Manager, IT Security

Avontix

$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in information security operations or engineering
  • 2+ years in a leadership role with team management experience
  • Hands-on expertise with Microsoft security stack tools
  • Proven experience with SOC 2 Type II and HIPAA compliance
  • Familiarity working with a managed security services provider (MSSP)
  • Experience in developing incident response programs
  • Strong communication skills for conveying technical concepts to non-technical stakeholders

Responsibilities

  • Lead daily security operations and manage EDR/XDR, SIEM, and other security tools
  • Organize and drive vulnerability remediation meetings and activities
  • Oversee identity and access management program including MFA and privileged access
  • Serve as main contact with MSSP for security incident management
  • Continuously enhance incident response playbook and internal processes
  • Facilitate tabletop exercises and security incident reviews
  • Support SOC 2 Type II audit processes and maintain compliance documentation
  • Directly manage a cross-border security operations team

Benefits

  • Opportunity to lead a dynamic security team
  • Engagement with cutting-edge security technologies
  • Potential for career advancement into director levels
  • Participation in cross-functional security initiatives
  • Emphasis on professional development and performance management
Full Job Description
Job Type

Full-time

Description

The Manager, IT Security leads day-to-day security operations and engineering for the company: coordinating with our managed security services provider (MSSP) on SOC alerting and response, driving vulnerability and identity/access management programs, maintaining incident response readiness, and supporting our SOC 2 Type II, HIPAA, and NIST CSF compliance programs. This person manages a small cross-border team of security practitioners and is the operational backbone of the security function as the broader organization builds out, including future Director and GRC leadership roles.

On a typical day, you'll be responsible for:
  • Own day-to-day security tooling and operations: EDR/XDR, SIEM, data-loss prevention, device compliance, and Conditional Access / Zero Trust controls across the Microsoft security stack (Defender for Endpoint, Sentinel, Purview, Intune, Entra ID)
  • Lead the Daily Security Huddle and weekly Vulnerability Management meeting; drive vulnerability remediation to closure against defined SLAs
  • Own the identity and access management program: MFA, Conditional Access, privileged access management, RBAC, and joiner/mover/leaver automation
  • Serve as the primary internal point of contact for the managed security services provider (MSSP/vCISO) on SOC alert triage, escalation, and remediation follow-through
  • Maintain and continuously improve the incident response playbook and runbooks, aligning internal procedures with the MSSP's SOC processes and pre-defined escalation thresholds
  • Coordinate tabletop exercises and post-incident reviews, and act as a security escalation point for active incidents
  • Support the annual SOC 2 Type II audit cycle - evidence collection, control walkthroughs, and auditor liaison - in partnership with the compliance/GRC function
  • Maintain NIST CSF control documentation and contribute to ongoing risk-remediation (POA&M) efforts
  • Support HIPAA/PHI security controls and periodic risk assessments; coordinate annual third-party penetration testing and remediation
  • Directly manage the security engineering/operations team, spanning U.S. and India-based staff
  • Own performance management, coaching, and bench-strength / succession planning within the team
  • Partner closely with Infrastructure, Workplace Services (help desk/IAM), and Development leadership on cross-functional security initiatives


Requirements

Who you are:
  • 10+ years in information security operations or engineering, including 2+ years in a people-management or team-lead capacity
  • Hands-on experience with the Microsoft security stack - Defender for Endpoint, Sentinel, Purview, Intune, Entra ID (Conditional Access, MFA, PIM)
  • Experience supporting SOC 2 Type II and/or HIPAA compliance programs (evidence gathering, control testing, auditor engagement)
  • Experience managing or closely partnering with a managed security services provider (MSSP) / outsourced SOC
  • Experience building or maturing an incident response program, including playbooks and tabletop exercises
  • Comfortable managing distributed, cross-border teams (U.S. and India)
  • Strong written and verbal communication skills, with the ability to translate technical risk into business terms for non-technical stakeholders

Similar Jobs

More Jobs at Avontix

  • Manager, IT Security
    $110K — $130K *
    Chesterfield, MO 63017 (Saint Louis County)
    Information Technology
    Hybrid
  • Manager, IT Security
    $110K — $130K *
    Remote
    Information Technology
    Remote in Chesterfield, MO

More Information Technology Jobs

Find similar Manager, IT Security jobs: