Manager, Cyber Security
HTS Engineering · Toronto, ON, CA ·
- Work mode
- Hybrid
- Category
- Security
- Experience
- 12+ years
HTS Engineering · Toronto, ON, CA ·
gilead · United States - California - Foster City
Military, Veterans and Diverse Job Seekers · Stafford, VA, United States
hlb · PJC-PJ City
Job Mandate:
Reporting to the Head of Cyber Security, the Manager of Cyber Security is responsible for
leading and managing key components of the organization’s cybersecurity program, working
closely with the Head of Cyber Security to execute security strategies, initiatives, and priorities.
The role provides leadership across cybersecurity governance, risk management, security
operations, vulnerability management, incident response, compliance, and security assurance.
The Manager oversees the implementation and effectiveness of security controls, identifies and
manages cyber risks, leads security improvement initiatives, and ensures alignment with
regulatory requirements, industry standards, and organizational policies. The role works
collaboratively with ITOps, Support Services, Business Solutions and other business
stakeholders to strengthen the organization’s cybersecurity posture, address emerging threats,
support security awareness, and drive continuous improvement in the overall security program.
Responsibilities:
Cybersecurity Strategy Execution and Program Delivery
Security Operations Management
·Manage day-to-day cybersecurity operations, ensuring effective monitoring, detection, response, and remediation of security events.
·Oversee incident response activities, including investigation, containment, recovery, root cause analysis, and lessons learned.
·Manage vulnerability management processes, including vulnerability identification, prioritization, remediation tracking, and reporting.
·Ensure cybersecurity controls and operational processes remain effective and aligned with organizational requirements.
·Must have hands on experience with Tools – EDR/XDR, SIEM, Forensics, Vulnerability scanners, Cloud Security, Firewalls
Cybersecurity Governance, Risk, and Compliance
·Support the Head of Cyber Security in maintaining cybersecurity governance frameworks, policies, standards, and procedures.
·Support ongoing compliance programs, including SOC 2, ISO 27001, NIST, and other applicable security frameworks.
·Develop and maintain cybersecurity metrics, dashboards, and KPIs to measure security performance and improvement.
Security Architecture and Technology Enablement
·Provide cybersecurity guidance and recommendations for infrastructure, applications, cloud services, and technology initiatives.
·Partner with IT Operations, Business Solutions, and development teams to integrate security into technology solutions.
·Support Secure DevOps (DevSecOps) practices by promoting security throughout the software development lifecycle.
·Support security reviews for emerging technologies, including artificial intelligence initiatives and AI governance requirements.
Security Service Delivery and Operational Improvement
·Support the continued development and maturity of cybersecurity service delivery capabilities.
·Assist in defining repeatable processes, operational procedures, and service standards that improve quality, efficiency, and scalability.
·Partner with the Head of Cyber Security to advance cybersecurity capabilities, including Managed Security Services (MSSP) offerings where applicable.
·Identify opportunities for automation, process optimization, and improved service delivery.
Security Awareness and Culture
·Promote security best practices through training, communications, presentations, and engagement activities.
Third-Party and Vendor Security
·Support third-party security assessments and vendor risk management activities.
·Review security requirements for external providers and technology partners.
·Collaborate with vendors and partners to address security risks and improve security outcomes.
Leadership and Collaboration
·Provide leadership, coaching, and guidance to cybersecurity team members.
·Foster collaboration across Cyber Security, IT Operations, Business Solutions, Help Desk, and business teams.
·Build strong relationships with stakeholders to ensure security requirements are understood and effectively implemented.
·Demonstrate accountability, ownership, and continuous improvement in all cybersecurity activities.
Strategy & Planning:
·Develop and execute the organization’s cybersecurity strategy, roadmap, and priorities.
·Align cybersecurity initiatives with business objectives, risk tolerance, and regulatory requirements.
·Lead cybersecurity risk assessments and establish priorities for risk reduction.
·Define cybersecurity goals, performance metrics, and security maturity targets.
·Develop and manage the cybersecurity program roadmap, budget, resources, and priorities.
·Evaluate emerging threats, technologies, and industry trends to inform security strategy.
·Establish and maintain cybersecurity governance, policies, standards, and frameworks.
·Lead strategic planning for security operations, incident response, vulnerability management, compliance, and risk management.
·Identify security gaps and develop remediation and continuous-improvement plans.
·Partner with IT and business leadership to integrate security into technology and business initiatives.
·Provide cybersecurity risk, performance, and investment recommendations to senior leadership.
·Ensure cybersecurity strategies support business continuity, resilience, and organizational objectives.
Working Conditions:
·Work environment consisting of 5 days in the office.
·Fast-Paced Environment: Fast-paced environment with tight deadlines.
·Transportation: Reliable access to personal transportation is a requirement.
·Travel: Must have a valid passport and be allowed entry into the US.
·Remote Work: Must have a reliable Internet connection for remote work.
Minimum Required Technical Skills / Qualifications:
·Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience.
·12+ years of experience in cybersecurity, information security, or related technology roles.
·Experience with security operations, incident response, vulnerability management, governance, and risk management.
·Experience with Managing technical teams
·Professional certifications such as CISSP, CISM, CRISC, GIAC, or Security+.
·Experience with SOC 2 Type 2, ISO 27001, NIST Cybersecurity Framework, or CIS Controls.
·Experience with cloud security, application security, DevSecOps, and secure software development practices.
·Experience with security metrics, governance reporting, and executive dashboards.
·Experience supporting Managed Security Services (MSSP) development or cybersecurity service delivery models.
·Experience supporting AI governance and emerging technology risk management.
Technical Skills:
·Strong knowledge of cybersecurity architecture, security operations, risk management, and governance.
·Experience with SIEM, EDR/XDR, IAM, vulnerability management, email security, and cloud security technologies.
·Proficiency with platforms such as Microsoft Sentinel, Microsoft Defender, Entra ID, Microsoft 365, or equivalent solutions.
·Strong understanding of network security, endpoint security, identity and access management, and cloud environments.
Minimum Required Behavioural / Soft Skills
·Strong communication and presentation skills with technical and executive audiences.
·Ability to translate complex cybersecurity risks into business impacts.
·Strong problem-solving, analytical, and critical-thinking skills.
·Ability to prioritize competing risks, projects, and operational demands.
·Strong stakeholder management and cross-functional collaboration skills.
·Ability to build effective relationships with IT, business, risk, audit, legal, and executive teams.
·Strong project and program management skills.
·Ability to manage and resolve security incidents and high-pressure situations effectively.
·Strong negotiation, influencing, and conflict-resolution skills.
·High level of accountability, integrity, and professional judgment.
·Ability to mentor, coach, and develop cybersecurity staff.
·Adaptability and willingness to stay current with emerging threats, technologies, and regulatory requirements.
Salary: $150K-$170K
RTX · DE-BW-HEIDELBERG-036-751 ~ Grenzhofer Weg 36 ~ BLDG 751