Description: The role of a Security Engineering Manager is critical in ensuring an organization's digital assets remain secure. Let's break down the responsibilities and qualifications for this position:
Responsibilities:
Aligning Processes: The Security Engineering Manager aligns threat and vulnerability management (TVM), network security, and code security processes across the organization. They also develop and document standards for organizational use.
Vulnerability Management: They manage the development and implementation of vulnerability management practices, frameworks, and playbooks to maintain consistency, quality, reliability, and integrity.
Understanding Business Processes: The manager demonstrates an advanced understanding of business processes, internal control risk management, IT controls, and related standards.
Balancing Access and Compliance: They facilitate the use of technology-based tools to review, design, and implement products and services, ensuring a strong program that balances access with compliance and confidentiality.
Risk Evaluation: Identifying and evaluating complex business and technology risks, internal controls, and opportunities for improvement.
Impact Assessment: Understanding the broader impact of decisions related to user access, data access, and information security.
Process Maturity: Developing and expanding vulnerability management, identity management, and network security processes.
Threat Intelligence: Monitoring external threat intelligence and vulnerability feeds, researching emerging threats, and deploying preventive solutions.
Metrics Development: Creating key metrics for executive and internal visibility into security posture.
Qualifications:
Experience: A minimum of ten years of progressive experience in cybersecurity, with at least four years in a leadership role.
Education: An undergraduate degree in computer science, information systems, cybersecurity, or a related field is preferred.
Industry Experience: Experience in the financial services industry is advantageous.
Project Management: Solid understanding of project management principles.
Cloud Security: Familiarity with security concepts in a hybrid cloud environment.
Vulnerability Management: Hands-on experience managing an enterprise vulnerability management program.
Knowledge Areas: Expertise in Cloud Platform Security, M365 Security, Application Security, Code Security, Data Security, End Point and Mobile Security, and Infrastructure and Network Security.
SDLC Integration: Ensuring controls are implemented and automated into the software development life cycle (SDLC).
Communication Skills: Strong oral and written communication skills.
Leadership: Ability to lead and manage a team independently.
Business Acumen: Translate security matters into clear business terms for executives.
Cross-Functional Collaboration: Work effectively in cross-functional teams.
Project Management: Assign tasks and think strategically.
Problem-Solving: Strong problem-solving and troubleshooting skills.
Certifications and Licenses:
Preferred certifications include CISSP, CISM, GSLC, GPEN, or other security certifications.
Contact: nmorrissey@judge.com
This job and many more are available through The Judge Group. Find us on the web at www.judge.com