Cyber Security and Risk Manager
Listed on 2026-07-19
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Since 1995, Red Oak Technologies has been a trusted partner in the tech industry, delivering innovative talent solutions that drive progress. We specialize in quickly acquiring and efficiently matching top-tier professional talent with clients in immediate need of highly skilled contract, permanent or project management based resources.
Title:
Cyber Security & Risk Manager
Location:
South Bend (Elkhart), Indiana
The Cybersecurity & Risk Manager is a hands‑on leader responsible for developing, implementing, and continuously improving the organization’s cybersecurity and risk management program. This role serves as the primary cybersecurity subject matter expert, driving strategic security initiatives while actively managing daily security operations, incident response, vulnerability management, compliance activities, vendor risk assessments, and security awareness programs.
The Cybersecurity & Risk Manager partners across the organization to identify and mitigate risk, align security practices with business objectives, and mature the cybersecurity program utilizing the NIST Cybersecurity Framework (CSF) and other applicable industry standards. As the organization’s security leader, this individual provides guidance to leadership, supports the protection of critical business and network infrastructure, and champions a culture of security throughout the enterprise.
ResponsibilitiesSecurity Operations & Monitoring
- Monitor security alerts, logs, and events daily; investigate and respond to threats and anomalies in real time.
- Track and refine cybersecurity KPIs to support trend analysis, improvements, and leadership reporting aligned with regulatory goals.
- Lead all phases of incident response, maintain and improve the Incident Response Playbook, and ensure accurate documentation and preventive actions through structured tracking and analysis.
- Draft, maintain, and enforce security policies; ensure accessibility and cross‑department compliance with corrective actions where needed.
- Analyze third‑party scan reports, maintain a vulnerability inventory, and coordinate remediation efforts with stakeholders within defined SLAs.
- Deliver and track security awareness programs and phishing simulations; adjust content based on performance and emerging threats.
- Manage a repeat offender remediation program for users who repeatedly fail phishing simulations, including targeted training, awareness reinforcement, performance tracking, and coordination with management when necessary.
- Maintain and update the organization’s Information Security Risk Register, ensuring timely tracking, ownership, and mitigation of identified risks.
- Coordinate annual enterprise cybersecurity risk and NIST maturity assessments with third‑party security partners, document findings, evaluate business impact, and track remediation activities through resolution.
- Develop and monitor risk treatment plans, ensuring identified risks are appropriately mitigated, transferred, accepted, or avoided based on organizational risk tolerance.
- Drive security initiatives, tool deployments, and improvements by tracking milestones, coordinating vendors, and reporting status to leadership.
- Coordinate tabletop exercises with third‑party facilitators; document results and follow‑up actions to enhance preparedness.
- Collaborate with external providers to maintain, test, and update BCP/DR plans; support internal drills and elevate identified risks.
- Manage vendor risk assessments, track remediation of findings, and ensure due diligence during onboarding and renewals.
- Develop and maintain the organization’s cybersecurity strategy, roadmap, security initiatives, and governance standards aligned with business objectives and organizational risk.
- Provide regular cybersecurity risk, compliance, and program maturity updates and recommendations to executive leadership.
- Evaluate emerging threats, technologies, and regulatory requirements,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).