CybersecurityJobs.io
← Back to all jobs

Job Description

Spokane, WA (onsite) opportunity for a hands-on Cybersecurity Manager to run day-to-day security execution and mature URM’s cybersecurity program.

Responsibilities

  • Oversee day-to-day cybersecurity operations and engineering, including operation, maintenance, and continuous improvement of security technologies, controls, processes, and engineering activities.
  • Lead and develop the Security Engineering team by setting ownership, priorities, technical standards, and measurable expectations while staying hands-on with security engineering, troubleshooting, implementation, configuration, and complex technical investigations.
  • Provide technical leadership across endpoint and application security, network security, vulnerability management, identity and privileged access, email security, and logging/monitoring; ensure solutions are configured, integrated, monitored, maintained, and continuously improved.
  • Partner with the Infrastructure & Cybersecurity Architect and Infrastructure Engineering teams to integrate cybersecurity into enterprise technology and architecture across network, systems, cloud, identity, and enterprise architecture.
  • Evaluate emerging cybersecurity technologies and recommend options based on risk reduction, technical fit, integration needs, and long-term supportability.
  • Establish and maintain operational standards and documentation, including cybersecurity standards, procedures, architecture diagrams, technical documentation, and security operations runbooks.
  • Lead security operations and incident response by coordinating internal security operations and working with managed security and detection-and-response partners.
  • Serve as the primary internal leader for Tier 2/3 escalations, including investigation, containment, remediation, and recovery.
  • Drive threat detection and response by ensuring meaningful telemetry is collected and used across endpoint, identity, network, cloud, email, infrastructure, and critical systems.
  • Lead incident activities during significant cybersecurity events by coordinating response across IT teams, external partners, and business stakeholders.
  • Strengthen incident preparedness by maintaining and continuously improving incident-response plans, playbooks, escalation procedures, and technical response capabilities.
  • Lead tabletop exercises and ensure identified actions and improvements are tracked through completion.
  • Improve operational accountability through post-incident reviews, documented lessons learned, and measurable metrics for detection, investigation, response, and control effectiveness; ensure outcomes feed back into controls, processes, architecture, and training.
  • Own vulnerability and exposure management with consistent, risk-based processes for identifying, prioritizing, remediating, and validating vulnerabilities.
  • Use risk evaluation factors including technical severity, exploitability, exposure, business criticality, sensitive-data considerations, and compensating controls.
  • Coordinate and measure remediation with infrastructure, application, endpoint, and system owners; monitor vulnerability aging, remediation SLAs, exceptions, compensating controls, and accepted risk.
  • Oversee security testing and validation by coordinating penetration testing, vulnerability assessments, remediation, and validation of findings.
  • Lead cybersecurity governance and control-maturity initiatives established by the Sr. Director, Infrastructure & Cybersecurity, including continued adoption and maturation of the NIST Cybersecurity Framework and other applicable requirements.
  • Support cybersecurity compliance, audits, and assessments including PCI DSS, regulatory and contractual requirements, and third-party assessments by maintaining repeatable policies, standards, procedures, control documentation, evidence, and technical validation.
  • Identify, track, and remediate cybersecurity risks and control gaps with technical and business owners, including practical remediation plans, tracking exceptions and compensating controls, and evaluating third-party security controls and documentation.
  • Collaborate with architecture, engineering, Applications, Data/Integration/AI, Member Services, business stakeholders, and external security partners to ensure controls are practical, effective, supportable, and aligned to URM’s objectives.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or related field, or equivalent experience.
  • 7+ years of progressive cybersecurity, security engineering, infrastructure security, or related technical experience.
  • 2+ years of technical leadership or people-management experience.
  • Hands-on experience implementing, operating, troubleshooting, and improving enterprise cybersecurity technologies and controls.
  • Strong knowledge of network security (firewalls, segmentation, VPNs), endpoint security, identity and access management, MFA, privileged access, logging, monitoring, and cloud security.
  • Experience in incident investigation and response, vulnerability and exposure management, security assessments, control validation, and remediation.
  • Working knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework.
  • Experience supporting PCI DSS or other regulated and audited environments, including audits, assessments, evidence collection, and remediation activities.
  • Ability to lead and develop a technical cybersecurity team while remaining hands-on with complex security engineering and investigations.
  • Experience working with infrastructure and technology teams, business stakeholders, managed security providers, vendors, auditors, and third-party assessors.
  • Strong skills in analytics, troubleshooting, documentation, planning, communication, and organization; ability to prioritize based on risk and business impact and remain effective during high-impact security incidents.

Technologies

  • NIST Cybersecurity Framework, NIST CSF, PCI DSS
  • Microsoft Entra, Microsoft 365, Azure
  • SIEM/XDR, Stellar Cyber, Qualys
  • ThreatLocker, BeyondTrust, Carbon Black, Microsoft Defender
  • Mimecast, Fortinet
  • Zero Trust, SASE/ZTNA
  • Network segmentation, modern identity architectures
  • CISSP, CISM, CRISC, GIAC, Security+, CySA+

Benefits

  • Salary: $150,000 - $160,000 DOE
  • URM pays 100% of Medical/Dental/Vision/RX premiums for the employee and over 93% for dependents
  • 401k Retirement Plan with company match up to 9% of annual salary
  • Subsidized Life Insurance for employees and great rates for family
  • Company paid Long-Term Disability insurance
  • Short-Term Disability and Cancer Insurance available
  • Life Flight Insurance at special rate
  • Great vacation plan
  • Six Paid Holidays and four Paid Personal Holidays
  • Paid Sick Days
  • Paid Volunteer Service Day
  • Company sponsored activities including URM March Madness Brackets, Family Hockey Night with the Chiefs, Holiday Mingle & Jingle, Summer Evening Wine & Music Event, and Winter Break Movie Night
  • Corporate discounts including gym memberships, cell phone plans, and computer discounts
  • Amazing Employee Discount Program at Company-owned Grocery Stores

Preferred Qualifications

  • Experience leading or supporting NIST CSF assessments, cybersecurity maturity programs, and PCI DSS technical controls
  • Experience with Microsoft Entra, Microsoft 365, Azure, hybrid/cloud environments, SIEM/XDR, endpoint protection, vulnerability management, application control, privileged access, email security, and network-security technologies
  • Experience with security platforms such as Stellar Cyber, Qualys, ThreatLocker, BeyondTrust, Carbon Black, Microsoft Defender, Mimecast, Fortinet, or comparable technologies
  • Experience with Zero Trust, SASE/ZTNA, network segmentation, and modern identity architectures
  • Experience in grocery, wholesale distribution, logistics, retail, or other high-availability operational environments
  • Relevant professional certifications such as CISSP, CISM, CRISC, GIAC, Security+, CySA+, or comparable credentials

Core Competencies

  • Technical Leadership: Combines strong cybersecurity expertise with effective people leadership and a hands-on approach to complex technical challenges
  • Risk-Based Decision Making: Translates cybersecurity frameworks, compliance requirements, and technical risks into practical controls and prioritizes work based on business impact and measurable risk reduction
  • Operational Excellence: Planning, execution, documentation, follow-through, and continuous improvement
  • Communication & Collaboration: Communicates with technical teams, leadership, business stakeholders, auditors, vendors, managed service providers, and external assessors; coordinates across teams and organizations

Similar Jobs