Cybersecurity Manager
Company Overview
A mission-driven organization based in the San Fernando Valley, California provides essential services and resources throughout the region. The organization supports a large, distributed workforce and maintains a highly regulated technology environment where information security, privacy, and operational resilience are critical. This is an opportunity to help shape and mature an enterprise cybersecurity program while making a meaningful impact within a community-focused organization.
Role Summary
The Cybersecurity Manager will lead the organization’s enterprise information security program while remaining actively involved in day-to-day security operations and engineering. This role will oversee cybersecurity strategy, Azure and Microsoft security, vulnerability management, incident response, identity and access management, compliance, and third-party security services. The ideal candidate is a hands-on cybersecurity leader who can balance strategic program development with technical execution while developing a growing team.
Key Responsibilities
- Develop and execute a multi-year cybersecurity strategy, roadmap, and program maturity plan aligned with organizational risk and business priorities.
- Lead security operations across cloud, identity, endpoint, email, data protection, vulnerability management, and network security.
- Strengthen security across Microsoft Azure and the broader Microsoft security ecosystem, including identity, endpoint, SIEM, device management, and data protection capabilities.
- Own vulnerability management processes, including identification, prioritization, remediation tracking, reporting, and continuous improvement.
- Develop and mature incident response processes, coordinate investigations, lead root-cause analysis, and oversee remediation activities.
- Establish and maintain security policies, standards, controls, risk assessments, and compliance documentation.
- Lead security governance and compliance initiatives within a HIPAA-regulated environment, including audit readiness and control effectiveness.
- Partner with IT and business stakeholders to embed security into system design, infrastructure standards, change management, and emerging technology initiatives.
- Manage security vendors, managed service providers, external assessments, penetration testing, and continuous monitoring relationships.
- Lead, mentor, and develop technical team members while establishing security KPIs, reporting, training, and awareness programs.
Additional Details
- Work model: On-site for the first 90 days, transitioning to a hybrid schedule with up to two remote days per week
- Leadership responsibility for systems and infrastructure professionals
- Approximately 60% hands-on technical work, 20% team leadership, and 20% vendor/service-provider management
- Opportunity to significantly influence cybersecurity strategy, tooling, processes, and long-term program maturity
- Current initiatives include privileged access management, incident response maturity, vulnerability management, email security, AI governance, and expanded use of enterprise security capabilities
Required Qualifications
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
- 7+ years of experience in cybersecurity, information security, risk management, security engineering, or related disciplines.
- 4+ years of leadership experience managing technical teams, security programs, or both.
- 5+ years of hands-on experience supporting security and compliance within HIPAA-regulated environments.
- Strong hands-on experience securing Microsoft Azure environments and working within a Microsoft-centric enterprise security ecosystem.
- Experience across security operations, vulnerability management, incident response, identity and access management, endpoint security, and network security.
- Demonstrated experience managing security vendors, managed service providers, and external security partners.
- Strong executive communication skills with the ability to translate technical vulnerabilities and cybersecurity risks into business impact.
Preferred Qualifications (Nice-to-Haves)
- Experience with Microsoft Sentinel, Entra ID, Intune, Defender, Purview/DLP, or comparable enterprise security technologies.
- Experience administering or securing Palo Alto or comparable enterprise firewall environments.
- Background improving privileged access management and identity security capabilities.
- Experience developing or maintaining an Information Security Management System and supporting ISO 27001 readiness.
- Familiarity with HITRUST and other healthcare security or privacy frameworks.
- Experience establishing governance and security policies for AI and emerging technologies.
- Experience supporting large, multi-site organizations with 1,000+ users.
- CISSP, CISM, CRISC, HCISPP, Microsoft Security/Azure, or comparable professional certifications.
Compensation & Benefits
- $160,000 - $165,000 with discretionary bonus
- Medical, dental, and vision benefits
- Employer-sponsored retirement benefits, including a defined-benefit pension program
- 403(b) and additional deferred compensation opportunities
- Three weeks of accrued vacation during the first year, plus sick time and paid holidays
- Life, disability, and additional employee wellness benefits
- Eligibility for qualifying public-service student loan forgiveness programs