
Information Security Manager
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in Ohio, +1 more state.
• Take ownership and lead CAG's information-security roadmap and priorities across all brands and locations.
• Create and uphold security policies, standards, and governance frameworks.
• Manage the risk register, address control gaps, oversee vulnerability management cadence, coordinate penetration testing, and track remediation efforts.
• Lead the KnowBe4 security awareness initiative, including training, phishing simulations, remediation, and performance metrics.
• Oversee security vendors and tools, including the co-managed SOC with Paragus, EDR, and email security solutions.
• Present security posture, KPIs, incident summaries, and risk assessments to the VP of Technology and the Executive Leadership Team (ELT).
• Direct security due diligence and integration processes for acquisitions.
• Manage cyber insurance renewal attestations and respond to customer and contractual security questionnaires and audits.
• Take charge of or co-manage business continuity and disaster recovery planning, validate backup integrity, and conduct recovery testing.
• Provide security expertise for ERP consolidation and significant technology projects.
• Lead investigations into incidents, including containment, resolution, runbook development, and post-incident reviews.
• Monitor and triage alerts from Huntress EDR, tune detections, and address high-severity incidents.
• Administer Mimecast for email security, including quarantine management and policy enforcement.
• Manage MFA/Conditional Access, oversee privileged access, and address Defender/Entra posture along with account compromise responses.
• Handle phishing reports and triage them in Zoho Desk.
• Coordinate vulnerability scans, prioritize findings, and ensure closure of patching and remediation efforts.
• A minimum of 5 years in information security with hands-on operational and program/leadership responsibilities.
• Direct experience in incident response and EDR tools such as Huntress, Microsoft Defender, CrowdStrike, or SentinelOne.
• Experience with Microsoft 365 / Entra (Azure AD) security, including MFA/Conditional Access, privileged access, and Defender.
• Background in email security administration with Mimecast, Proofpoint, or similar platforms.
• Experience in vulnerability management and remediation processes.
• Demonstrated experience in leading or significantly contributing to a security awareness program like KnowBe4.
• Capability to establish policy/governance and report security posture to executive leadership.
• Excellent written and verbal communication skills; ability to convey risk to non-technical stakeholders.
• Authorization to work in the United States.
• A bachelor's degree in cybersecurity, information systems, computer science, or a related field, or equivalent experience.
• Security certifications such as CISSP, CISM, GIAC, or CompTIA Security+/CySA+ are advantageous but not mandatory.
• Experience managing a co-managed SOC / MSSP relationship is preferred.
• Experience in manufacturing or multi-site/multi-entity environments is preferred.
• Familiarity with Huntress, Mimecast, KnowBe4, Microsoft Defender/Entra, Zoho Desk, and Intune is preferred.
• Up to a 10% bonus.
• Permanent full-time employment opportunity.
• Occasional travel across CAG's U.S. locations.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.