Information Security Lead
Listed on 2026-08-28
-
IT/Tech
Cybersecurity
Working directly with the Vice President of Information Security, this role is designed for a highly autonomous security leader who combines strong technical depth with the ability to independently own and execute large-scale security initiatives.
Operating within a lean corporate team, you will serve as the primary technical project owner for the security program across multiple operating companies. This is a builder role, not a maintenance or oversight position.
You will be expected to architect, implement, and troubleshoot security controls from a blank canvas, while navigating business constraints across both corporate offices and 24/7 manufacturing environments. Success in this position requires an exceptional engineer who can own projects end-to-end, enforce a strict security framework mindset, and remain fully hands-on at the keyboard.
Essential Functions:- Enterprise Tool Ownership: Take complete engineering ownership of the core security stack, including Microsoft 365, Microsoft Defender, Intune (MDM/MAM), Entra (Identity & Access Management), Rapid7, and Proofpoint.
- Strategic Security Architecture: Serve as an expert in security technologies and controls, driving decisions across infrastructure, identity, endpoint, and network security.
- Project Leadership: Own and lead end-to-end security projects to independently scope requirements, define and track project timelines, manage vendor relationships, coordinate with IT teams, and ensure on-time delivery without disrupting business operations.
- Incident Response & Root Cause Analysis: Investigate and perform root-cause analysis of issues including but not limited to: malware infections, data leakage, internal/external network abuse, and phishing attempts.
- Vulnerability Management & Remediation: Drive the internal vulnerability management program utilizing Rapid7, actively identifying, prioritizing, and remediating potential security exposures, misconfigurations, and noncompliance issues across the enterprise.
- Security Frameworks & Playbooks: Build and maintain security playbooks, standards, and procedures, acting as a creator of frameworks, not just a follower.
- Continuous Auditing: Perform technical audits on patch management, privileged access, endpoint detection and response, network devices, wired/wireless access, and user access.
- Provide hands-on support across Active Directory, Entra, endpoint systems, network segmentation, and access control rules as needed.
- Support and mature security awareness and phishing simulation programs.
- Stay current on threat landscape, tooling, and security frameworks, applying knowledge directly to the environment.
- Act as a trusted technical advisor to leadership across security and infrastructure decisions.
- Bachelor’s Degree in Information Security, Computer Science, or Information Systems.
- ISC², GIAC, ISACA, SANS, CompTIA, Offensive Security, or CISSP security certification is preferred.
- 5-10+ years of hands-on experience in systems, network engineering, or security engineering roles.
- Proven ability to design and implement security solutions from scratch, not just support or monitor existing environments.
- Demonstrated experience owning and driving large-scale projects independently
- Deep understanding of:
- Endpoint security and EDR tools
- Vulnerability management and patching strategies
- Strong experience with incident response and forensic analysis, including root cause investigation (not just remediation).
- Ability to operate without heavy reliance on MSSPs or external vendors.
- Lift up to 50 lbs.
- Up to 10% travel is required.
- Strong security-first mindset, balancing business needs without compromising controls.
- Thrives in a highly autonomous environment with minimal oversight.
- Comfortable pushing through organizational resistance and change-management challenges.
- Highly curious with a strong desire to understand how systems work, not just tools.
- Excellent communication skills across technical and non-technical stakeholders.
- Ability to prioritize and execute multiple concurrent initiatives.
Rate:
In accordance with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).