Cybersecurity Manager
Manager
Application Security
Cloud Platforms
Cybersecurity Tools
Data Security
Endpoint Security
Facilities Management
Identity and Access Management
Information Security
InfoSec
Management
Project Management
Risk Governance
Risk Management
Security
Security Compliance
Security Operations
Security Standards
Siem And Xdr
Software Security
Solution Architecture
Zero Trust
Zero Trust Architecture
Job Description
Spokane, WA (onsite) opportunity for a hands-on Cybersecurity Manager to run day-to-day security execution and mature URM’s cybersecurity program.
Responsibilities
- Oversee day-to-day cybersecurity operations and engineering, including operation, maintenance, and continuous improvement of security technologies, controls, processes, and engineering activities.
- Lead and develop the Security Engineering team by setting ownership, priorities, technical standards, and measurable expectations while staying hands-on with security engineering, troubleshooting, implementation, configuration, and complex technical investigations.
- Provide technical leadership across endpoint and application security, network security, vulnerability management, identity and privileged access, email security, and logging/monitoring; ensure solutions are configured, integrated, monitored, maintained, and continuously improved.
- Partner with the Infrastructure & Cybersecurity Architect and Infrastructure Engineering teams to integrate cybersecurity into enterprise technology and architecture across network, systems, cloud, identity, and enterprise architecture.
- Evaluate emerging cybersecurity technologies and recommend options based on risk reduction, technical fit, integration needs, and long-term supportability.
- Establish and maintain operational standards and documentation, including cybersecurity standards, procedures, architecture diagrams, technical documentation, and security operations runbooks.
- Lead security operations and incident response by coordinating internal security operations and working with managed security and detection-and-response partners.
- Serve as the primary internal leader for Tier 2/3 escalations, including investigation, containment, remediation, and recovery.
- Drive threat detection and response by ensuring meaningful telemetry is collected and used across endpoint, identity, network, cloud, email, infrastructure, and critical systems.
- Lead incident activities during significant cybersecurity events by coordinating response across IT teams, external partners, and business stakeholders.
- Strengthen incident preparedness by maintaining and continuously improving incident-response plans, playbooks, escalation procedures, and technical response capabilities.
- Lead tabletop exercises and ensure identified actions and improvements are tracked through completion.
- Improve operational accountability through post-incident reviews, documented lessons learned, and measurable metrics for detection, investigation, response, and control effectiveness; ensure outcomes feed back into controls, processes, architecture, and training.
- Own vulnerability and exposure management with consistent, risk-based processes for identifying, prioritizing, remediating, and validating vulnerabilities.
- Use risk evaluation factors including technical severity, exploitability, exposure, business criticality, sensitive-data considerations, and compensating controls.
- Coordinate and measure remediation with infrastructure, application, endpoint, and system owners; monitor vulnerability aging, remediation SLAs, exceptions, compensating controls, and accepted risk.
- Oversee security testing and validation by coordinating penetration testing, vulnerability assessments, remediation, and validation of findings.
- Lead cybersecurity governance and control-maturity initiatives established by the Sr. Director, Infrastructure & Cybersecurity, including continued adoption and maturation of the NIST Cybersecurity Framework and other applicable requirements.
- Support cybersecurity compliance, audits, and assessments including PCI DSS, regulatory and contractual requirements, and third-party assessments by maintaining repeatable policies, standards, procedures, control documentation, evidence, and technical validation.
- Identify, track, and remediate cybersecurity risks and control gaps with technical and business owners, including practical remediation plans, tracking exceptions and compensating controls, and evaluating third-party security controls and documentation.
- Collaborate with architecture, engineering, Applications, Data/Integration/AI, Member Services, business stakeholders, and external security partners to ensure controls are practical, effective, supportable, and aligned to URM’s objectives.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or related field, or equivalent experience.
- 7+ years of progressive cybersecurity, security engineering, infrastructure security, or related technical experience.
- 2+ years of technical leadership or people-management experience.
- Hands-on experience implementing, operating, troubleshooting, and improving enterprise cybersecurity technologies and controls.
- Strong knowledge of network security (firewalls, segmentation, VPNs), endpoint security, identity and access management, MFA, privileged access, logging, monitoring, and cloud security.
- Experience in incident investigation and response, vulnerability and exposure management, security assessments, control validation, and remediation.
- Working knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework.
- Experience supporting PCI DSS or other regulated and audited environments, including audits, assessments, evidence collection, and remediation activities.
- Ability to lead and develop a technical cybersecurity team while remaining hands-on with complex security engineering and investigations.
- Experience working with infrastructure and technology teams, business stakeholders, managed security providers, vendors, auditors, and third-party assessors.
- Strong skills in analytics, troubleshooting, documentation, planning, communication, and organization; ability to prioritize based on risk and business impact and remain effective during high-impact security incidents.
Technologies
- NIST Cybersecurity Framework, NIST CSF, PCI DSS
- Microsoft Entra, Microsoft 365, Azure
- SIEM/XDR, Stellar Cyber, Qualys
- ThreatLocker, BeyondTrust, Carbon Black, Microsoft Defender
- Mimecast, Fortinet
- Zero Trust, SASE/ZTNA
- Network segmentation, modern identity architectures
- CISSP, CISM, CRISC, GIAC, Security+, CySA+
Benefits
- Salary: $150,000 - $160,000 DOE
- URM pays 100% of Medical/Dental/Vision/RX premiums for the employee and over 93% for dependents
- 401k Retirement Plan with company match up to 9% of annual salary
- Subsidized Life Insurance for employees and great rates for family
- Company paid Long-Term Disability insurance
- Short-Term Disability and Cancer Insurance available
- Life Flight Insurance at special rate
- Great vacation plan
- Six Paid Holidays and four Paid Personal Holidays
- Paid Sick Days
- Paid Volunteer Service Day
- Company sponsored activities including URM March Madness Brackets, Family Hockey Night with the Chiefs, Holiday Mingle & Jingle, Summer Evening Wine & Music Event, and Winter Break Movie Night
- Corporate discounts including gym memberships, cell phone plans, and computer discounts
- Amazing Employee Discount Program at Company-owned Grocery Stores
Preferred Qualifications
- Experience leading or supporting NIST CSF assessments, cybersecurity maturity programs, and PCI DSS technical controls
- Experience with Microsoft Entra, Microsoft 365, Azure, hybrid/cloud environments, SIEM/XDR, endpoint protection, vulnerability management, application control, privileged access, email security, and network-security technologies
- Experience with security platforms such as Stellar Cyber, Qualys, ThreatLocker, BeyondTrust, Carbon Black, Microsoft Defender, Mimecast, Fortinet, or comparable technologies
- Experience with Zero Trust, SASE/ZTNA, network segmentation, and modern identity architectures
- Experience in grocery, wholesale distribution, logistics, retail, or other high-availability operational environments
- Relevant professional certifications such as CISSP, CISM, CRISC, GIAC, Security+, CySA+, or comparable credentials
Core Competencies
- Technical Leadership: Combines strong cybersecurity expertise with effective people leadership and a hands-on approach to complex technical challenges
- Risk-Based Decision Making: Translates cybersecurity frameworks, compliance requirements, and technical risks into practical controls and prioritizes work based on business impact and measurable risk reduction
- Operational Excellence: Planning, execution, documentation, follow-through, and continuous improvement
- Communication & Collaboration: Communicates with technical teams, leadership, business stakeholders, auditors, vendors, managed service providers, and external assessors; coordinates across teams and organizations