Security Manager
Title: Security Manager
Job Category: Exempt
Business Unit/Depart: Information Technology
Reports to: CIO/BIO/IT Director
Position Purpose:
Under general direction, the Security Officer oversees firm-wide information and physical security by guiding risk assessments, asset auditing, and security planning activities. This role also serves as the Disaster Recovery Manager, responsible for developing, maintaining, and periodically testing Disaster Recovery and Business Continuity Plans. The Security Officer brings strong technical expertise and proven leadership skills, including the ability to influence and motivate cross-functional teams without direct reporting authority. The position is responsible for establishing and enforcing effective security policies and systems that align with organizational goals and operate within defined budget, time, and performance constraints.
Responsibilities/Duties/Functions/Tasks:
· Directs the overall security program for the Firm.
· Develops and supervises all security measures in the company, to include IT, legal, human resources, corporate communications and related departments.
· Determines appropriate levels of security controls and monitoring systems.
· Serves as an independent security advisor to the senior management of the firm.
· Provides direct oversight and training to all employees, alliances and affiliate marketing partners to create security awareness.
· Conducts periodic vulnerability and security risk assessment of the assets of the company. This includes SOC/ISO and penetration testing annually.
· Identifies and eliminate foreseeable information security risks and vulnerabilities to comply with privacy and information security policies and procedures. Solutions should be strategic in nature and increase data safety.
· Monitors compliance of information security procedures and policies and reports infringements to their Management.
· Coordinate and manage Business Continuity and Disaster Recovery planning and testing in partnership with the business, HR, and management committee.
· Prepares the disaster recovery plan and updates it periodically.
· Chairs the Information Security Committee.
· Audits and reviews Information Security issues in the organization
· Cooperate with other Organizations on Information Security Issues.
· Handles Information Security Incidents.
· Meets client expectations for Information Security of the organization.
· Responds to Client Audit reviews on Information and Physical Security issues.
· Identify and recommend new security technology solutions that competitively position the business for future success.
· Benchmark, analyze, report on and make recommendations for the improvement and growth of the overall security program.
· Build and maintain relationships, alignment and commitment within the business and support groups and encourage team members to work collaboratively
· Interfaces with industry experts on Cyber Security and related matters.
· Support the planning, engineering and implementation of software and hardware upgrades.
· Coordinates and facilitates security portions of client audits and/or visits.
· Take responsibility for own professional development.
· Monitor networks and logs for security breaches and investigate any suspicious activity or violations.
· Effectively manage self, time, and resources.
Qualifications:
· BS/BA or higher in Computer Science, Information Systems or a related field or equivalent work experience.
· At least 5+ years of experience in computing or related areas with a focus on technology, management, policy and/or security operations.
· Preferably be in the process or already have professional IT security certifications such as CISSP/GIAC/SSCP/CISSA
· Ability to make sound and logical judgments.
· Demonstrated leadership and people/project management skills.
· Ability to prioritize and execute tasks in a high-pressure environment and make sound decisions in emergency situations.
· Technical understanding of Cloud computing, desktop, and Infrastructure environments.
· Highly self-motivated and self-directed.
· Ability to build relationships with business unit leaders and their staff.
· Excellent client service orientation.
· Excellent computer, communication and management skills.
Work Requirements:
· While performing the duties of this job, the employee is frequently required to sit at the workstation for extended periods. The employee must have the ability to communicate effectively in written and oral form; enter data into a computer; and operate standard office equipment including computer, telephone, printer, copier, and facsimile machine.
· May be required to work a flexible work schedule. Occasional travel to other firm locations is required.
· The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Normal office conditions. The noise level in the work environment is usually moderate