- Location
- Center 53, United States of America
- Type
- Full-time
- Department
- Security
- Seniority
- Manager
- Source
- Workday
Description
We Go Beyond:
At Bed Bath & Beyond, we believe that everyone should “Be You!”. Bed Bath & Beyond is a community that upholds a culture of understanding, acceptance, and respect. We believe a person’s individuality, traits, beliefs, and characteristics should be valued and embraced. Living by this ethos is essential to the success of our business. Our goal is to foster a more inclusive environment where every employee visibly demonstrates inclusive behaviors and respect for individuals.
Responsible for safeguarding enterprise and customer-facing technology environments by identifying, mitigating, and remediating cybersecurity risks. This role leads security operations, incident response coordination, security tooling administration, vulnerability management, vendor/MSSP engagement, and continuous improvement of security controls across the organization.
ESSENTIAL JOB DUTIES
Lead daily security operations, including alert triage, investigation, escalation, containment, remediation coordination, documentation, and post-incident follow-up.
Serve as an operational leader for incident response, ensuring events are validated, classified, escalated, tracked, and managed through appropriate ticketing and incident management processes.
Maintain and improve security runbooks, response procedures, investigation workflows, evidence handling, technical timelines, and post-incident review practices.
Operate and mature detection, response, threat monitoring, threat hunting, and suspicious activity review capabilities.
Partner with Fraud Prevention and Application Security on account takeover, bot, abuse, credential attack, and other adversarial activity affecting customer or commerce platforms.
Own administration, integration, performance, documentation, lifecycle planning, SME coverage, and support expectations for core security operations tools.
Improve tooling effectiveness to reduce risk, improve visibility, or reduce operational complexity.
Own or coordinate vulnerability management workflows, including intake, prioritization, remediation tracking, exception handling, validation, assessments, penetration tests, assumed breach exercises, and reporting.
Partner with Application Security, Infrastructure, Cloud, and Technology teams to drive timely remediation of vulnerabilities and control gaps.
Manage WAF, bot mitigation, API protection, and related edge security changes while balancing risk reduction with customer and platform availability.
Manage day-to-day relationships with security vendors, VARs, and consulting partners.
Support cybersecurity standards, audit evidence, PCI/SOX-related controls, incident response readiness, and privacy/compliance requirements where security operations evidence or technical support is needed.
Lead, coach, and develop cybersecurity operations team members while establishing priorities, ownership, operating rhythms, on-call expectations, escalation paths, and accountability.
Perform other duties as required, including leading special projects assigned by leadership.
IMPACT
The Manager of Cybersecurity directly improves the company’s ability to detect, investigate, contain, and recover from cybersecurity threats. This role keeps security operations aligned with business priorities, reduces operational and customer-facing risk, improves the effectiveness of security tools, and ensures the organization is prepared to respond to security events with speed, discipline, and appropriate documentation.
MINIMUM QUALIFICATIONS
SKILLS
Security Operations and Incident Response
Security Information and Event Management (SIEM) and log analytics
Endpoint Detection and Response (EDR/XDR)
Digital Forensics and Incident Response (DFIR)
Threat Hunting and Detection Engineering
Threat and Vulnerability Management
Penetration Testing, Assumed Breach Assessments, and Remediation Validation
Web Application Firewall (WAF), Bot Mitigation, API Protection, and Edge Security
Public Cloud Security
Network Security, Identity Security, Email Security, DLP/CASB, and Endpoint Hardening
Security Architecture and Secure Design Collaboration
Security Automation, Tool Integration, Dashboards, and Operational Metrics
Vendor, VAR, Licensing, Renewal, and Service Management
PCI DSS, SOX, NIST, Incident Response Standards, and security/privacy control environments
EDUCATION/LICENSING/CERTIFICATION:
Graduation from an accredited institution with a bachelor’s degree in a technical discipline, Information Systems, Cybersecurity, Computer Science, Computer Engineering, or a related field; or any equivalent combination of education, certification, and/or practical experience.
CERTIFICATIONS (any of the following are acceptable)
SANS/GIAC (GSEC, GCIH, GCIA, etc.)
Public Cloud Security or DevOps certifications
CEH, CHFI, OSCP, CISSP, CISM
Relevant network or coding certifications
Physical Requirements
This position requires the incumbent to sit, stand and perform general office functions. The incumbent may also be required to lift 25 pounds or more occasionally. Bending, stooping and reaching are also frequently required.
Equal Employment Opportunity
It is company policy to provide equal employment opportunity for all applicants and associates. This policy includes our commitment to ensure that all employment decisions are made without regard to race, color, religion, gender, national origin, disability, pregnancy, veteran status (including Vietnam era veterans), age, sexual orientation, gender identity, or any other non-job-related characteristic protected by law.
Who We Are:
We’re a passionate group of collaborative problem solvers and creative innovators, working on cutting-edge technology. From building award-winning retail applications (with amazing AR functionality) to creating leading blockchain and machine learning technologies, each of us embodies a unique value and contributes a diverse perspective to the team.
What We Offer:
401k (6% match)
Flexible Schedules
Tuition Reimbursement, Leadership Development Program, & Mentorship Program
Employee Resource Groups (LatinX, Black Employee Network, LGBTQIA+, Women’s Network, Women In Tech)
And More…
*Benefits vary based on position, tenure, location, and employee election
Physical Requirements:
This position requires you to sit, stand and perform general office functions. You may also be required to lift up to 25 pounds occasionally. Bending, stooping and reaching are also frequently required.
Equal Employment Opportunity:
It is our policy to provide equal employment opportunity for all applicants and associates. This policy includes our commitment to ensure that all employment decisions are made without regard to race, color, religion, gender, national origin, disability, pregnancy, veteran status (including Vietnam era veterans), age, sexual orientation, gender identity, or any other non-job-related characteristic protected by law.