The education essentials company.
Technical Security Manager
Location
United States
Posted
6 days ago
Salary
0
Seniority
Senior
Job Description
Technical Security Manager
Cambium Learning Group
• Maintain, mature, and take ownership of our program that ensures conformance to security standards. This includes but is not limited to conformance with ISO 27001, ISO 27018, ISO 42001, Privacy laws, ISO 9001, GovRAMP, FedRAMP, NIST 800, SOC, and CIS Top Controls. • Facilitate annual independent audits of our organization by third-party security and privacy experts. Create audit plan, co-ordinate with stakeholders, review reports and remediate audit findings. • Responsible for planning and managing multiple security improvement projects from requirements phase through deployment/implementation. • Managing document and record control processes and procedures, including maintaining accurate inventories and records of compliance/conformance artifacts • Responsible for our Security Awareness and related training programs. Maintains and improves processes, platforms and systems that support our training campaigns and content. Creates, monitors and reports on campaigns. • Supports business development by responding to requests for security and privacy information that is included in proposals for new business. • Performs security risk assessments of software acquisitions, technical services, business systems and new technologies. • Owns and administers a GRC tool to track security controls and current conformance status. Ensures that relevant security artifacts are recorded and updated. • Conducts enterprise risk assessment reviews and report out to senior management regarding security issues and metrics – both as an ongoing process and on an as-needed basis. • Assists in continual improvement by examining our current security posture and security practices, identifying risks or gaps, and recommending programs to address them. • Manages privacy risks including exposures created by cookies and APIs. Maintains Privacy policies and ensures compliance.
Job Requirements
- Bachelor’s Degree in Information Security, Cybersecurity, computer science, engineering, Information Systems or related technical field
- Minimum 5 years hands-on experience in the information security field
- Extensive and deep knowledge of security and privacy frameworks, standards, and industry best practices.
- Knowledge of Privacy laws and principles such as GDPR, COPPA, and FERPA
- Extensive and deep knowledge of tools and techniques used to protect against cybersecurity attacks and respond to incidents.
- Information Security Certifications such as CISSP, GIAC, ISACA, AWS Security. PMP certification a plus.
- Experience with GRC tools
- Exceptional verbal and written communication skills to effectively and accurately communicate with a variety of teams ranging from highly detailed discussions with technical and subject matter experts to executive-level communications required for senior leaders and decisionmakers.
- Demonstrated working experience with: Security and privacy standards such as ISO, GovRAMP, FedRAMP and/or other industry best practice frameworks.
- Writing, developing, and maintaining official security and privacy-relevant records and documentation
- Reducing organizational risk by conducting risk assessments, gap analysis, improvement plans and tracking associated corrective actions or POAMs to closure
- Developing and executing project management plans for technical projects.
Benefits
- Health insurance
- Paid time off
- Retirement plans
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Coach
LelandAccess coaching, courses, and content powered by 1,000+ career and admissions experts.
• Work with clients looking to break into or grow within cybersecurity roles • Teach core cyber security strategy, network security, and incident response skills • Help clients build strong risk assessment, security auditing, and vulnerability management practices • Support clients on the career side, offering resume review, LinkedIn review, and cover letter guidance • Provide behavioral and technical interview prep tailored to cybersecurity roles • Additional support includes networking strategy, salary negotiation, promotion strategy, broader skill building, and guidance for freelancing opportunities
• Advance the frontier of AI Reinforcement Learning development and delivery • Build the infrastructure and tooling that transforms real-world vulnerability research into large-scale reinforcement learning environments • Create training environments that teach AI systems how to hack and defend software • Work at the intersection of AI, security research, and systems engineering
• Administer, configure, deploy, and maintain Cisco FirePower Threat Defense (FTD) and SkyHigh Web Gateway appliances across the authorization boundary and enterprise-level environments • Implement advanced intrusion prevention systems (IPS) using CISCO FirePower to identify and block malicious traffic • Implement CISCO routers (CSRs) to do Policy Based Routing (PBR) on all network traffic from the Virtual Private Clouds (VPC) • Design and optimize Security Rule Sets (SRUs) and tailor policies to meet organizational and mission-critical security requirements • Perform threat analysis, event correlation, and deep packet inspection to mitigate emerging cyber threats • Configure and manage Cisco FireSight/FirePower Management Center (FMC) for centralized policy management, event monitoring, and system reporting • Integrate FirePower NGIPS with other security solutions such as SIEM or SOAR platforms to enable automated threat response capabilities • Conduct regular audits and vulnerability assessments within FirePower systems to identify gaps in coverage • Troubleshoot Cisco FirePower appliances for performance issues, ensuring high availability and resilience across the network • Collaborate with cross-functional IT and security teams to optimize firewall configurations and enforce Zero Trust principles • Create and maintain detailed documentation for system configurations, policies, procedures, and operational tasks • Provide technical expertise, guidance, and training to internal teams on Cisco FirePower operations and best practices
• Coordinate occupational safety activities, implementing preventive and corrective actions to minimize risks to employees' health and integrity, ensuring compliance with internal policies, regulatory standards and current legislation, with a focus on promoting a safe, healthy environment in accordance with legal and operational requirements. • Coordinate the Occupational Health and Safety (SESMT) teams at the industrial units, ensuring standardization of processes, execution of planned activities and alignment with corporate Occupational Health and Safety guidelines. • Work in partnership with company departments to identify, assess and control occupational risks, proposing actions that contribute to the prevention of accidents and occupational diseases. • Plan, coordinate and monitor safety programs, training and campaigns, promoting the strengthening of a prevention culture and safe behavior. • Coordinate initiatives aimed at reducing accidents and occupational diseases, overseeing the preparation and revision of legally required programs, risk analyses and other Occupational Health and Safety requirements. • Monitor performance indicators, analyze accidents, incidents and deviations, follow up on action plans and promote continuous improvement of safety processes. • Participate in corporate and operational projects and initiatives, working collaboratively with other departments, supporting audits and inspections, and contributing to digital transformation initiatives, process automation and the use of data to improve Occupational Health and Safety management.




