Manager, Information Security
Building Service 32BJ Benefit Funds
Job Description
Job Description
Job Title: Manager, Information Security
Grade: TBD
Department: Information Technology
Reports To: Senior Manager, IT Infrastructure
FLSA Status: Exempt (Management)
Summary: The Manager, Information Security will be responsible for the strategic leadership, execution, and continuous improvement of the organization’s information security program designed to protect the Funds’ systems, networks, and data. This role will provide critical oversight of security operations, develop and maintain policies and frameworks, and mentor members of the Information Security team. The Manager will be responsible for managing the risk register, define and implement frameworks to improve Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), Incident Response Plans, and ensure the Information Security Policy Manual and Business Continuity Plan addresses the evolving threat landscape and compliance requirements. The successful candidate will be a hands-on leader, well-versed in both operational security and governance, and capable of building a scalable, resilient information security team aligned with the Funds’ broader IT strategy.
Essential Duties and Responsibilities:
- Lead and manage the IT Security Operations team, including Information Security Analysts, Engineers, and Incident Responders.
- Provides guidance and expertise in the field of risk management regarding the protection and security of digital assets in the cloud and on-premises.
- Designs and develops Information Security architectures to prevent unauthorized access to our system, networks, data, and information.
- Develops, maintains, enhances, and implements information security policies and procedures, including
- the Information Security Policy Manual, Incident Response plans, playbooks, runbooks, and the Business Continuity Plan documents on a regular basis as changes occur.
- Coordinates and performs business continuity planning and incident response exercises on an annual basis within IT and with business champions. Coordinates and leads response efforts during security incidents.
- Manages, maintains, and monitors security technologies such as vulnerability scanning solutions, IDS/IPS, anti-virus technologies, DLP capabilities, SIEM technologies, EDR, host forensics and malware analysis, core and web application firewalls, network security groups, threat intel platforms, and proxy solutions.
- Oversees and collaborates with our Security Operations Center (SOC) provider to review threat alerts, reports, and ensures the team follows up on all actionable information.
- Receives guidance and collaborates with our vCISO to manage all security initiatives, risk mitigation plans, annual assessments, security audits, and penetration testing activities.
- Manages real time threat detection technologies to identify and quarantine threats, monitors endpoint security alerts and takes corrective action.
- Minimizes security threats by examining governance, technology infrastructure, and facilities to identify security deficiencies, using risk analysis and follow up with corrective action plan.
- Monitors internal control systems to ensure appropriate access levels are maintained, protects against unauthorized system access, modification and destruction.
- Reviews security related reports, logs and occurrences; escalates issues and initiates security response procedures.
- Creates and reviews vulnerability reports, tracks compliance with vulnerability management policies, and escalates.
- Researches and evaluates emerging technologies, latest cybersecurity threats, trends, tools, and best practices in support of security technology enhancements applicable to the organization’s environment, proposes technical solutions to management, to address security weaknesses, and coordinates with relevant stakeholders to implement.
- Reviews, updates, and enforces data security practices within the organization; tests for exposures to ensure adherence to relevant regulations and frameworks (e.g., NIST, ISO 27001, PCI-DSS, HIPAA) and procedures and works with platform experts to implement remedial measures as appropriate.
- Tests security controls and manages the associated remediation of any deficiencies as needed.
- Assesses security information, triaging and responding to security events, identifying false positives, and conducts correlation analysis across numerous internal and external data sources while prioritizing information security incidents.
- Performs project management tasks for security initiatives and projects.
- Manages incident-handling processes, which include implementation of containment, protection, and remediation activities.
- Supports information security training and awareness by providing ideas and content and collaborates with the Training and Development department with updates to employee security awareness education and training.
- Manage multiple priorities and deadlines concurrently.
- Provides support after hours, on weekends, and through on-call rotation.
- Performs other duties as assigned.
Qualifications:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required.
- 7+ years in Information Security, or IT Operations management and systems administration with at least 5 years specific to IT Security and at least 2 years managing IT Security staff.
- Strong knowledge of Information Security design, principles, and processes; Experience in writing and maintaining information security policies, standards, and guidelines.
- Incident response experience is required; in-depth knowledge of Windows/Unix operating system forensics, event logging systems, authentication methods, remote and local web application security, and penetration testing.
- Advanced experience in networking (TCP/IP) protocols, DNS, LDAP, AD, DHCP, web browsers, firewalls, and other computer/network and application security and system administration.
- Demonstrated ability to monitor and audit network security systems such as Firewalls, IPS, SIEM, DLP, web proxy, NAC, and Vulnerability Scanners.
- Hands on experience with mitigating security controls (i.e., IAM, RBACs, anti-virus, IPS/IDS, DLP, web and network proxies, URL content filtering, multi-factor authentication, SSL VPNs).
