National Audubon Society

Senior Manager, IT Security Operations

National Audubon Society$123K — $138K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or related field.
  • Minimum 8 years of IT operations experience with a focus on cybersecurity.
  • Strong knowledge of cybersecurity technologies and best practices.
  • Proficiency in administering various security tools and systems.
  • Excellent problem-solving and analytical skills.
  • Effective communication and interpersonal abilities, focusing on detail and accuracy.
  • Experience with specific technologies like Defender for Endpoint, Okta, and AWS/Azure preferred.

Responsibilities

  • Partner with senior leadership to assess and respond to security incidents.
  • Monitor and respond to security alerts according to compliance policies.
  • Manage and evaluate security tools and vendor services for effectiveness.
  • Assist in developing and enforcing security policies and industry compliance standards.
  • Administer Identity Provider (IdP) for user account management and access control.
  • Oversee vulnerability management including scans and penetration tests.
  • Develop and maintain a security awareness training program for employees.

Benefits

  • Hybrid work model with flexibility in scheduling office visits.
  • Exposure to cutting-edge cybersecurity technologies and practices.
  • Opportunity to collaborate with cross-functional teams on security strategies.
  • Work in a mission-driven environment committed to organizational values.
  • Potential for professional growth in a rapidly evolving field.
Full Job Description
Position Summary:

We are seeking a highly skilled and motivated Senior Manager, IT Security Operations to join our team. As the Senior Manager, IT Security Operations, you will play a crucial role in safeguarding our organization's assets, ensuring the integrity and confidentiality of sensitive information, and maintaining the overall security posture of our systems and networks.

This position is classified as hybrid preferred. Hybrid employees are expected to work in an Audubon office every Monday and Tuesday and an additional two days each month of the employee's choosing. Remote work within the United States may be considered only for candidates not within commuting distance of an Audubon office, in accordance with Audubon's "Where We Work" Policy. Audubon offices include locations in:

Albuquerque, NM; Albany, NY; Anchorage, AK; Baltimore, MD; Charleston, SC; Chicago, IL; Columbia, SC; Fargo, ND; Fort Collins, CO; Lincoln, NE; Miami, FL; New Orleans, LA; New York, NY; Oakland, CA; Palm Desert, CA; Roseville, MN; Sacramento, CA; Salt Lake City, UT; Tallahassee, FL; and Washington, DC.

Compensation:

Salary range based on geo-differentials:
  • $109,372 - $123,044 / year = Albuquerque, NM; Charleston, SC; Columbia, SC; Fargo, ND; Fort Collins, CO; Lincoln, NE; Miami, FL; New Orleans, LA; Salt Lake City, UT; Tallahassee, FL
  • $123,041 - $138,421 / year = Albany, NY; Anchorage, AK; Baltimore, MD; Chicago, IL; Palm Desert, CA; Roseville, MN; Sacramento, CA; Washington, DC
  • $136,718 - $155,808 / year = New York, NY; Oakland, CA


Additional Job Description

Essential Functions:
  • Security Incident Response:
    • Partner with Chief Technology Officer, Senior Director of Information Technology, and Virtual Chief Information Security Officer (vCISO) to assess and respond to security incidents.
    • Monitor and respond to security alerts and incidents compliant with service level agreements outlined by policy.
    • Investigate, analyze, and document security incidents compliant with "chain of custody" processes, and implement appropriate countermeasures.
  • Security Tool and Services Management:
    • Evaluate, procure, administer, and manage security tools and supporting vendor services, including but not limited to password managers, phishing threat management, firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint management, endpoint detection and response (EDR), managed detection and response (MDR), antivirus, document management, and Security Information and Event Management (SIEM) solutions.
    • Regularly monitor, update, and fine-tune security systems to enhance effectiveness.
    • Lead vendor security review process in partnership with vCISO.
  • Security Policy and Compliance:
    • Assist in the development, implementation, review, and enforcement of security policies, standards, and procedures guided by ISO 27000 standards.
    • Ensure compliance with industry-specific regulations (e.g., PCI) and standards and coordinate and participate in regular audits.
  • Access Control and Authentication:
    • Administer Identity Provider (IdP) to manage user accounts, permissions, and access levels across various systems, following Identity and Access Management (IAM) workflows.
    • Maintain system role mapping documentation and lead and coordinate regular entitlement reviews as necessary.
    • Implement, administer, and manage multi-factor authentication (MFA) and single sign-on (SSO) solutions.
  • Vulnerability Management:
    • Oversee scheduled vulnerability scans and penetration tests.
    • Coordinate with relevant teams to remediate identified vulnerabilities.
  • Security Awareness and Training:
    • Curate and oversee security awareness program and portal for employees.
    • Provide specialized training on best practices for security hygiene.
    • Oversee phishing test program and remediation training program.
  • Security Documentation:
    • Maintain accurate and up-to-date security documentation, including incident reports, policies, procedures, and configurations.
  • Collaboration and Communication:
    • Collaborate with cross-functional teams to ensure security measures align with overall business objectives.
    • Communicate security risks and recommendations to management and relevant stakeholders.
    • Act as lead facilitator of IT Security Operations working group and participate in Architectural Review Board meetings.
  • Server and Network Configuration:
    • Assist cloud and network administration team with configurations and function of servers to limit access, mitigate intrusions, and protect assets.
    • Assist cloud and network administration team with configurations and topology of network devices to safeguard points of access and data security, including firewalls, routing, and ACLs.
  • Maintain and foster culture of safety.
  • Other job-related duties as assigned.


Qualifications and Experience:
  • Bachelor's degree in Information Security, Computer Science, or a related field.
  • Minimum 8 years of experience with IT operations with progressive experience in cybersecurity in a corporate or non-profit environment. An equivalent combination of education and work experience will also be considered.
  • Strong knowledge of cybersecurity technologies and best practices.
  • Proficiency in administering security tools and systems.
  • Excellent problem-solving and analytical skills.
  • Effective communication and interpersonal abilities.
  • Detail-oriented with a focus on accuracy.
  • Ability to work both independently and collaboratively in a team environment.
  • Experience with Defender for Endpoint, and Defender for Identity preferred.
  • Experience with Okta preferred.
  • Experience with Sonicwall FW hardware preferred.
  • Experience with distributed network environments preferred.
  • AWS / Azure / Public cloud expertise preferred.
  • Experience with SecDevOps best practices preferred.
  • Commitment to Audubon's organizational values of care, collaboration, change, integrity, impact, and innovation.
  • Experience fostering inclusive and collaborative work environments is valued.


National Audubon Society Competencies: This role will also be accountable to apply and develop the following competencies.

Fostering Relationships: Build trust, mutual respect, and understanding through regular and genuine interactions while promoting a positive and inclusive environment.

Analytical Thinking: Recognize and value diverse perspectives and experiences in data analysis to foster a more comprehensive and equitable approach to problem-solving.

Creativity and Innovation: Leverage creativity and imagination to generate new insights and solutions while embracing diverse ideas and approaches that foster innovation.

Facilitating Change: Work with others to explore innovative approaches to problem-solving while promoting inclusivity, equity, accessibility, and belonging in the change process.

Team Leadership: Communicate vision and engage others or the team to solve problems while valuing diverse perspectives and fostering inclusivity.

About National Audubon Society

The National Audubon Society is a non-profit organization dedicated to the conservation of birds and their habitats. The organization was founded in 1905 and has since grown to become one of the largest and most influential conservation organizations in the United States. Audubon operates a network of nature centers and sanctuaries across the country, and works to protect and restore critical bird habitats through advocacy, education, and on-the-ground conservation efforts. The organization is named after John James Audubon, a 19th-century naturalist and artist who is best known for his illustrations of North American birds.
Learn more about National Audubon Society
Size
1,000 employees
Industry

Similar Jobs

More Jobs at National Audubon Society

More Information Technology Jobs

Find similar Senior Manager, IT Security Operations jobs: