Sr. Manager, IT Security
Listed on 2026-06-22
-
IT/Tech
Cybersecurity, Information Security, IT Project Manager, IT Consultant
Overview
PURPOSE STATEMENT
The Sr. Manager, IT Security is responsible for leading and operating a comprehensive, risk‑based cybersecurity and information protection program for a regulated utility environment. This role will provide enterprise leadership for security strategy, governance, risk management, security operations, incident response, identity and access management, vulnerability management, and security architecture. This position requires deep technical breadth, strong management skills, and executive‑level judgment.
The Sr. Manager, IT Security serves as a key advisor to IT and business leadership, translates cyber risk into business impact, and contributes to enterprise technology decision‑making.
ESSENTIAL FUNCTIONS/RESPONSIBILITIES
Leadership & People Management
- Manages a team to oversee security operations, including monitoring, detection, investigation, and response activities.
- Leads succession planning, talent development, workforce planning, and organizational capability building for the IT Security function.
- Develops and manages the cybersecurity budget, including strategic planning for staffing, technology investments, consulting services, and managed security providers.
Cybersecurity Strategy & Governance
- Leads the design, implementation, and continuous improvement of the enterprise information security program.
- Develops and executes the organization's long‑term cybersecurity vision, strategy, and roadmap in alignment with business objectives and technology initiatives.
- Develops and maintains security strategy, policies, standards, procedures, and multi‑year roadmaps aligned with business objectives and regulatory requirements.
- Serves as the primary cybersecurity advisor to executive leadership, providing recommendations regarding enterprise risk, security investments, and emerging threats.
- Leads enterprise‑wide cybersecurity governance, ensuring security policies, standards, and controls are consistently implemented across all business units and technology environments.
- Sponsors and drives cybersecurity program maturity initiatives through the adoption of industry frameworks, best practices, and continuous improvement efforts.
Security Operations & Incident Response
- Leads cybersecurity incident investigations, coordinates containment and recovery activities, and engages external resources as required.
- Develops, maintains, and regularly tests incident response plans and playbooks, including tabletop exercises with IT and business stakeholders.
- Manages security technologies and platforms, including but not limited to email security, endpoint detection and response (EDR), vulnerability management, identity protection, and logging/SIEM solutions.
- Stays current on emerging cybersecurity threats, vulnerabilities, and industry‑specific risk trends affecting utility operations.
Risk Management, Compliance & Audit
- Establishes and maintains a cybersecurity risk management framework, including risk identification, assessment, prioritization, mitigation, and reporting to executive leadership.
- Maintains an enterprise security risk register, including risk assessments, remediation plans, and formal risk acceptance documentation.
- Oversees cybersecurity compliance efforts related to applicable regulatory, legal, contractual, and industry requirements.
- Leads enterprise cybersecurity audits, assessments, and third‑party reviews, ensuring timely remediation of identified findings and recommendations.
- Directs third‑party cybersecurity risk management activities, including security due diligence, vendor assessments, and ongoing monitoring of critical suppliers and service providers.
Vulnerability & Security Engineering Management
- Leads vulnerability scanning, prioritization, remediation tracking, and reporting across infrastructure, applications, and cloud environments.
- Partners with Infrastructure, Applications, OT, and Operations teams to manage patching cadence, exceptions, and remediation SLAs.
- Directs security architecture and security‑by‑design initiatives to ensure cybersecurity requirements are integrated into infrastructure, applications, cloud environments, and operational technology…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).