The Security manager is responsible for defining and ensuring adherence to security policies and standards within the Enterprise Information Technology (IT) environment and works to develop security policies and guidelines in conjunction with application and process owners. The Security Manager is responsible for promoting organizational security awareness and advising management about security issues and potential threats. He/she may also carry out risk analysis activities. It is important that the Security Manager be current on the latest security problems/risks/resolutions. Interacting with partner companies and security organizations to share ideas around security issues is highly recommended.
Responsibilities
- Develops enterprise security standards and policies
- Makes recommendations to achieve operational and project goals in conjunction with security requirements and best practices
- Monitors and assesses security vulnerabilities across technical disciplines
- Acts as a subject matter expert for the technical security arena
- Provides advisory services to direct reports, security team members and the business
- Serves as an escalation point for security related issues and works to resolve security risks and to minimize potential threats
- Researches and stays current on new and evolving technologies and associated security risks
- Develops security tools and utilities that may be leveraged by the organization
- Reviews security specific change requests and provides risk assessments for changes
- Builds and maintains relationships with peer security professionals
Qualifications/Certifications
- Experience in the IT security sector
- Ability to lead and manage technical staff
- Capable of designing and implementing state-of-the-art security services
- Experience providing advisory services in the area of technology and security architecture
- Broad understanding of computer and communication systems and networks and their interrelationships
- Strong task and project management skills with the ability to manage parallel work streams
- Good understanding of privacy and regulatory laws, their implications, and mitigating measures
- CISSP or related certification