DescriptionJob SummaryAs the Manager, Information Security (Threat & Vulnerability Management), you will serve in a highly technical "player-coach" leadership role, requiring a blend of hands-on engineering and project/people management. Reporting directly to the Director of Cyber & Information Security, you will lead the specialized Threat & Vulnerability Management functional pillar within the department. While managing and mentoring a team of cross-trained Cybersecurity Engineers and overseeing domain-specific projects, you act as the ultimate technical escalation point for your domain. The ideal candidate actively implements technologies, drives complex incident response, oversees vulnerability mitigation, and translates high-level business risk into day-to-day technical operations.
Key Responsibilities- Threat Management:
- Provides operational oversight of all Threat and Vulnerability Management systems, technologies, processes, and reporting.
- Actively manages and tunes Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platforms.
- Leads the coordination of technical data and evidence collection during moderate-to-severe security incidents, supporting the Director who serves as the overarching Incident Commander.
- Integrates global threat intelligence feeds and analyzes Indicators of Compromise (IoCs) to proactively fortify network and endpoint defenses.
- Develops, maintains, and automates technical Incident Response playbooks utilizing Security Orchestration, Automation, and Response (SOAR) concepts to accelerate threat containment.
- Leads the threat modeling and security posture management of enterprise Artificial Intelligence (AI) and Machine Learning (ML) systems, defending against adversarial threats (e.g., prompt injection, model poisoning), while leveraging AI-driven analytics to accelerate threat detection and streamline vulnerability prioritization.
- Vulnerability Management:
- Drives enterprise vulnerability scanning and coordinates internal or external penetration testing exercises, prioritizing risks and leading cross-functional remediation efforts.
- Collaborates with system owners to evaluate the technical risk of identified vulnerabilities and architects compensating controls when immediate patching is not possible.
- Documentation & Stakeholder Communication:
- Leads efforts to create, document, and continuously maintain Standard Operating Procedures (SOPs) for technical TVM workflows and departmental processes.
- Translates complex technical security risks into clear operational impacts for peer IT leaders.
- Customer & Project Support:
- Partners closely with other IT departments (Infrastructure, Networking, Software Development) to integrate security controls into their respective business projects without disrupting velocity.
- Executes the technical rollout of new threat and vulnerability vendor products from proof-of-concept to full enterprise deployment.
- Leads, tracks, and executes security-focused projects from inception to completion, ensuring milestones, Service Level Agreements (SLAs), and Mean Time to Resolve (MTTR) metrics are met for the TVM pillar.
- Manages relationships with critical security vendors, ensuring platforms are properly deployed, maintained, and delivering maximum ROI.
- Continuous Improvement & Operations:
- Manages, mentors, and develops a high-performing team of technical Cybersecurity Engineers.
- Handles all core HR responsibilities, including performance evaluations, hiring, goal setting, and guiding career ladder progression.
- Researches new security processes and emerging TVM technologies, evaluating their efficacy and presenting formal recommendations for changes to department leadership.
- Drives the department's cross-domain training goals, ensuring team members build proficiency outside their primary operational focus to maintain a well-rounded, agile workforce.
- Identity & Access Management (IAM):
- Partners closely with the IAM pillar to correlate identity-based threats, investigate authentication anomalies, and enforce automated access revocations during active security incidents.
Travel Information- Occasional Domestic Occasional travel may be required to attend industry conferences, participate in professional training, or support operations at remote office locations.
QualificationsEducation- Bachelor's degree or equivalent experience Bachelor's degree or equivalent experience in a computer-related field such as Computer Science, Mathematics, or Engineering. Master's or other advanced degree is preferred. Req
Work Experience- 10-15 years 10 - 15+ years of progressive, hands-on experience within the Information Security or Cybersecurity field. Req
- 2-4 years Readiness for first-tier management of direct people and project management experience. Req
Licenses and Certifications - Relevant professional management and engineering certifications such as ISACA CISM, (ISC)² CISSP, or equivalent senior-level architecture certifications are highly preferred. Upon Hire Pref
Skills and Requirements - Technical Skills & Concepts:
- Deep, proven engineering experience operating at a Senior or Lead level strictly within Threat Management and Vulnerability Management.
- Strong willingness and ability to remain hands-on-keyboard (60% allocation), executing complex technical tasks alongside the engineering team.
- Advanced expertise in modern threat detection/response toolsets, network security, and enterprise vulnerability lifecycles.
- Expert knowledge of security technologies including advanced encryption algorithms, enterprise network security, complex firewall architecture, PKI, and cloud-native security paradigms.
- Mastery of Artificial Intelligence (AI) tools to automate and assist with complex cybersecurity tasks, threat hunting, and operational workflows.
- Advanced understanding of application development life cycle (SDLC) models and modern DevSecOps testing tools.
- Intimate knowledge of highly complex operating system environments, hybrid cloud directory synchronization, and advanced networking protocols.
- Soft Skills:
- Demonstrated ability to manage TVM operations and pivot seamlessly between deep technical troubleshooting, project tracking, and high-level team management.
- Exceptional communication and presentation skills, with the ability to clearly articulate complex risks to senior executives and technical staff. • Strong technical leadership, mentorship, and work direction skills with a proven ability to elevate the capabilities of the engineering team. • Strong decision-making capabilities, able to operate authoritatively in high-stress, real-time crisis scenarios. • Ability to effectively prioritize competing projects and operational incidents in a fast-paced environment.
Other Requirements:As defined in IEEE Policies, individuals currently serving on an IEEE board or committee are not eligible to apply.
PLEASE NOTE: This position is not budgeted for employer-sponsored immigration support, this includes all persons in F (both CPT and OPT), J, H, L, or O status.
For information on work demands and conditions required for this position, please consult the reference document, ADA Requirements. This position is classified under Category I - Office Positions.