Manager, Information Security at BLDG SVC 32 B-J | New York, NY, US | Rezi

Manager, Information Security at BLDG SVC 32 B-J

Manager, Information Security

BLDG SVC 32 B-J · New York, NY, US

5 days ago

Manager, Information Security

BLDG SVC 32 B-J · New York, NY, US

6 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Manager, Information Security will provide strategic leadership and execution for the organization’s information security program, protecting systems, networks, and data. This role involves overseeing security operations, developing policies, mentoring the team, managing the risk register, and improving incident response metrics. The ideal candidate is a hands-on leader skilled in operational security and governance, capable of building a scalable security team aligned with IT strategy.

Responsibilities

  • Lead and manage the IT Security Operations team, including Information Security Analysts, Engineers, and Incident Responders.
  • Provide guidance and expertise in risk management regarding the protection and security of digital assets in the cloud and on-premises.
  • Design and develop Information Security architectures to prevent unauthorized access to systems, networks, data, and information.
  • Develop, maintain, enhance, and implement information security policies and procedures, including the Information Security Policy Manual, Incident Response plans, playbooks, runbooks, and Business Continuity Plan documents.
  • Coordinate and perform business continuity planning and incident response exercises annually.
  • Coordinate and lead response efforts during security incidents.
  • Manage, maintain, and monitor security technologies such as vulnerability scanning solutions, IDS/IPS, anti-virus technologies, DLP capabilities, SIEM technologies, EDR, host forensics and malware analysis, core and web application firewalls, network security groups, threat intel platforms, and proxy solutions.
  • Oversee and collaborate with the Security Operations Center (SOC) provider to review threat alerts and reports, ensuring the team follows up on all actionable information.
  • Manage all security initiatives, risk mitigation plans, annual assessments, security audits, and penetration testing activities with guidance from the vCISO.
  • Manage real-time threat detection technologies to identify and quarantine threats, monitor endpoint security alerts, and take corrective action.
  • Minimize security threats by examining governance, technology infrastructure, and facilities to identify security deficiencies, using risk analysis and follow-up with corrective action plans.
  • Monitor internal control systems to ensure appropriate access levels are maintained, protecting against unauthorized system access, modification, and destruction.
  • Review security-related reports, logs, and occurrences; escalate issues and initiate security response procedures.
  • Create and review vulnerability reports, track compliance with vulnerability management policies, and escalate.
  • Research and evaluate emerging technologies, latest cybersecurity threats, trends, tools, and best practices to support security technology enhancements.
  • Propose technical solutions to management to address security weaknesses and coordinate with stakeholders for implementation.
  • Review, update, and enforce data security practices within the organization.
  • Test for exposures to ensure adherence to relevant regulations and frameworks (e.g., NIST, ISO 27001, PCI-DSS, HIPAA) and procedures.
  • Work with platform experts to implement remedial measures as appropriate.
  • Test security controls and manage the associated remediation of any deficiencies.
  • Assess security information, triage and respond to security events, identify false positives, and conduct correlation analysis across numerous internal and external data sources while prioritizing information security incidents.
  • Perform project management tasks for security initiatives and projects.
  • Manage incident-handling processes, including implementation of containment, protection, and remediation activities.
  • Support information security training and awareness by providing ideas and content.
  • Collaborate with the Training and Development department with updates to employee security awareness education and training.
  • Manage multiple priorities and deadlines concurrently.
  • Provide support after hours, on weekends, and through on-call rotation.
  • Perform other duties as assigned.

Requirements

  • 7+ years in Information Security, or IT Operations management and systems administration with at least 5 years specific to IT Security and at least 2 years managing IT Security staff.
  • Strong knowledge of Information Security design, principles, and processes.
  • Experience in writing and maintaining information security policies, standards, and guidelines.
  • Incident response experience is required.
  • In-depth knowledge of Windows/Unix operating system forensics, event logging systems, authentication methods, remote and local web application security, and penetration testing.
  • Advanced experience in networking (TCP/IP) protocols, DNS, LDAP, AD, DHCP, HTTP, web browsers, firewalls, and other computer/network and application security and system administration.
  • Demonstrated ability to monitor and audit network security systems such as Firewalls, IPS, SIEM, DLP, web proxy, NAC, and Vulnerability Scanners.
  • Hands-on experience with mitigating security controls (i.e., IAM, RBACs, anti-virus, IPS/IDS, DLP, web and network proxies, URL content filtering, multi-factor authentication, SSL VPNs).
  • Familiar with regulatory compliance regulations (PCI, PII, HIPAA, GDPR, etc.).
  • Strong knowledge of common security frameworks (ISO, NIST, etc.).
  • Experience in risk assessments and vulnerability management.
  • General knowledge of Endpoint protection solutions.
  • Knowledge of mainstream operating systems (Microsoft Windows, Linux, IOS) and a wide range of security technologies.
  • Microsoft Azure DevOps Security design implementation, automation is a plus.
  • General knowledge of Database technologies and queries (Microsoft SQL, MySQL, Oracle, etc.) is a plus.
  • Ability to independently identify, research, and resolve issues with minimal supervision.
  • Ability to work with peers in a team effort.
  • Detail-oriented with excellent communication, organization, and analytical skills.
  • Ability to plan, take initiative to accomplish objectives in a timely fashion, and work independently.
  • Ability to prioritize work and meet deadlines.
  • Ability to establish and maintain effective working relationships with project team members, supervisors, and other employees.
  • Speak, read, write, and understand English.
  • High reasoning ability.

Skills

  • Information Security
  • IT Operations management
  • Systems administration
  • IT Security
  • Risk management
  • Cloud security
  • On-premises security
  • Information Security architectures
  • Information security policies
  • Incident Response
  • Business Continuity Planning
  • Vulnerability scanning
  • IDS/IPS
  • Anti-virus technologies
  • DLP
  • SIEM
  • EDR
  • Host forensics
  • Malware analysis
  • Firewalls
  • Network security groups
  • Threat intelligence platforms
  • Proxy solutions
  • Security Operations Center (SOC) collaboration
  • Risk mitigation
  • Security audits
  • Penetration testing
  • Threat detection
  • Endpoint security
  • Governance
  • Technology infrastructure security
  • Internal control systems
  • Access control
  • Vulnerability management
  • Endpoint protection
  • Microsoft Windows
  • Linux
  • IOS
  • Microsoft Azure DevOps Security
  • Database technologies
  • Microsoft SQL
  • MySQL
  • Oracle
  • Communication skills
  • Organization skills
  • Analytical skills
  • Project management

Experience Level

  • Management

Education Level

  • Bachelor’s Degree in Computer Science, or a related discipline.