- Salary
- $109k – $123k
- Location
- National Audubon Society Washington, DC Office, United States of America · New York, NY
- Workplace
- Remote, Hybrid
- Type
- Full-time
- Department
- Operations
- Seniority
- Senior
- Experience
- 8+ years
- Education
- Master
- Source
- Workday
Description
About Audubon
The National Audubon Society is a leading nonprofit conservation organization with 120 years of science-based, community-driven impact, dedicated to protecting birds and the places they need, today and tomorrow. Birds are powerful indicators of our planet’s health, acting as sentinels that warn us of environmental change and inspire action. Audubon works across the Western Hemisphere, driven by the understanding that what is good for birds is good for the planet. Through a collaborative, bipartisan approach across habitats, borders, and the political spectrum, Audubon drives meaningful and lasting conservation outcomes. With 800 staff and over 1.9 million supporters, Audubon is a dynamic and ever-growing force committed to ensuring a better planet for both birds and people for generations to come. Learn more at www.audubon.org and on Facebook, Twitter and Instagram @audubonsociety.
Position Summary:
We are seeking a highly skilled and motivated Senior Manager, IT Security Operations to join our team. As the Senior Manager, IT Security Operations, you will play a crucial role in safeguarding our organization’s assets, ensuring the integrity and confidentiality of sensitive information, and maintaining the overall security posture of our systems and networks.
This position is classified as hybrid preferred. Hybrid employees are expected to work in an Audubon office every Monday and Tuesday and an additional two days each month of the employee’s choosing. Remote work within the United States may be considered only for candidates not within commuting distance of an Audubon office, in accordance with Audubon’s “Where We Work” Policy. Audubon offices include locations in:
Albuquerque, NM; Albany, NY; Anchorage, AK; Baltimore, MD; Charleston, SC; Chicago, IL; Columbia, SC; Fargo, ND; Fort Collins, CO; Lincoln, NE; Miami, FL; New Orleans, LA; New York, NY; Oakland, CA; Palm Desert, CA; Roseville, MN; Sacramento, CA; Salt Lake City, UT; Tallahassee, FL; and Washington, DC.
Compensation:
Salary range based on geo-differentials:
$109,372 - $123,044 / year = Albuquerque, NM; Charleston, SC; Columbia, SC; Fargo, ND; Fort Collins, CO; Lincoln, NE; Miami, FL; New Orleans, LA; Salt Lake City, UT; Tallahassee, FL
$123,041 - $138,421 / year = Albany, NY; Anchorage, AK; Baltimore, MD; Chicago, IL; Palm Desert, CA; Roseville, MN; Sacramento, CA; Washington, DC
$136,718 - $155,808 / year = New York, NY; Oakland, CA
Additional Job Description
Essential Functions:
Security Incident Response:
Partner with Chief Technology Officer, Senior Director of Information Technology, and Virtual Chief Information Security Officer (vCISO) to assess and respond to security incidents.
Monitor and respond to security alerts and incidents compliant with service level agreements outlined by policy.
Investigate, analyze, and document security incidents compliant with “chain of custody” processes, and implement appropriate countermeasures.
Security Tool and Services Management:
Evaluate, procure, administer, and manage security tools and supporting vendor services, including but not limited to password managers, phishing threat management, firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint management, endpoint detection and response (EDR), managed detection and response (MDR), antivirus, document management, and Security Information and Event Management (SIEM) solutions.
Regularly monitor, update, and fine-tune security systems to enhance effectiveness.
Lead vendor security review process in partnership with vCISO.
Security Policy and Compliance:
Assist in the development, implementation, review, and enforcement of security policies, standards, and procedures guided by ISO 27000 standards.
Ensure compliance with industry-specific regulations (e.g., PCI) and standards and coordinate and participate in regular audits.
Access Control and Authentication:
Administer Identity Provider (IdP) to manage user accounts, permissions, and access levels across various systems, following Identity and Access Management (IAM) workflows.
Maintain system role mapping documentation and lead and coordinate regular entitlement reviews as necessary.
Implement, administer, and manage multi-factor authentication (MFA) and single sign-on (SSO) solutions.
Vulnerability Management:
Oversee scheduled vulnerability scans and penetration tests.
Coordinate with relevant teams to remediate identified vulnerabilities.
Security Awareness and Training:
Curate and oversee security awareness program and portal for employees.
Provide specialized training on best practices for security hygiene.
Oversee phishing test program and remediation training program.
Security Documentation:
Maintain accurate and up-to-date security documentation, including incident reports, policies, procedures, and configurations.
Collaboration and Communication:
Collaborate with cross-functional teams to ensure security measures align with overall business objectives.
Communicate security risks and recommendations to management and relevant stakeholders.
Act as lead facilitator of IT Security Operations working group and participate in Architectural Review Board meetings.
Server and Network Configuration:
Assist cloud and network administration team with configurations and function of servers to limit access, mitigate intrusions, and protect assets.
Assist cloud and network administration team with configurations and topology of network devices to safeguard points of access and data security, including firewalls, routing, and ACLs.
Maintain and foster culture of safety.
Other job-related duties as assigned.
Qualifications and Experience:
Bachelor's degree in Information Security, Computer Science, or a related field.
Minimum 8 years of experience with IT operations with progressive experience in cybersecurity in a corporate or non-profit environment. An equivalent combination of education and work experience will also be considered.
Strong knowledge of cybersecurity technologies and best practices.
Proficiency in administering security tools and systems.
Excellent problem-solving and analytical skills.
Effective communication and interpersonal abilities.
Detail-oriented with a focus on accuracy.
Ability to work both independently and collaboratively in a team environment.
Experience with Defender for Endpoint, and Defender for Identity preferred.
Experience with Okta preferred.
Experience with Sonicwall FW hardware preferred.
Experience with distributed network environments preferred.
AWS / Azure / Public cloud expertise preferred.
Experience with SecDevOps best practices preferred.
Commitment to Audubon’s organizational values of care, collaboration, change, integrity, impact, and innovation.
Experience fostering inclusive and collaborative work environments is valued.
National Audubon Society Competencies: This role will also be accountable to apply and develop the following competencies.
Fostering Relationships: Build trust, mutual respect, and understanding through regular and genuine interactions while promoting a positive and inclusive environment.
Analytical Thinking: Recognize and value diverse perspectives and experiences in data analysis to foster a more comprehensive and equitable approach to problem-solving.
Creativity and Innovation: Leverage creativity and imagination to generate new insights and solutions while embracing diverse ideas and approaches that foster innovation.
Facilitating Change: Work with others to explore innovative approaches to problem-solving while promoting inclusivity, equity, accessibility, and belonging in the change process.
Team Leadership: Communicate vision and engage others or the team to solve problems while valuing diverse perspectives and fostering inclusivity.
EEO Statement
We are an equal opportunity employer and do not discriminate based on race, color, religion, sex, national origin, age, disability, veteran status, or any other protected characteristic outlined by federal, state, or local laws. We are committed to providing an inclusive and accessible hiring process for all candidates.
Accessibility Statement
The National Audubon Society endeavors to keep our careers site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact [email protected]. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.