- Location
- Elk River, MN, US
- Type
- Full-time
- Department
- IT
- Seniority
- Manager
- Closing date
- Today
- Source
- iCIMS
Description
Overview
Position summary
The Cybersecurity Manager leads and executes the enterprise cybersecurity program across a growing manufacturing organization. Reporting to the CIO, this role is a hands-on player-coach responsible for both executing and leading cybersecurity operations, risk management, incident response, security architecture, and team leadership.
The Cybersecurity Manager will own and drive execution of the cybersecurity maturity roadmap, primarily aligned to the NIST Cybersecurity Framework, while also ensuring alignment with CMMC, ITAR, customer security requirements, and cyber insurance expectations.
This role will expand cybersecurity practices from traditional IT environments into Operational Technology (OT) and manufacturing environments while remaining actively involved in day-to-day cybersecurity activities.
Responsibilities
Essential Job Functions
Cybersecurity Program, Governance & Risk
- Own and execute the enterprise cybersecurity maturity roadmap, including prioritizing and leading security improvement initiatives from planning through implementation.
- Maintain the cybersecurity risk register, remediation plans, risk acceptance, and leadership reporting.
- Develop and maintain cybersecurity policies, standards, and procedures.
- Ensure alignment with NIST, CMMC, ITAR, customer security, cyber insurance, and other applicable requirements.
- Develop and report cybersecurity KPIs and KRIs.
- Partner with business and technology leaders to identify and reduce cybersecurity risk.
Security Operations & Incident Response
- Provide hands-on technical leadership and directly participate in security monitoring, vulnerability management, endpoint security, identity and access management, email security, logging, and network security.
- Serve as the primary cybersecurity incident lead, coordinating investigation, containment, remediation, recovery, post-incident review, and internal and external response resources.
- Participate in after-hours response and escalation when significant incidents occur.
- Continuously evaluate security controls, tools, vulnerabilities, and emerging threats.
Security Architecture & OT Cybersecurity
- Review new systems, applications, infrastructure, cloud services, integrations, and technology projects and establish practical cybersecurity requirements.
- Partner with infrastructure, applications, and business teams to incorporate security into solution design.
- Develop and mature cybersecurity practices for manufacturing and Operational Technology environments, including risk assessment, segmentation, access, monitoring, and incident response.
Third-Party & Partner Management
- Serve as the primary relationship manager for MDR/MSSP providers, security integrators, testing firms, and other cybersecurity partners.
- Manage vendor performance, escalations, service effectiveness, and improvement opportunities.
- Evaluate cybersecurity products and services and recommend cost-effective solutions.
Team Leadership & Cybersecurity Culture
- Lead, coach, and develop cybersecurity team members, including the IT Security Operations Engineer and Cybersecurity Risk Analyst.
- Establish priorities across security operations, risk, governance, resilience, and awareness.
- Remain actively involved in technical cybersecurity execution while building the capabilities of the cybersecurity team.
- Communicate cybersecurity risks and priorities effectively to technical and non-technical audiences.
Qualifications
Minimum Requirements, Education & Experience (incl. KSA’s and certifications)
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education and relevant experience.
- 5+ years of cybersecurity, information security, security engineering, or security operations experience.
- 2+ years of leadership, team lead, project leadership, or people management experience.
- Demonstrated experience leading cybersecurity improvement projects from planning through implementation.
- Strong hands-on experience with cybersecurity technologies and practices, including endpoint security, vulnerability management, incident response, identity and access management, network security, logging, and security monitoring.
- Experience leading cybersecurity incident response.
- Experience identifying, assessing, and remediating cybersecurity risk.
- Working knowledge of the NIST Cybersecurity Framework.
- Strong communication, problem-solving, organization, and prioritization skills.
- Ability to respond to significant cybersecurity incidents outside normal business hours.
- Ability to travel periodically between company locations.
Desirable Criteria & Qualifications
- CISSP, CISM, or similar advanced cybersecurity certification preferred.
- Security+, GIAC, or other relevant technical certifications valued.
- Experience in manufacturing, medical device, regulated, or multi-site environments.
- Experience with OT or manufacturing cybersecurity.
- Experience with CMMC, ITAR, customer security requirements, or cyber insurance.
- Experience managing MDR/MSSP providers and other cybersecurity partners.
- Experience with business continuity, disaster recovery, tabletop exercises, and recovery testing.
- Experience reviewing new technology and architecture from a cybersecurity perspective.
Pay Range
USD $112,000.00 - USD $168,000.00 /Yr.Pay Range Details
This pay range reflects the base hourly rate or annual salary for positions within this job grade, based on our market-based pay structures. Actual compensation will depend on factors such as skills, relevant experience, education, internal equity, business needs, and local market conditions. While the full hiring range is shared for transparency, offers are rarely made at the minimum or maximum of the range.
Company Benefits
All Employees:
Our 401k retirement savings plan with a company match contribution; onsite health clinics, discretionary holiday bonus program (based on years of service), Cretex University, 24/7 employee assistance program with access to five confidential visits with a licensed counselor at no cost, wellness program with incentives, an employee death benefit, and employee sick and safe leave are available to all Cretex employees.
20+hours:
Cretex’s medical benefit package includes: comprehensive medical insurance with access to virtual providers; dental insurance (Little Partners Dental benefit covers services 100 percent for children 12 and younger when seen by a Health Partners in network provider); vision insurance; a pre-tax health savings account, healthcare and dependent care pre-tax reimbursement accounts; paid holidays, paid time off; and our discretionary profit sharing program are available to employees working 20+ hours/week.
30+ hours:
Parental Leave, accident and critical illness benefits, optional employee, spouse, and child life; short and long term disability; company provided life insurance; and tuition assistance programs are available to employees working 30+ hours per week.
(Some benefits are subject to eligibility criteria.)
Applicants will receive consideration for employment regardless of their race, color, creed, religion, national origin, sex, sexual orientation, gender identity, disability, age, veteran status, marital status, family status, status with regard to public assistance, or any other protected status as required by law.
Our company uses E-Verify to confirm the employment and eligibility of all newly hired employees. To learn more about E-Verify, including your rights and responsibilities, please visit www.dhs.gov/E-Verify.