- Familiar with regulatory compliance regulations (PCI, PII, HIPAA, GDPR, etc.).
- Strong knowledge of common security frameworks (ISO, NIST, etc.).
- Experience in risk assessments and vulnerability management.
- General knowledge of Endpoint protection solutions.
- Knowledge of mainstream operating systems (Microsoft Windows, Linux, IOS) and a wide range of security technologies.
- Microsoft Azure DevOps Security design implementation, automation is a plus
- General knowledge of Database technologies and queries (Microsoft SQL, MySQL, Oracle, etc.) is a plus
- Ability to independently identify, research and resolve issues with minimal amount of supervision, and ability to work with peers in a team effort.
Interpersonal Skills:
- Detail oriented with excellent communication, organization and analytical skills.
- Ability to plan, take initiatives to accomplish objectives in a timely fashion, and work independently.
- Ability to prioritize work and meet deadlines.
- Ability to establish and maintain effective working relationships with project team members, supervisors, and other employees.
Education and/or Experience: Bachelor’s Degree in Computer Science, or a related discipline.
Language Skills: Speak, read, write and understand English
Reasoning Ability: High
Certificates, Licenses, Registrations: CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), or CISA (Certified Information Systems Auditor) certification are highly preferred.
Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals to perform the essential functions.
- Under 1/3 of the time: Standing, Walking, Climbing or Balancing, Stooping, Kneeling, Crouching, or Crawling
- 1/2 to 2/3 of the time: Sitting, Reaching with Hands & Arms
- Over 2/3 of the time: Talking or Hearing
- 100% of the time: Using Hands
Work Environment: The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
- 1/3 to 2/3 of the time: Work near moving or mechanical parts, exposure to radiation, moderate noise.
$109.37k - $123.04k
...Summary:We are seeking a highly skilled and motivated Senior Manager, IT Security Operations to join our team. As the Senior Manager, IT... ...assets, ensuring the integrity and confidentiality of sensitive information, and maintaining the overall security posture of our...SuggestedFull timeWork experience placementWork at officeLocal areaRemote work$155k - $207k
...Director of Engineering, you are a pragmatic security leader who acts as a business enabler... ....You are a technical player-coach who manages the "how" behind engineering initiatives... ...within their respective domains.Govern the Information Security Program, developing high-...SuggestedWork at officeImmediate startFlexible hours$169k - $296k
...the world. If you're excited to shape the future of design and collaboration, join us!Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic initiatives and engagement across the organization. This is a fast-moving role...SuggestedMinimum wageFull timeLocal areaRemote workFlexible hours$157k - $210k
..., platforms, processes, and tools. As a security technical program leader focused on enterprise security and Identity & Access Management (IAM), you will work across cross-functional... ...or SaaS industry.A Bachelor's degree in Information Security, Computer Science, or a related...SuggestedPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours- Job Title: Manager, Information Security Grade: TBD Department: Information Technology Reports To: Senior Manager, IT Infrastructure FLSA Status: Exempt (Management) Summary: The Manager, Information Security will be responsible for the strategic leadership, execution...SuggestedLocal areaRemote workWeekend work
$192k - $278k
...executive stakeholders.Drive updates and secure commitments for technical security... ...coding developments.Lead significant change management to coordinate teams adapting to the agentic... ...product development with engineers. The Information Security Engineering (ISE) Technical...$175.4k - $283.8k
...of work across engineering related to security audits (SOC 2, ISO 27001)Assist engineering... ...Customer Trust teams to ensure correct information is provided to customers and prospects... ...and maintain Third Party Risk Management for all unique-to-Chronosphere risksBuild...Full timeRemote work$140k - $245k
...join us! We’re looking for an expert Technical Program Manager (TPM) to support our Security Operations team. In this role, you’ll partner with our... ...technology or security teams Strong understanding of information security principles and controls, including data protection...Full timeRemote workWork from home$100k - $132k
...and delivery for a cross-functional Cyber Security or IT program, including influence over... ..., and stakeholder engagement Manage multiple complex projects timelines, risks... ...stakeholders ~ Strong understanding of information security frameworks (e.g., NIST, PCI-DSS...$192.6k - $260.5k
Amazon's Specialized Businesses Security team is seeking a Security Engineer Manager to lead our Specialized Detections team. This is a forward-driving leadership... ...to what your team should build next quarter, informed by coverage gap analysis and intelligence from the Vulnerability...Remote workFlexible hours- ...Director, Information Security At the NYC Department of Buildings, we are responsible for ensuring the safe and lawful use of buildings... ...awareness. Responsibilities will also encompass security and Risk Management Framework (RMF) focused architecture and engineering of the...
- ...Job Description Job Description / Qualifications Project Manager (Security Business Lead) Acting as Security Business Lead, this... ...Certifications Preferred Certifications: CISSP (Certified Information Systems Security) CISM (Certified Information Security Manager...Work at office2 days per week
- ...Iceberg, a world-leading hedge fund in New York, seeks an experienced cyber security professional to take on a player-coach role with a roughly 70/30 split between leadership and hands-on technical work, owning the company’s detection and response functions. The environment...
- ...service at any time.Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO)... ...the incumbent will serve as the Director of the Cyber Risk Management (CRM) bureau, providing oversight of the Vulnerability Management...Work at officeShift work
$180k - $230k
...can accurately and scalably synthesize information from medical records, with the mission... ...round, etc. We're scaling up the security function at Layer Health, and we're looking... ..., network security, secrets and key management, vulnerability management, secure configuration...Full time$156k - $195k
...adopt AI applications and agentic systems, security teams need visibility and control over... ...ensuring sensitive data is properly managed from model training through production.As... ...applications. Privacy and AI Guidelines:Any information you submit to Datadog as part of your...Work at office- ....KPMG is currently seeking an Associate Director, Regional Information Security Awareness Lead to join our Global Technology and Knowledge... ...corporate environment with at least two years of experience in management positionBachelor's degree from an accredited college/...H1bLocal area
- DescriptionCompany Overviewiboss is a cloud security company that enables the modern workforce to connect securely and directly... ...Fortune 500 companies. To learn more, visit .Job DescriptionThe Manager of Information Security & Compliance is a key leadership role responsible...
$165k - $185k
...hands-on Director, Applications and Data Security to support the security of the League’s... ..., threat modeling, vulnerability management, and secure software development practices... ...ExperienceBachelor’s degree in Computer Science, Information Security, Engineering, Information...Work at officeLocal areaRemote work1 day per week- ...Florida, and Washington DC, Fairstead owns and manages a portfolio of more than 30,000 apartments, including... ..., dedication, and integrity. The Security Manager provides strategy and activities related to information security and physical security of the property(...All shiftsFlexible hoursShift work
$148.5k - $223.9k
...Salesforce.Location: New York, NYThe ExperienceAs a Manager, Office of the CISO, you serve as a trusted security, compliance, privacy, and risk advisor to... ...or Public Sector.You've worked within a Business Information Security Office, Office of the CISO, Customer Trust...Full timeWork at office$154k - $205k
We’re looking for a Senior Technical Product Marketing Manager to join our security product marketing team and help bring Datadog’s rapidly growing... ..., and Enablement to craft differentiated messaging, inform roadmap decisions, and build cross-product solution narratives...Work at office$136.5k - $350k
...the role of Senior Director of Network Security - Engineering Lead to join our Network... ...Cloud engineering governance, delivery management, and prioritization using Agile practices... ...preferred15+ years of experience in information security or related technology experience...Temporary workWork experience placementRemote workWorldwideFlexible hours$160k - $250k
...stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native... ...for a seasoned Principal Product Manager to join our team, with experience in developing... ...disability, medical condition, genetic information, membership or activity in a local human...Full timeWork experience placementWork at officeLocal areaFlexible hours2 days per week$185k - $296k
...in the world. If you're excited to shape the future of design and collaboration, join us!Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll...Minimum wageFull timeLocal areaRemote workFlexible hours- Job DescriptionData Product Manager/Business Analyst - Securities Markets Technology (Capital Markets)The Role - What You’ll DoYou will be part of a cross-cultural global team working on a variety of business consulting engagements in Capital Market. You will be a part...Full timeTemporary work
$143k - $210k
...more at .What You’ll Do:The Data Center Security organization at CoreWeave is responsible... ...Center Security Business Operations Program Manager, you will own the financial, contractual... ...origin, veteran status, or genetic information.As part of this commitment and consistent...Permanent employmentFull timeContract workTemporary workFor contractorsCasual workWork at officeFlexible hours- Head of Infrastructure Security | Global Alternative Investment Firm Head of Infrastructure... ...shape policy, drive tooling adoption, manage high-performing engineers and architects... ...Bachelor’s degree in Computer Science, Information Security, or a related field (Preferred)...Full timeWork at officeRemote work
$87.5k - $170k
...proud to be home to 90% of the top 30 asset managers in the private markets, and more than 6,... ...: We are looking for an Application Security Manager to lead and scale our... ...Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent...Local areaFlexible hoursShift work- ...mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower... ...successful at Vanta without it. We are seeking an experienced Manager of Security Operations, reporting to the Director of Security,...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager, Information Security. Be the first to apply!
- security engineering manager New York, NY
- security operations manager New York, NY
- senior security manager New York, NY
- physical security manager New York, NY
- security manager New York, NY
- program manager with security clearance New York, NY
- director global security New York, NY
- surveillance manager New York, NY
- senior director information security New York, NY
- security systems manager New York, NY


