experience managing cybersecurity vendors, SOC providers, third-party risk, budgets, and resources.
  • Strong people leadership, execution discipline, and ability to drive multiple initiatives to measurable outcomes.
  • Strong written and verbal communication skills with the ability to translate technical issues into clear business risk and recommendations.
  • Ability to constructively challenge technical teams, vendors, and assumptions while maintaining effective cross-functional relationships.
  • Proactive, accountable mindset focused on measurable risk reduction and operational execution.
  • Education and Experience
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
  • Seven or more years of progressive cybersecurity experience, including at least three years leading security operations, programs, significant initiatives, or teams.
  • Demonstrated experience across security operations, incident response, vulnerability management, identity, endpoint, network and cloud security, security monitoring, and compliance.
  • Experience working with SOC/MSSP providers, security vendors, auditors, penetration testing firms, and cross-functional technology teams.
  • Experience in retail, restaurant, franchise, or another distributed multi-location environment is preferred.
  • Relevant certifications such as CISSP, CISM, CCSP, Microsoft Security, or GIAC are preferred.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
  • Seven or more years of progressive cybersecurity experience, including at least three years leading security operations, programs, significant initiatives, or teams.
  • Demonstrated experience across security operations, incident response, vulnerability management, identity, endpoint, network and cloud security, security monitoring, and compliance.
  • Experience working with SOC/MSSP providers, security vendors, auditors, penetration testing firms, and cross-functional technology teams.
  • Experience in retail, restaurant, franchise, or another distributed multi-location environment is preferred.
  • Relevant certifications such as CISSP, CISM, CCSP, Microsoft Security, or GIAC are preferred.

What We Offer

Join our team and enjoy an unusually fun work environment with an upbeat atmosphere and great team members. It is our purpose to maintain an environment our team members can brag about, where our focus and belief are built on our core values: We Are Better Together, We Keep Evolving, We Live Our Mission, We Do the Right Thing, and We Focus and Finish. With our core values at the forefront of every decision we make, it allows for collaboration, passion, and a no-limits mindset when it comes to your future! We keep our team happy with our great benefits package, free smoothies, flexible work schedules, office lunches and parties, monthly fitness challenges, free gym access, and more fun activities to make Smoothie King a happy and healthy place to work.

Similar Jobs

More Jobs at Smoothie King

More Information Technology Jobs

Find similar Manager, Cybersecurity jobs: