Schellman & Co

Manager of Security Operations and Infrastructure

Schellman & Co$110K — $130K *
US-AnywhereRemote in Florida, US
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security operations or cybersecurity engineering
  • 1-3 years of people management experience
  • Strong knowledge of SecOps domains like SIEM and EDR
  • Familiar with DevOps concepts and cloud infrastructure
  • Hands-on experience with Microsoft and Okta security platforms
  • Excellent communication skills to convey technical risks
  • Collaborative leadership style, prioritizing empowerment and consensus

Responsibilities

  • Lead and mature the SecOps program for threat detection and incident response
  • Oversee day-to-day security tooling operations
  • Drive security incident response processes and continuous improvement
  • Manage SecOps Engineers, providing mentorship and career growth
  • Champion integration of security across the DevOps lifecycle
  • Collaborate on security strategy and roadmap planning with leadership
  • Communicate security posture and updates to IT leadership

Benefits

  • Flexible and balanced work environment
  • Remote work opportunities unless specified otherwise
  • Valuable continuous education and collaboration opportunities
  • Required annual travel for in-person training and meetings
  • Travel based on business and client needs
Full Job Description
JOB SUMMARY

Application Process:

You must complete this exercise to be considered for this role.

Please send your resume as well as an answer to the question below in lieu of a cover letter. This is a short exercise to simulate a chat/email request you might be asked in this role. It should take about 15 minutes and is intentionally open-ended, you can go into as much or little detail as you feel is necessary. Communicate in whatever ways work best for you (words, diagrams, etc.) to share your solution.

Be sure to label the document in this format: FirstName_LastName_SchellmanDevOpsExercise

ASSESSMENT QUESTION 1: Security Control Implementation & Operational Impact

You're tasked with implementing DLP (Data Loss Prevention) enforcement across the organization. This will require significant coordination between security and the business, impact user workflows, and affect multiple systems. Describe your approach to: (1) Assessing operational and business impact before rollout, (2) Building alignment and buy-in across Leadership, (3) Planning and phasing the implementation to minimize disruption, and (4) Measuring success without compromising critical business operations.

ASSESSMENT QUESTION 2: Team Capability Development

Your security and infrastructure team is growing. Describe how you would: (1) Identify skill gaps and capability needs across the team, (2) Decide between hiring specialists versus developing existing team members' capabilities, and (3) Create a mentorship or learning plan to build expertise

ASSESSMENT QUESTION 3: Cloud Infrastructure Scaling for Growth

As the organization grows, your cloud infrastructure must scale reliably and cost-effectively. Describe your approach to: (1) Assessing current infrastructure capacity and identifying gaps for future growth, (2) Planning a scaling strategy that balances performance, cost, and operational complexity, and (3) Explain your framework for deciding which processes, tasks, or functions deserve automation investment and why, given limited resources and time.

The Manager of Security Operations & Infrastructure is a hands-on player-coach leadership role responsible for the security and operational integrity of Schellman's technology infrastructure. This role oversees the Security Operations (SecOps) and DevOps functions, with a primary emphasis on building and maturing the SecOps program. This role reports to the Director of IT and is a key member of the CTO organization, contributing to IT strategy, security governance, and cross-functional initiatives across a ~500-person professional services firm.

Essential Functions:
  • Lead and mature Schellman's SecOps program, including threat detection, incident response, vulnerability management, and security monitoring
  • Own the day-to-day operations of security tooling across the environment, including EDR, SIEM, and related platforms
  • Drive security incident response processes, including escalation procedures, post-incident reviews, and continuous improvement
  • Partner with Compliance and Risk teams to support internal security controls and other frameworks relevant to Schellman's operations
  • Manage and develop SecOps Engineers, providing mentorship, prioritization support, and career growth opportunities
  • Lead vulnerability management efforts including prioritization, remediation tracking, and executive reporting
  • Provide management oversight for the DevOps team
  • Partner with the Senior DevOps Engineer on technical direction, infrastructure decisions, and delivery execution - leveraging their expertise while providing organizational leadership and prioritization support
  • Champion security integration across the DevOps lifecycle, including CI/CD pipeline security, IaC security standards, and cloud security posture management
  • Support cloud security operations across AWS and Microsoft Azure environments
  • Serve as a key stakeholder in Schellman's IT governance and AI governance programs
  • Collaborate with the Director of IT and CTO on security strategy, roadmap planning, and budget inputs
  • Represent the SecOps and DevOps functions in cross-departmental initiatives
  • Communicate security posture, risks, and program updates clearly to IT leadership and non-technical stakeholder


Knowledge, Skills, and Abilities:
  • 5+ years of experience in security operations, cybersecurity engineering, or a related discipline
  • 1-3 years of people management or formal team lead experience
  • Strong working knowledge of SecOps domains: SIEM, EDR, incident response, threat intelligence, and vulnerability management
  • Familiarity with DevOps concepts and cloud infrastructure - enough to lead DevOps engineers effectively and speak credibly to technical decisions
  • Hands-on experience with Microsoft and Okta security and identity platforms preferred
  • Excellent communication skills with the ability to translate technical risk into business context
  • Collaborative, low-ego leadership style - comfortable empowering technical leads and building consensus across functions
  • Our ideal candidate is located in the Eastern time zone


Education, Work Experience and Certifications:
  • Security certifications such as CISSP, CISM, Security+, or equivalent
  • Experience at a professional services, audit, or compliance firm
  • Exposure to SOC 2, FedRAMP, CMMC, or ISO 27001 is a strong plus


At Schellman, we strive to provide a flexible and balanced environment and therefore offer the opportunity to work remotely, unless otherwise stated in the job requirements. Connecting, collaborating and continuous education are also highly valued and therefore we require some travel annually for our Internal Service Delivery roles, which can include in-person training, team meet-ups, and strategy meetings. Service Delivery team members will also be required to travel based on business and client needs.

About Schellman & Co

Schellman & Company is a global provider of assurance and compliance services. They specialize in IT security and privacy, regulatory compliance, and attestation reporting. The firm was founded in 2002 and has offices in the United States, Europe, and Asia. Schellman & Company has been recognized as a Best Place to Work by the Tampa Bay Business Journal and the Atlanta Business Chronicle.
Learn more about Schellman & Co
Size
500 employees
Industry
Net Income
$5 million
Founded
2002
5 Year Trend
+10%
Revenue
$50 million

Similar Jobs

More Jobs at Schellman & Co

More Information Technology Jobs

Find similar Manager of Security Operations and Infrastructure jobs: