- Salary
- $150k – $160k/yr
- Location
- Spokane, WA
- Department
- IT
- Seniority
- Manager
- Education
- Master
- Source
- Paylocity
Description
Description
URM Stores, Inc. is looking for a talented Cybersecurity Manager to join our ever-growing team here at our Corporate office in Spokane, WA. The Cybersecurity Manager is a hands-on technical leader responsible for the day-to-day execution, operation, and continued maturation of URM’s cybersecurity program. This role leads and develops the Security Engineering team while remaining actively engaged in security engineering, incident response, vulnerability management, security operations, identity and access security, and complex technical investigations. The Cybersecurity Manager translates cybersecurity strategy, standards, and risk priorities into effective technical controls, operational processes, and measurable outcomes, while providing operational leadership for governance and compliance activities, including NIST Cybersecurity Framework maturity, PCI DSS, security assessments, audit support, control validation, and remediation.
As our Cybersecurity Manager, you’ll partner closely with the Infrastructure & Cybersecurity Architect, infrastructure engineering teams, Applications, Data/Integration/AI, Member Services, business stakeholders, and external security partners to ensure cybersecurity controls are practical, effective, supportable, and aligned with URM’s business and technology objectives. The ideal candidate combines strong technical cybersecurity expertise with effective people leadership, collaboration, and operational judgment, with the ability to balance hands-on technical work with the leadership and continuous improvement responsibilities of a growing cybersecurity program.
Key Areas of Responsibility:
Cybersecurity Operations & Engineering
- Lead cybersecurity operations and engineering by overseeing the day-to-day operation, maintenance, and continuous improvement of URM’s cybersecurity technologies, controls, processes, and engineering activities.
- Lead and develop the Security Engineering team by establishing clear ownership, priorities, technical standards, and measurable expectations while maintaining hands-on involvement in security engineering, troubleshooting, implementation, configuration, and complex technical investigations.
- Provide technical leadership across the cybersecurity environment, including endpoint and application security, network security, vulnerability management, identity and privileged access, email security, logging, monitoring, and related technologies. Ensure security solutions are properly configured, integrated, monitored, maintained, and continuously improved.
- Integrate cybersecurity into enterprise technology and architecture by partnering with the Infrastructure & Cybersecurity Architect and Infrastructure Engineering teams across network, systems, cloud, identity, and enterprise architecture. Evaluate emerging cybersecurity technologies and provide recommendations based on risk reduction, technical fit, integration, and long-term supportability.
- Establish and maintain operational standards and documentation including cybersecurity standards, procedures, architecture diagrams, technical documentation, and operational runbooks to promote consistent, effective, and sustainable security operations.
Security Operations & Incident Response
- Lead security operations and incident response by overseeing URM’s internal security operations and coordinating with managed security and detection-and-response partners. Serve as the primary internal leader for Tier 2/3 cybersecurity escalations, including investigation, containment, remediation, and recovery.
- Drive effective threat detection and response by ensuring meaningful security telemetry is collected and leveraged across endpoint, identity, network, cloud, email, infrastructure, and critical systems. Provide technical leadership during significant cybersecurity incidents and coordinate response activities across IT teams, external partners, and business stakeholders.
- Strengthen incident preparedness and response capabilities by maintaining and continuously improving incident-response plans, playbooks, escalation procedures, and technical response capabilities. Lead cybersecurity tabletop exercises and ensure identified actions and improvements are tracked through completion.
- Drive continuous improvement and operational accountability through post-incident reviews, documented lessons learned, and measurable metrics for detection, investigation, response, and security-control effectiveness. Ensure findings translate into meaningful improvements to security controls, processes, architecture, and training.
Vulnerability & Exposure Management
- Lead URM’s vulnerability and exposure management program by establishing consistent, risk-based processes for identifying prioritizing, remediating, and validating vulnerabilities across technology environments. Evaluate risk based on technical severity, exploitability, exposure, business criticality, sensitive-data considerations, and compensating controls.
- Coordinate and measure vulnerability remediation with infrastructure, application, endpoint, and system owners. Monitor vulnerability aging, remediation SLAs, exceptions, compensating controls, and accepted risk, and provide leadership with meaningful metrics focused on measurable risk reduction.
- Oversee security testing and validation by coordinating penetration testing, vulnerability assessments, remediation activities, and validation of findings to ensure identified risks are appropriately addressed.
Governance, Risk & Compliance
- Lead cybersecurity governance and control-maturity initiatives established by the Sr. Director, Infrastructure & Cybersecurity, including the continued adoption and maturation of the NIST Cybersecurity Framework and other applicable cybersecurity requirements.
- Support cybersecurity compliance, audits, and assessments including PCI DSS, regulatory and contractual requirements, and third-party security assessments. Maintain accurate and repeatable policies, standards, procedures, control documentation, evidence, and technical validation to support assessments and demonstrate control effectiveness.
- Identify, track, and remediate cybersecurity risks and control gaps by partnering with technical and business owners to develop practical remediation plans. Monitor findings, remediation activities, exceptions, compensating controls, and risk acceptance, while evaluating third-party security controls and documentation as needed.
Required Qualifications:
- Education and experience: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field, or equivalent experience, with 7+ years of progressive cybersecurity, security engineering, infrastructure security, or related technical experience, including 2+ years of technical leadership or people-management experience.
- Technical expertise: Demonstrated hands-on experience implementing, operating, troubleshooting, and improving enterprise cybersecurity technologies and controls, with strong knowledge of network security, firewalls, segmentation, VPNs, endpoint security, identity and access management, MFA, privileged access, logging, monitoring, and cloud security.
- Security operations and risk management: Proven experience with cybersecurity incident investigation and response, vulnerability and exposure management, security assessments, control validation, and remediation.
- Governance and compliance: Working knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework, with experience supporting PCI DSS or other regulated and audited environments, including audits, assessments, evidence collection, and remediation activities.
- Leadership and collaboration: Ability to lead and develop a technical cybersecurity team while remaining hands-on with complex security engineering and investigations. Demonstrated ability to work effectively with infrastructure and technology teams, business stakeholders, managed security providers, vendors, auditors, and third-party assessors.
- Communication and problem-solving: Strong analytical, troubleshooting, documentation, planning, communication, and organizational skills, with the ability to prioritize cybersecurity initiatives based on risk and business impact and remain effective during high-impact security incidents.
Preferred Qualifications:
- Experience leading or supporting NIST CSF assessments, cybersecurity maturity programs, and PCI DSS technical controls.
- Experience with Microsoft Entra, Microsoft 365, Azure, hybrid/cloud environments, SIEM/XDR, endpoint protection, vulnerability management, application control, privileged access, email security, and network-security technologies.
- Experience with cybersecurity platforms such as Stellar Cyber, Qualys, ThreatLocker, BeyondTrust, Carbon Black, Microsoft Defender, Mimecast, Fortinet, or comparable technologies.
- Experience with Zero Trust, SASE/ZTNA, network segmentation, and modern identity architectures.
- Experience working in grocery, wholesale distribution, logistics, retail, or other high-availability operational environments.
- Relevant professional certifications such as CISSP, CISM, CRISC, GIAC, Security+, CySA+, or comparable credentials.
Core Competencies:
- Technical Leadership: Combines strong cybersecurity expertise with effective people leadership and a hands-on approach to complex technical challenges.
- Risk-Based Decision Making: Translates cybersecurity frameworks, compliance requirements, and technical risks into practical controls and prioritizes work based on business impact and measurable risk reduction.
- Operational Excellence: Demonstrates strong planning, execution, documentation, follow-through, and continuous improvement skills.
- Communication & Collaboration: Clearly communicates with technical teams, leadership, business stakeholders, auditors, vendors, managed service providers, and external assessors while effectively coordinating across teams and organizations.
A Legacy of Local Impact Since 1921
For over a century, URM Stores, Inc. has been the powerhouse behind independent grocers throughout the Inland Northwest. Our mission is simple: help local grocers thrive by handling everything from purchasing and warehousing to the timely delivery of top-quality merchandise.
What makes URM so unique? Our co-operative model means our Member-Owners aren’t just customers, they’re shareholders. We reinvest in their success by returning earnings to our Co-Op members as patronage dividends.
Today, URM employs more than 3,000 dedicated team members, including those at our subsidiaries Rosauers Supermarkets and Peirone Produce.
We work in a supportive team environment and in addition to our amazing culture, our employees enjoy many perks, and below are a few of the highlights of our complete compensation package:
- An employee’s pay position within the salary range will be based on several factors including, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, and business or organizational needs. Salary $150,000 - $160,000 DOE, plus so much more!
- Insurance Benefits – So that our non-union employees have more to take home from their paycheck, URM pays 100% of the Medical/Dental/Vision/RX Insurance premiums for the employee and over 93% for the employee’s dependents!
- 401k Retirement Plan with an amazing Company match up to 9% of your annual salary!
- Subsidized Life Insurance for employees and great rates for the employee’s family.
- Company paid Long-Term Disability insurance.
- Short-Term Disability and Cancer Insurance available.
- Life Flight Insurance at Special Rate.
- Great vacation plan!
- Six Paid Holidays and four Paid Personal Holidays.
- Paid Sick Days.
- Paid Volunteer Service Day! Get paid to volunteer at your favorite non-profit!
- Experience enjoyable Company sponsored activities through events like URM March Madness Brackets, Family Hockey Night with the Chiefs, Holiday Mingle & Jingle with great raffle giveaways, Summer Evening Wine & Music Event, and Winter Break Movie Night, which are just a glimpse of the fun we have to offer for employees and their families!
- Plus, enjoy a variety of Corporate discounts, from gym memberships, cell phone plans, to computer discounts!
- We also offer an Amazing Employee Discount Program at our Company-owned Grocery Stores!!!!
URM Stores, Inc. is proud to be an equal opportunity employer, committed to fostering an inclusive workplace. We provide equal employment opportunities to all individuals regardless of race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, disability, ancestry, veteran status, genetic information, or any other characteristic protected by federal or state law.
We are dedicated to maintaining a work environment free from discrimination in all aspects of employment, including recruitment, hiring, training, promotions, compensation, and workplace practices.