Responsibilities
- Manage security operations
- Supervise daily activities of the Managed Detection and Response Partner
- Administer and oversee security technologies like firewalls, intrusion detection systems, and SIEM solutions
- Ensure prompt identification, analysis, and handling of security incidents
- Handle incident response
- Create and update incident response plans and protocols
- Direct security incident responses, including investigations, reporting, and corrective actions
- Perform regular drills and training exercises to maintain readiness
- Manage threats
- Monitor and assess threat intelligence to spot potential security risks
- Deploy and administer threat detection and prevention technologies
- Execute penetration testing and red-team exercises to test defensive measures
- Oversee vulnerability management
- Lead the complete vulnerability management program, covering scanning, evaluation, and prioritization of findings in infrastructure and applications
- Collaborate with IT and practice stakeholders for timely remediation and patching, ensuring issues are resolved within set service level agreements
- Report on vulnerability status, trends, and remediation metrics to leadership
- Ensure data security
- Develop and maintain data security policies, including standards for data classification, encryption, and access control
- Implement and monitor data loss prevention controls to safeguard sensitive patient, client, and business information
- Work with IT and practice leadership to secure data handling across systems, vendors, and integrations
- Promote security awareness
- Design and execute a company-wide security awareness program, covering onboarding and continuous employee education
- Conduct phishing simulations and awareness campaigns, tracking and reporting on employee participation and risk trends
- Develop tailored training for high-risk teams and communicate emerging threats in clear, actionable terms
- Handle risk management and compliance
Requirements
- Bachelor's degree in Information Technology, Computer Science, or a related discipline
- At least four years of security operations experience, including data security, vulnerability management, or security awareness initiatives
- Demonstrated history of managing security operations and incident response, with preference for team leadership background
- Comprehensive understanding of security technologies, threat management, data protection methods, and vulnerability management tools and procedures
- Background in creating or conducting security awareness and training initiatives
- Outstanding leadership, communication, and interpersonal abilities
Nice to Have
- Advanced degree is advantageous
- Professional certifications such as CISSP, CISM, GSEC, or Security+ are strongly preferred
Work Arrangement
Remote
What we are Searching For
- Bachelor's degree in Information Technology, Computer Science, or a related discipline
- Advanced degree is advantageous
- Minimum four years in security operations, with experience in data security, vulnerability management, or security awareness programs
- Proven record in managing security operations and incident response, ideally with team leadership
- Strong grasp of security technologies, threat management, data protection practices, and vulnerability management tools and processes
- Experience in designing or operating security awareness and training programs
- Excellent leadership, communication, and interpersonal skills
- Relevant certifications like CISSP, CISM, GSEC, or Security+ are highly desirable