LaBella is looking to hire an Information Security Manager at our Rochester, NY office. The primary responsibilities of this position are the leadership and administration of security aspects of our organization's technology and related risk management, including the organization's security personnel and vendors. The position is tasked with ensuring a secure workplace by planning and executing security practices using preventive measures, education, and policy as required by local laws, regulatory compliance, and best practices for the industries LaBella provides service for.
Responsibilities
Specific Duties/Responsibilities include but are not necessarily limited to the following:
Team Leadership:
Supervise, train, and mentor security team including cybersecurity engineers, cybersecurity analysts and GRC/compliance personnel.
Strategy and Policy:
Develop and enforce security policies, standards, and procedures to prevent unauthorized access, loss, or destruction of company data.
Oversee policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies.
Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals.
Risk Management:
Identify vulnerabilities, conduct threat assessments, and implement mitigation strategies.
Advise senior management on risk levels and security posture.
Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s).
Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
Coordinate with IT leadership to ensure cybersecurity goals align with IT goals and technology.
Technical Oversight:
Monitor networks for security breaches, manage security alerts, encryption policies, and security tools, and ensure compliance with security controls.
Collect and maintain data needed to meet system cybersecurity reporting.
Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
Incident Response:
Lead the response to security breaches, viruses, or cyberattacks.
Supervise or manage protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
Compliance & Training:
Ensure compliance with legal/regulatory requirements and conduct security awareness training for staff.
Oversee the information security training and awareness program.
Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
Continuously validate the organization against policies/guidelines/procedures/regulations/laws to ensure compliance.
Vendor Management:
Manage third-party risks by assessing vendor security protocols.
Provide system-related input on cybersecurity requirements to be included in statements of work and other appropriate procurement documents.
Salary Range: $105,000 - $125,000 per year
The specific salary offered may be influenced by a variety of factors including but not limited to the candidate's relevant experience, education, and work location.
Numbers & Facts
Location
Rochester, NY
Salary
$105,000–$125,000 Per Year
Skills
Best Practicesunmatched
Computer Securityunmatched
Cryptographyunmatched
Data Collectionunmatched
Education Regulationsunmatched
IT Requirementsunmatched
Incident Responseunmatched
Information Technology & Information Systemsunmatched
Information/Data Security (InfoSec)unmatched
Internet Securityunmatched
Leadershipunmatched
Maintain Complianceunmatched
Mentoringunmatched
Network Monitoringunmatched
Network Securityunmatched
Policy Implementationunmatched
Purchasing/Procurementunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Regulatory Requirementsunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Security Analysisunmatched
Security Attacksunmatched
Security Complianceunmatched
Security Monitoringunmatched
Security Protocolsunmatched
Staff Trainingunmatched
Standards Strategyunmatched
Statement of Work (SOW)unmatched
Systems Administration/Managementunmatched
Team Lead/Managerunmatched
Technical Leadershipunmatched
Training Programunmatched
Training/Teachingunmatched
Vendor/Supplier Evaluationunmatched
Vendor/Supplier Managementunmatched
Virusesunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.