Information Security Manager

LaBella Associates
  • Rochester, NY
  • $105,000–$125,000 Per Year
  • Quick Apply
5 days ago

Job Description

LaBella is looking to hire an Information Security Manager at our Rochester, NY office. The primary responsibilities of this position are the leadership and administration of security aspects of our organization’s technology and related risk management, including the organization’s security personnel and vendors. The position is tasked with ensuring a secure workplace by planning and executing security practices using preventive measures, education, and policy as required by local laws, regulatory compliance, and best practices for the industries LaBella provides service for.

Responsibilities

Specific Duties/Responsibilities include but are not necessarily limited to the following:

  • Team Leadership:
    • Supervise, train, and mentor security team including cybersecurity engineers, cybersecurity analysts and GRC/compliance personnel.
  • Strategy and Policy:
    • Develop and enforce security policies, standards, and procedures to prevent unauthorized access, loss, or destruction of company data.
    • Oversee policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies.
    • Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals.
  • Risk Management:
    • Identify vulnerabilities, conduct threat assessments, and implement mitigation strategies.
    • Advise senior management on risk levels and security posture.
    • Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s).
    • Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
    • Coordinate with IT leadership to ensure cybersecurity goals align with IT goals and technology.
  • Technical Oversight:
    • Monitor networks for security breaches, manage security alerts, encryption policies, and security tools, and ensure compliance with security controls.
    • Collect and maintain data needed to meet system cybersecurity reporting.
    • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
  • Incident Response:
    • Lead the response to security breaches, viruses, or cyberattacks.
    • Supervise or manage protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
  • Compliance & Training:
    • Ensure compliance with legal/regulatory requirements and conduct security awareness training for staff.
    • Oversee the information security training and awareness program.
    • Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
    • Continuously validate the organization against policies/guidelines/procedures/regulations/laws to ensure compliance.
  • Vendor Management:
    • Manage third-party risks by assessing vendor security protocols.
    • Provide system-related input on cybersecurity requirements to be included in statements of work and other appropriate procurement documents.

Salary Range: $105,000 - $125,000 per year

The specific salary offered may be influenced by a variety of factors including but not limited to the candidate's relevant experience, education, and work location.

Requirements

  • Bachelor’s degree or higher in Cybersecurity, Information Technology, or a related field.
  • Certification: CISSP, CISM, or similar
  • Proven experience in IT security, network administration, and managing security teams.
  • Strong leadership skills.
  • Strong knowledge of network infrastructure, security tools, risk management, incident response, and compliance frameworks.
  • Excellent written communication skills with the ability to independently compose clear reports and directive communications to management and employees.
  • Excellent verbal communication skills for both one-on-one conversations and for speaking before groups.
  • Excellent organizational skills with attention to detail and follow-through.
  • Ability to work in a team environment and to communicate effectively with people at all levels within the organization.
  • Self-motivated to continuously seek ways to aid and improve processes.
  • Ability to multi-task.
  • An uncompromised ability to keep information confidential.
  • Knowledge of applicable regulatory requirements.
  • Core Knowledge Requirements:
    • Team leadership and mentoring.
    • Data backup and recovery concepts and workflows.
    • Business continuity and disaster recovery continuity of operations plans.
    • Intrusion detection methodologies and techniques for detecting host and network-based intrusions.
    • Physical, logical, and policy controls related to the use, processing, storage, and transmission of data.
    • Policy directives on full-disk and file-level encryption technologies and encryption methods for secure exchange of data with 3rd parties.
    • Policy and procedural alignment with LaBella’s enterprise Information Technology (IT) goals and objectives.
    • Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Measures or indicators of system performance and availability.
    • Laws, policies, procedures, or governance relevant to cybersecurity for critical infrastructures for US, UK, Spain, and other similar countries and regions. GDPR experience a plus.
    • Familiarity with network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools and network traffic analysis methods.
    • In-depth knowledge of server and client operating systems.
    • Skill in creating policies that reflect system security objectives.
    • Information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures.
    • New and emerging information technology (IT) and cybersecurity technologies and current and emerging threats/threat vectors.
    • Vulnerability information dissemination sources (e.g., alerts, advisories, errata, and bulletins) and what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
    • Penetration testing principles, tools, and techniques.

