Under the general direction of the Director, manages the day-to-day operations and staff responsible for company-wide infrastructure operations and risk management related to information security operations. Manages activities aimed at safeguarding the organization's information assets and ensuring the alignment of security measures with overarching business objectives and regulatory standards. Ensures adherence to NERC Critical Infrastructure Protection (CIP), Statement on Standards for Attestation Engagements no. 18 (SSAE18), and related regulatory standards and frameworks. Responsible for maintaining the integrity, availability, and confidentiality of critical infrastructure and information systems. Oversees the planning and implementation of the enterprise IT systems, business operations and IT related facility defenses against security breaches and vulnerability issues and manages the administration of security policies, standards, and activities. Aligns strategies with operations-related business areas for the delivery and support of critical business solutions, balancing business needs and cost of ownership, while achieving customer satisfaction. Ensures business solution roadmaps and IT activities achieve short and long-term ISO security objectives. Delivers feasible business solution roadmaps and proactive system management, oversees strategic software vendor relationships related to security, and guides the implementation and continuous improvement of our security posture. Responsible for the overall success of Information Security Operations and related business solutions.
What You Will Be Doing:
Level of Education and Discipline:
A Bachelor's degree (BA, BS) or equivalent education, training or experience in Engineering, Computer Science or related field. Master’s degree preferred.
Amount of Experience:
Equivalent years of education and training, plus ten (10) or more years related experience, including five (5) or more as a lead or equivalent.
Certifications:
ITIL technical certifications desired. CISA, CISM, CISSP or CIPP desired.
Type of Experience:
Management experience desired. Experience with one or more of the following: IT strategic planning and management, system management of real-time systems, system development, business management, customer relationship management, vendor management. Thorough knowledge of ISO operations and systems. Experience working within NERC / CIP, NIST CSF, ISO 27001 and related standards and frameworks as they apply to information security. Knowledge of U.S. Federal Laws and regulations. Experience in field of Information Assurance Information Security. Thorough knowledge of software development life cycle methodologies related to information security.
Additional Skills and Abilities:
Ability to think strategically and devise solutions to problems in keeping with multiple considerations. Excellent leadership and management abilities with experience coaching and developing others. Must demonstrate sound judgment and critical thinking when making decisions. Must be able to work effectively in a team environment as team leader, facilitator and team member. Strong analytical and quantitative skills required. Excellent interpersonal, communication and writing skills required, including the ability to effectively communicate complex materials and concepts. Must be able to handle a dynamic and changing work environment, and work well independently.
The pay range for the Manager, Information Security Operations is $146,100 - $243,500 annually.
All your information will be kept confidential according to EEO guidelines.