INFORMATION SECURITY MANAGER
$150k - $155kCatalyst Acoustics Group
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
INFORMATION SECURITY MANAGER
Full Time Professional Agawam, MA, US
Salary Range: $150,000.00 To $155,000.00 Annually
Department: Technology
Reports to: VP, Technology (David Crandall)
Direct reports: None initially (program is MSP-backed — Paragus co-managed SOC)
Primary location: Boston or Chicago metro preferred; Columbus, OH (Dublin/Kinetics hub), Remote
Travel: Occasional, across CAG's U.S. sites
FLSA status: Exempt
Comp reference: $120,000–$155,000 base + up to 10% bonus
About Catalyst Acoustics Group
Catalyst Acoustics Group (CAG) is a mid-market manufacturer of noise-control and vibration control products, operating a family of brands (Kinetics Noise Control, Sound Seal, IAC Acoustics, Frasch, Lamvin, Noise Barriers, RealAcoustix, Madrid, CurbTech, and Riverbank Acoustical Laboratories) across roughly a dozen U.S. sites, with the Dublin, OH Kinetics campus as our technology hub. We run a cloud-first Microsoft 365 / Azure environment backed by a managed security provider (Paragus). Security is being established as its own dedicated function within Technology.
Role summary
We are seeking an Information Security Manager — a hands-on player-coach who will both run the security program and do the operational security work. This is the senior owner of CAG's information-security function: you set the roadmap, governance, and reporting, and you also personally respond to incidents, tune the tooling, and work the queue. It is a single-owner role (no direct reports at the outset), leveraging our managed provider (Paragus co-managed SOC) for scale rather than an internal team.
This role is the permanent successor to CAG's summer security internship, which concludes in August 2026. It assumes senior ownership of the three functions the intern ran day-to-day — security ticket triage, the KnowBe4 awareness program, and Huntress EDR response — and adds the program governance, risk/compliance, and leadership reporting that a manager owns. A clean handoff package from the intern will be available.
You will report to the VP, Technology and partner across IT, HR, Operations, and the brands, plus manage security vendors and the co-managed SOC relationship.
Scope covers IT and information security across CAG’s cloud-first Microsoft 365 / Azure environment; operational-technology (OT) systems on the plant floor are addressed in partnership with Operations.
Essential functions
Program ownership (the “manager” half)
- Own and drive CAG's information-security roadmap and priorities across all brands and sites.
- Develop and maintain security policy, standards, and governance; drive toward a defined baseline (e.g., change management, access governance, IR plan approved by the ELT).
- Own risk and compliance: risk register, control gaps, vulnerability-management program cadence, annual penetration-test coordination, and remediation tracking.
- Own the security awareness program (KnowBe4): training assignment/completion, monthly phishing-simulation campaigns, targeted remediation with HR, and metrics.
- Manage security vendors and tooling — including the Paragus co-managed SOC relationship, EDR, and email security — holding them to scope and outcomes.
- Report to leadership: regular security posture, KPIs, incident summaries, and risk readouts for the VP, Technology and the ELT.
- Lead security due diligence and integration for CAG acquisitions — assess acquired environments and fold them into CAG’s security baseline.
- Own cyber-insurance renewal attestations and respond to customer and contractual security questionnaires and audits.
- Own or co-own business continuity and disaster-recovery planning, including backup-integrity validation and recovery testing.
- Contribute the security lens to the multi-brand ERP consolidation and other major technology projects (access model, segregation of duties, secure design).
Hands-on operations (the “player” half)
- Incident response — lead investigation, containment, and resolution; own the IR runbooks and post-incident reviews; elevate to the VP, Technology as appropriate; available for reasonable after-hours response to high-severity incidents.
- EDR (Huntress) — monitor and triage the alert queue, validate and classify alerts, respond to standard types, tune detections, and drive novel/high-severity cases to closure.
- Email security (Mimecast) — administer the platform, manage quarantine and policy, and respond to email-borne threats.
- Identity & M365 security — MFA/Conditional Access, privileged-access and elevated-permission governance, Defender/Entra security posture, and account-compromise response.
- Phishing response — own end-user phishing reports and “is this safe?” triage in Zoho Desk, applying and improving the playbooks.
- Vulnerability management — run/coordinate regular scans, prioritize findings, and drive patching/remediation to closure.
Qualifications
Required
- 5+ years in information security with a mix of hands-on operations and program/leadership responsibility — able to both run the program and do the work directly. (Hands-on technical depth is weighted over policy-only backgrounds, per leadership direction.)
- Direct experience with incident response and EDR tooling (Huntress, Microsoft Defender, CrowdStrike, SentinelOne, or similar).
- Microsoft 365 / Entra (Azure AD) security depth: MFA/Conditional Access, privileged access, Defender.
- Email security administration (Mimecast, Proofpoint, or similar).
- Vulnerability management and remediation experience.
- Experience owning or heavily contributing to a security awareness program (KnowBe4 or similar).
- Ability to set policy/governance and to report security posture to executive leadership.
- Strong written and verbal communication; can translate risk for non-technical stakeholders.
- Authorization to work in the United States.
- Bachelor’s degree in cybersecurity, information systems, computer science, or a related field, or equivalent experience.
Preferred
- Security certifications (CISSP, CISM, GIAC, or CompTIA Security+/CySA+) are a plus but not required.
- Experience managing a co-managed SOC / MSSP relationship.
- Manufacturing or multi-site / multi-entity (incl. post-acquisition) environment.
- Familiarity with our stack: Huntress, Mimecast, KnowBe4, Microsoft Defender/Entra, Zoho Desk, Intune.
What success looks like (first 6–12 months)
- Clean assumption of the three intern-run functions (ticket triage, KnowBe4, Huntress) with a clean transition from the intern’s coverage and interim arrangements in place as needed.
- A published security roadmap and baseline policy set, with an ELT-approved incident-response plan.
- A running cadence: vulnerability scans, awareness campaigns, and a monthly security readout to leadership.
- The Paragus co-managed SOC relationship actively managed to defined outcomes.
EEO Statement: The Company is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
#J-18808-Ljbffr$134.5k - $265.1k
Position Summary Data Privacy ManagerAs a Manager in Deloitte’s Digital Trust & Privacy practice, you will lead the discovery,... ...functional, and business requirements and establish use cases to inform future state architecture.Architect:Navigate complex IT...SuggestedLocal area$105.67k - $128.86k
...Want to make an impact? I Am Boundless is hiring for a Information Systems Security Manager ! Boundless is a non‑profit organization specializing in assisting individuals with I/DD and has been serving Ohio for over 40 years. At I Am Boundless, we’re on a mission to...SuggestedFull timeImmediate startFlexible hours- ...the Bank's technology governance, risk management, and compliance (GRC) program. Serves as... ...; ensure contract provisions address security, privacy, SLAs, and right-to-audit. Coordinates... .... Job RequirementsBachelor’s degree in Information Systems, Computer Science, Business, or...SuggestedContract workWork at office
$90k - $110k
...provides cost-effective, business-driven, collaborative, and secure IT services and solutions to public service agencies... ...accomplish with our support. Job Summary The Enterprise Information Security Manager , reporting to the Chief Information Security Officer , is...SuggestedTemporary workFor contractorsLive inLocal area- About this role:Wells Fargo is seeking an Information Security Engineering Manager to lead a Privileged Access Management (PAM) engineering organization. This role is responsible for securing, modernizing, and evolving enterprise privileged access capabilities, including...SuggestedFull timeWork experience placementSecond jobRemote workFree visa
$125k - $135k
...Led by an experienced management team and supported by a strong investor group, including large and experienced institutions and strategic... ...demanding Network, Content, and Cloud customers. Title: Area Security Manager, Ohio Position: Full Time Location: Columbus, Ohio...Full timeContract workWorldwideShift work- ...to an already outstanding team.Accenture Security helps organizations prepare, protect,... ...cyber defense, application security and managed service solutions to rethink the entire... ...paid holidays, and paid time off. See more information on our benefits here:U.S. Employee Benefits...Full timeWork experience placementLive inWork at officeLocal area
$148.2k - $292.3k
...Summary As a Full Stack Engineer Manager in Deloitte Cyber’s Digital Trust &... ...communicate effectively with business, security, privacy, legal, and compliance stakeholders... ...degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent...Local areaVisa sponsorship$127.5k - $204k
...Fintech and payments, and we move money and information in a way that moves the world. We... ...of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay... ..., including Identity and Access Management (IAM), Privileged Access Management (PAM...Full timeTemporary workH1bWork at officeMonday to Friday$134.5k - $265.1k
...but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address evolving threats through integrated security strategies, technologies, and managed services. By advising on how to strengthen risk management, security...Contract workLocal areaVisa sponsorship$134.5k - $265.1k
...opportunities by delivering solutions and managed services that reduce complexity,... ...You will design, implement, and optimize secure, outcome-focused solutions while collaborating... ...in Computer Science, Cybersecurity, Information Systems, or another technical field, or...Local areaVisa sponsorship- ...imagine.ABOUT ACCENTURE SECURITYAccenture Security helps organizations prepare, protect,... ...bring.The WorkAs an OT Cybersecurity Senior Manager, you will lead complex, multi-workstream... ...holidays, and paid time off. See more information on our benefits here:U.S. Employee...Full timeWork experience placementLive inWork at officeLocal area
$163.4k - $322.1k
...advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities... ..., investigations, emergency communications, case and incident management, and physical security technology. The Physical Security...Local areaVisa sponsorship$196k - $294k
...cybersecurity leader redefining how organisations secure human risk. Our AI-powered, API-enabled Human Risk Management platform is purpose-built to protect... ...& backgroundDepth of experience in enterprise information security, with 10+ years in a leadership role -...Full timeWork at officeLocal areaImmediate startWorldwide2 days per week$105.4k - $207.8k
...could be the place for you. Traditional security programs have often been unsuccessful... ...control assessments, approvals, exception management, and go-live governance.Support the... ...degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information...Local areaWorldwideVisa sponsorship$105.4k - $207.8k
...an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support... ..., and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation, and...Local areaVisa sponsorship- ...position available immediately for a IT Security Specialist(ITSS2) to join our customer in... ...that include:-Monitor network and information system activity.-Respond to alerts (analyze... ...ensure that the customer is satisfied. -Manage, update, modify alerts, adjust/fine tune...Contract workImmediate start
$134.5k - $265.1k
...landscape. Through powerful solutions and managed services that simplify complexity, we... ...with confidence, and proactively manage to secure success.Recruiting for this role ends on... ...Saviynt.Understand complex business and information technology management processes. Execute...Local areaVisa sponsorship$65k - $75k
...Job Title: Cyber Security SOC Analyst II Experience: 1–2 years Compensation: $65,000 – $75,000 per year (Negotiable) Work Authorization... ...queries. Qualifications Bachelor's degree in Cyber Security, Information Technology, Computer Science, or a related field. 0–2 years of...- ...using their STEM background. This position offers unique opportunities to enhance your engineering skills while tackling national security threats. As an agent, you will conduct federal investigations, work with elite professionals, and have access to advanced technology...Work at office
- The Federal Bureau of Investigation (FBI) in the United States seeks individuals to become special agents. You will plan and conduct investigations into federal violations, cybersecurity incidents, and public safety threats, applying advanced analytical skills and professional...Work at office
- ...UnityTec in Columbus, OH is seeking a Vulnerability Management Analyst (OS/Infrastructure) to proactively discover, assess, and remediate security risks across enterprise networks, operating systems, and applications, while collaborating with mission partners to prioritize...
- ...Field Chief Information Security Officer (CISO) About the Company Prominent provider of cloud-based email management services Industry Information Technology and Services Type Public Company Founded 2003 Employees 1001-5000 Categories Accounting...Work at office
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry... ..., and brings a unique perspective to the team. Hiring Manager Title SVP, Security & CISO Functions ~ Information Technology...Remote work
- ...Network And System Security SpecialistTesting and identifying network and system vulnerabilitiesEvaluating the organization’s security needs and establishing best practices and standards accordinglyTaking appropriate security measures to ensure that DRC’s infrastructure...
- ...Job Description Job Description The Manager, Cybersecurity is responsible for leading... ...practice sites. This position oversees security operations, threat detection and incident... ...and vendors handling protected health information, and ensure Business Associate Agreements...
$105.4k - $207.8k
...ownership in privacy-by-design initiatives, Consent & Preference Management, and AI governance efforts, and large-scale technology... ...functional, and business requirements and establish use cases to inform future state architecture.General awareness of global and domestic...Local area- ...clients. By combining advanced business and security practitioner knowledge, the Sr. CSA... ...Identity Governance, Digital Access Management (MFA/SSO), Privileged Access Management... ...facilitating thought leadership, support, information, and guidance in conjunction with sales...Full timeWork experience placementLocal areaRemote workWork from home
- ...you canABOUT ACCENTURE SECURITYAccenture Security helps organizations prepare, protect,... ...cyber defense, application security, and managed service solutions to rethink what security... ...holidays, and paid time off. See more information on our benefits here:U.S. Employee Benefits...Full timeWork experience placementLive inWork at officeLocal areaRemote work
$174k - $252k
Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.Create... ...requirements, including potential access to classified information.Bachelor's degree or equivalent practical experience.5 years of...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to INFORMATION SECURITY MANAGER. Be the first to apply!
- entry level information security analyst Columbus, OH
- data center security officer Columbus, OH
- information security compliance analyst Columbus, OH
- director information security Columbus, OH
- information security lead Columbus, OH
- information security Columbus, OH
- senior information security analyst Columbus, OH
- sr information security engineer Columbus, OH
- information technology security engineer Columbus, OH
- entry level information security analyst