Benefits

Body, mind, and wallet—LaBella’s benefits support a holistic approach to your health and wellness, creating the foundation for physical, mental, and financial well-being. Our benefit offerings cover the must-haves (healthcare and retirement), the just-in-cases (insurances and employee assistance programs), and the cherry-on-tops (fitness reimbursements, year-end incentive pay, and tuition assistance). Visit our website for more details on benefits listed below.

  • Flexible Work Schedule
  • Health/Dental Insurance
  • 401k Plan with Employer Match
  • Paid Parental Leave
  • Short & Long Term Disability
  • Profit Sharing
  • Paid Time Off
  • Leadership Development Program
  • Fitness Reimbursement
  • Tuition Reimbursement
  • Referral Bonus Program
  • Wellness Program
  • Team Building Events
  • Community Service Events

LaBella is committed to facilitating a culture where diversity, equity, and inclusion are respected, valued, and celebrated by implementing thoughtful, practical, and innovative strategies that support our employees and serve the communities in which we reside. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws.

LaBella Associates does not accept unsolicited resumes from recruiting professionals or agencies, nor do we accept resumes from any source that does not reference a specific, open position. LaBella Associates will not be responsible for any fees arising from the use of resume submitted by recruiting professionals or agencies that do not have a current placement fee agreement with LaBella Associates. All initial communication with recruiting professionals or agencies must go through human resources.

Numbers & Facts

LocationRochester, NY
Salary$105,000–$125,000 Per Year

Skills

  • Best Practicesunmatched
  • Business Continuity Planning (BCP)unmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Communication Skillsunmatched
  • Community and Social Servicesunmatched
  • Computer Securityunmatched
  • Cryptographyunmatched
  • Data Collectionunmatched
  • Data Recoveryunmatched
  • Data Storageunmatched
  • Database Backupunmatched
  • Detail Orientedunmatched
  • Disaster Recoveryunmatched
  • Diversityunmatched
  • Education Regulationsunmatched
  • Emerging Technologyunmatched
  • Employee Assistance Planunmatched
  • File Encryptionunmatched
  • Fitnessunmatched
  • Follow Throughunmatched
  • Healthcareunmatched
  • Human Resourcesunmatched
  • IT Requirementsunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Management Strategyunmatched
  • Mentoringunmatched
  • Multitaskingunmatched
  • Network Administration/Managementunmatched
  • Network Monitoringunmatched
  • Network Securityunmatched
  • Network Systemsunmatched
  • Network Traffic Analysisunmatched
  • Operating Systemsunmatched
  • Organizational Skillsunmatched
  • Penetration Testingunmatched
  • Performance Analysisunmatched
  • Policy Developmentunmatched
  • Policy Implementationunmatched
  • Presentation/Verbal Skillsunmatched
  • Process Improvementunmatched
  • Purchasing/Procurementunmatched
  • Recruiting/Staffing Agencyunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Reimbursementunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Complianceunmatched
  • Security Monitoringunmatched
  • Security Protocolsunmatched
  • Staff Trainingunmatched
  • Standards Strategyunmatched
  • Statement of Work (SOW)unmatched
  • Supply Chainunmatched
  • Supply Chain Managementunmatched
  • Systems Administration/Managementunmatched
  • Team Buildingunmatched
  • Team Lead/Managerunmatched
  • Team Playerunmatched
  • Technical Leadershipunmatched
  • Training Programunmatched
  • Training/Teachingunmatched
  • Tuition Feesunmatched
  • Vendor/Supplier Evaluationunmatched
  • Vendor/Supplier Managementunmatched
  • Virusesunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder