Job Type
Full-time
Description
The Manager, IT Security leads day-to-day security operations and engineering for the company: coordinating with our managed security services provider (MSSP) on SOC alerting and response, driving vulnerability and identity/access management programs, maintaining incident response readiness, and supporting our SOC 2 Type II, HIPAA, and NIST CSF compliance programs. This person manages a small cross-border team of security practitioners and is the operational backbone of the security function as the broader organization builds out, including future Director and GRC leadership roles.
On a typical day, you'll be responsible for: - Own day-to-day security tooling and operations: EDR/XDR, SIEM, data-loss prevention, device compliance, and Conditional Access / Zero Trust controls across the Microsoft security stack (Defender for Endpoint, Sentinel, Purview, Intune, Entra ID)
- Lead the Daily Security Huddle and weekly Vulnerability Management meeting; drive vulnerability remediation to closure against defined SLAs
- Own the identity and access management program: MFA, Conditional Access, privileged access management, RBAC, and joiner/mover/leaver automation
- Serve as the primary internal point of contact for the managed security services provider (MSSP/vCISO) on SOC alert triage, escalation, and remediation follow-through
- Maintain and continuously improve the incident response playbook and runbooks, aligning internal procedures with the MSSP's SOC processes and pre-defined escalation thresholds
- Coordinate tabletop exercises and post-incident reviews, and act as a security escalation point for active incidents
- Support the annual SOC 2 Type II audit cycle - evidence collection, control walkthroughs, and auditor liaison - in partnership with the compliance/GRC function
- Maintain NIST CSF control documentation and contribute to ongoing risk-remediation (POA&M) efforts
- Support HIPAA/PHI security controls and periodic risk assessments; coordinate annual third-party penetration testing and remediation
- Directly manage the security engineering/operations team, spanning U.S. and India-based staff
- Own performance management, coaching, and bench-strength / succession planning within the team
- Partner closely with Infrastructure, Workplace Services (help desk/IAM), and Development leadership on cross-functional security initiatives
Requirements
Who you are: - 10+ years in information security operations or engineering, including 2+ years in a people-management or team-lead capacity
- Hands-on experience with the Microsoft security stack - Defender for Endpoint, Sentinel, Purview, Intune, Entra ID (Conditional Access, MFA, PIM)
- Experience supporting SOC 2 Type II and/or HIPAA compliance programs (evidence gathering, control testing, auditor engagement)
- Experience managing or closely partnering with a managed security services provider (MSSP) / outsourced SOC
- Experience building or maturing an incident response program, including playbooks and tabletop exercises
- Comfortable managing distributed, cross-border teams (U.S. and India)
- Strong written and verbal communication skills, with the ability to translate technical risk into business terms for non-technical stakeholders