Cybersecurity Manager
Manager
Cloud Platforms
Cybersecurity Tools
Data Security
Endpoint Security
Identity and Access Management
Incident Response
Information Security
Infosec
Management
Nist Cybersecurity Framework
NIST SP 800-53
Project Management
Risk Governance
Risk Management
Security
Security Automation
Security Compliance
Vulnerability Management
Job Description
Information Security Manager to lead security operations and compliance programs across the organization, in a hybrid role based in Durham, NC.
Responsibilities
- Security Operations & Engineering Endpoint Security: administer and optimize Microsoft Defender across the endpoint environment, including policy configuration, alert triage, incident response, and reporting.
- Network and Access Security: manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.
- SIEM Operations: own SIEM administration, detection engineering, log source onboarding, alerting, incident workflows, dashboards, and operational metrics.
- Vulnerability Management: lead vulnerability scanning efforts across AWS, Azure, and on-premises environments. Prioritize, track, and validate remediation activities in partnership with IT and engineering teams.
- Patch Management: maintain endpoint patching programs, reporting, exception tracking, and service-level compliance.
- Digital Forensics & Incident Response: investigate security events, perform forensic analysis, document findings, and coordinate response activities with internal and external stakeholders.
Requirements
- AI technologies usage to enhance and scale security operations, with an AI-first mindset for Security Operations.
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
- 5+ years of progressive information security experience with expertise in security operations, engineering, or related fields.
- Hands-on administration and tuning of Microsoft Defender (Endpoint, Identity, and Cloud).
- Production experience managing Zscaler (ZIA and/or ZPA), including policy administration and troubleshooting.
- Strong SIEM experience, including detection development, alert tuning, incident investigation, and log source integration.
- Experience managing vulnerability programs across AWS and Azure cloud environments.
- Working knowledge of digital forensics and incident response methodologies.
- Experience operating security programs aligned with the NIST Cybersecurity Framework and/or NIST 800-53.
- Proven ability to write, maintain, and operationalize security policies and standards.
- Excellent written and verbal communication skills, including the ability to explain technical risks to non-technical audiences.
- Ability to work in a hybrid environment with regular in-office presence.
Technologies
- Microsoft Defender, Zscaler (ZIA, ZPA), AWS, Azure, Python, PowerShell, KQL, NIST Cybersecurity Framework, NIST 800-53
Benefits
- 401(k)
- Dental insurance
- Employee assistance program
- Flexible schedule
- Parental leave
- Relocation assistance
- Retirement plan
- Tuition reimbursement
Pay
- USD 140,000 - 170,000 per year
Location
- Hybrid remote in Durham, NC 27711
Preferred Qualifications
- Industry certifications such as CISSP, CISM, GCIH, GCFA, GCIA, or equivalent.
- Experience in highly regulated environments or critical infrastructure sectors.
- Familiarity with industry regulatory frameworks and compliance requirements.
- Experience scripting or automating security workflows using Python, PowerShell, KQL, or similar technologies.
- Prior experience serving as a senior technical lead preparing to transition into a management role.