Job SummaryACCO Brands is seeking a dynamic, forward-thinking
Sr. Cybersecurity Manager to lead a global team of cybersecurity analysts, secure ACCO Brands' global digital ecosystem, and drive cross-functional risk-reduction initiatives across business units and infrastructure teams. Reporting to the VP of Global Cybersecurity and Infrastructure, this role oversees day-to-day cybersecurity operations, drives strategic security initiatives, and serves as a key liaison across IT, business units, and external partners.
ResponsibilitiesStrategy, Governance & Risk- Partner with the VP of Global Cybersecurity and Infrastructure to align security initiatives with enterprise risk posture, compliance obligations, and business objectives, translating them into cybersecurity priorities and roadmaps.
- Leverage external security benchmarking and maturity assessments (e.g., BitSight, NIST) to develop cybersecurity performance metrics for executive leadership as part of broader risk and performance reporting.
- Represent Cybersecurity in enterprise-level initiatives and governance councils, influencing business decisions through security insights and risk intelligence.
- Lead enterprise-wide governance initiatives aligned with the NIST Cybersecurity Framework (CSF), translating technical risk into actionable business insights for executive stakeholders and identifying areas for improvement and control gaps.
- Define and track key performance indicators (KPIs) and control metrics aligned with NIST CSF functions.
- Contribute to and enforce cybersecurity policies, standards, and procedures that support compliance with PCI DSS, GDPR, SOX, and internal governance requirements.
- Drive control validation initiatives to ensure the ongoing effectiveness of technical and administrative safeguards.
Team Leadership & Development- Lead, mentor, and manage a team of cybersecurity analysts and security engineers.
- Coordinate workload planning, performance evaluations, and skill development across the cybersecurity team.
- Foster a collaborative team culture through one-on-one coaching, career development, and goal setting.
Security Operations & Incident Response- Oversee daily security operations, including monitoring, triage, and incident response, using tools such as Rapid7 InsightIDR and CrowdStrike Falcon.
- Serve as a key member of the cybersecurity incident response process, supporting the VP of Global Cybersecurity and Infrastructure from detection through resolution and post-incident review.
- Manage continuous threat detection, intelligence gathering, and escalation procedures.
- Oversee and guide analysts and engineers responsible for managing tools such as Proofpoint, Cisco Umbrella, SSO/MFA platforms, and next-generation firewalls, ensuring alignment with security strategy and best practices.
Additional ResponsibilitiesVulnerability & Threat Management- Manage the enterprise vulnerability management lifecycle, including identification, validation, and risk-based remediation.
- Partner with IT and infrastructure teams to validate remediation plans and enforce patching SLAs.
- Coordinate and advance internal remediation activities and processes to improve and maintain the organization's external risk posture.
Cloud & Application Security- Oversee the development, implementation, and management of cloud security controls within Microsoft Azure and other cloud providers as applicable.
- Collaborate with application development teams to integrate security practices into the software development lifecycle (SDLC).
- Evaluate and enhance application security policies, secure coding practices, and code review procedures.
- Ensure secure configurations and identity management across cloud-native platforms.
- Partner with business and IT teams on security architecture reviews and secure project enablement.
Vendor, Third-Party & Awareness Programs- Design and roll out a Third-Party Risk Management program to inventory and assess cybersecurity risk across third parties, and integrate findings into the enterprise risk posture.
- Manage vendor relationships, including MSSPs and security solution providers, to ensure alignment with program goals, service levels, and cost-effectiveness.
- Evaluate and review security tools and technologies, recommending improvements, replacements, or integrations that strengthen the security program.
- Own the strategy and execution of the enterprise-wide security awareness program, including phishing simulations, social engineering campaigns, annual Cybersecurity Awareness Month activities, and internal newsletters.
Qualifications- Bachelor's degree in Information Security, Computer Science, or a related field, or equivalent work experience.
- 10+ years of progressive experience in cybersecurity, including at least 2 years in a leadership or supervisory capacity.
- Demonstrated experience managing security operations, incident response, and vulnerability remediation in cloud environments.
- Experience working with Managed Security Service Providers (MSSPs).
- Strong working knowledge of security tooling, including SIEM platforms, EDR (e.g., CrowdStrike), and email security gateways (e.g., Proofpoint).
- Hands-on familiarity with Cisco Umbrella, Microsoft 365 security, SSO/MFA, NGAV/EDR, and enterprise firewall platforms.
- Solid understanding of enterprise IT, networking, identity and access management, encryption, and SIEM architecture.
- Familiarity with security frameworks such as NIST CSF, ISO 27001, or CIS Controls.
- Working knowledge of AI governance principles and experience supporting the implementation of AI governance frameworks within an enterprise security program.
- Proven ability to manage competing priorities across multiple teams and time zones.
- Excellent verbal and written communication skills, with the ability to translate technical risk into business terms for executive audiences.
- Strong collaboration and stakeholder management skills across IT, business units, and external partners.
Preferred Qualifications- CISSP, CISM, or CISA
- Cloud security certification (e.g., Microsoft Certified: Azure Security Engineer Associate)
- GIAC certifications (e.g., GCIH, GSEC) a plus
Salary Range: $140,000 - $180,000
#LI-Hybrid
What we offer:- Comprehensive medical, prescription, dental, and vision plans
- 4% 401(k) match with immediate eligibility and vesting
- Competitive time off, available from the first day of employment
- Parental leave
- Company-paid life and disability benefits
- Critical illness, accident, and long-term care insurance options
- Employee and family assistance programs