Manager, Information Security
El Segundo, CA  / Denver, CO  / Chicago, IL  / New York, NY  / Dallas, TX  / Vienna, VA ...View All
View Less
Share
Posted 14 days ago
Job Description
Description

Information Security Manager

AArete is one-of-a-kind when it comes to consulting firm culture.

Why AArete?

We are a global, innovative management and technology consulting firm, with offices in the U.S., India, and the U.K. Our name comes from the Greek word for excellence: "Arete." And excellence is exactly what we strive for.

Our success starts with enriching and empowering our people. From robust career development planning to competitive life and wellness benefits, AArete's "Culture of Care" takes a holistic approach to the employee experience. At AArete, we encourage you to unlock your full potential by directly contributing to our mission and prioritizing space for personal development and fulfillment.

The Role

AArete is looking for an Information Security Manager. You are highly technical with an entrepreneurial spirit and commitment to excellence. You strive in a team environment and can flip tasks and priorities midstream because you love an exciting challenge. The bar is set high at AArete. There is a lot to do around here, and you love getting the job done right.

Work You'll Do

  • Lead and oversee information security budget, staffing, and contracting.
  • Communicate the value of information technology (IT) security throughout all levels of the organization stakeholders.
  • Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support information technology (IT) security goals and objectives and reduce overall organizational risk.
  • Provide leadership and direction to information technology (IT) personnel by ensuring that cybersecurity awareness, basics, literacy, and training are provided to operations personnel commensurate with their responsibilities.
  • Promote awareness of security issues among management and ensure sound security principles are reflected in the organization's vision and goals.

  • Security Program & Operations
  • Lead and align information technology (IT) security priorities with the business strategy.
  • Identify security requirements specific to an information technology (IT) system in all phases of the system life cycle.
  • Oversee policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity best practices.
  • Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs) against HITRUST, ISO, SOC2, etc. frameworks
  • Collect and maintain data needed to meet system cybersecurity reporting.
  • Ensure that security improvement actions are evaluated, validated, and implemented as required.
  • Ensure that cybersecurity inspections, tests, and reviews are coordinated for the network environment.
  • Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture.
  • Establish overall enterprise information security architecture.
  • Evaluate and approve development efforts to ensure that baseline security safeguards are appropriately installed.
  • Establish information security strategies to address organizational security objective.
  • Identify information technology (IT) security program implications of new technologies or technology upgrades.
  • Interface with external organizations (e.g., public affairs, law enforcement, Command or Component Inspector General) to ensure appropriate and accurate dissemination of incident and other Computer Network Defense information.
  • Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
  • Manage the monitoring of information security data sources to maintain organizational situational awareness.
  • Manage threat or target analysis of cyber defense information and production of threat information within the enterprise.
  • Oversee the information security training and awareness program.
  • Participate in an information security risk assessment during the Security Assessment and Authorization process.
  • Participate in the development or modification of the computer environment cybersecurity program plans and requirements.
  • Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations.
  • Recognize a possible security violation and take appropriate action to report the incident, as required.
  • Recommend resource allocations required to securely operate and maintain an organization's cybersecurity requirements.
  • Recommend policy and coordinate review and approval.
  • Use organization-specific published documents to manage operations of the computing environment system(s).
  • Evaluate the effectiveness of procurement function in addressing information security requirements and supply chain risks through procurement activities and recommend improvements.
  • Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals.
  • Continuously validate the organization against policies/guidelines/procedures/regulations/laws to ensure compliance.
  • Forecast ongoing service demands and ensure that security assumptions are reviewed, as necessary.
  • Evaluate risk levels and security posture and advise senior management.
  • Advise senior management on cost/benefit analysis of information security programs, policies, processes, systems, and elements.
  • Advise appropriate senior leadership or Authorizing Official of changes affecting the organization's cybersecurity posture.
  • Supervise or manage protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
  • Track audit findings and recommendations to ensure that appropriate mitigation actions are taken.
  • Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.

Requirements

  • Bachelor's Degree in information security, computer science, cybersecurity preferred
  • Minimum 5 years of experience in Information Technology Security with at least 3 years of managerial experience
  • Minimum 2 years of experience with Amazon Web Services (AWS)
  • Security certifications such as CISSP, CISM, OSCP, or AWS Security is ideal.
  • Ability to clearly explain complex security requirements to technical and non-technical audiences.
  • Prior experience in Healthcare and/or Financial sector a plus
  • Prior experience at a consulting or professional services firm a plus
  • Applicants must be based in Chicago, IL and flexible to work from our Chicago office as needed

Benefits

  • Flexible PTO, monthly half-day refuels, volunteer time off, 10 paid holidays
  • Own Your Day flexible work policy
  • Competitive majority employer-paid benefits: Medical, Dental, Vision, 401K Match
  • Employee Stock Ownership Plan
  • Generous maternity/paternity leave options
  • Completely employer paid Life Insurance, STD, LTD
  • Charitable contribution matching program
  • New client commission opportunities and referral bonus program
  • Video-free Fridays
  • Bike share discount program

About AArete

AArete is a global management and technology consulting firm specializing in strategic profitability improvement, digital transformation, and advisory services. Our cross-industry solutions are powered by modern technology, market intelligence, and big data to drive purposeful change and actionable outcomes.

AArete is guided by our deeply embedded principles: Excellence, Passion, Loyalty to Clients, Stewardship, Family, Community, Sustainability, and Inclusion.

We are proud to have earned a Great Place to Work Certification and named one of America's Best Management Consulting Firms by Forbes, Vault's Top 50 Firms to Work For, Crain's Chicago Business Fast 50, Inc 5000's Fastest Growing Firms, Consulting Magazine's Fastest Growing Firms.

AAP/EEO Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

#LI-DNI

 

Job Summary
Company
Start Date
As soon as possible
Employment Term and Type
Regular, Full Time
Required Education
Bachelor's Degree
Required Experience
5+ years
Email this Job to Yourself or a Friend
Indicates required fields