Cole Haan Logo

Cole Haan

Senior Manager, Cybersecurity Operations & Risk Management (Remote)

Reposted 6 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Greenland, NH
155K-185K Annually
Senior level
In-Office or Remote
Hiring Remotely in Greenland, NH
155K-185K Annually
Senior level
Lead and improve cybersecurity operations, incident response, vulnerability management, and technical risk reduction. Coordinate cross-functional remediation, manage security technologies and vendors, develop metrics and playbooks, and communicate risks to stakeholders and leadership.
The summary above was generated by AI
Job Summary & Responsibilities

Reporting to the Senior Director, Cybersecurity & Compliance, the Senior Manager, Cybersecurity Operations & Risk Management is responsible for the operational oversight and continuous improvement of cybersecurity operations, incident response, vulnerability management, and technical risk reduction activities. This is a senior manager-level individual contributor role that leads initiatives through influence, coordination, and cross-functional partnership rather than direct people management.

 

The role partners with IT teams, business stakeholders, vendors, and managed service providers to strengthen security controls, reduce risk, and drive timely remediation of security issues. As the operational lead for key cybersecurity functions, this position helps ensure threats, vulnerabilities, and control weaknesses are effectively identified, prioritized, and addressed.

 

The ideal candidate combines strong technical expertise, operational leadership, and communication skills with a demonstrated ability to drive measurable security improvements across a global environment

 

CORE ACCOUNTABILITIES:

 

Security Operations & Incident Response

  • Lead cybersecurity monitoring, investigations, and incident response activities
  • Serve as the operational lead and primary coordinator for cybersecurity incidents and investigations
  • Coordinate containment, recovery, stakeholder communications, and post-incident remediation activities
  • Develop and maintain incident response procedures, playbooks, and tabletop exercises
  • Partner with internal teams, vendors, and managed security service providers to investigate and resolve security events
  • Develop operational metrics and reporting related to threats, incidents, response effectiveness, and overall security posture
  • Develop and maintain operational dashboards and reporting that provide leadership visibility into critical vulnerabilities, remediation status, technology lifecycle risks, security incidents, and unresolved risk exposures

Vulnerability & Threat Management

  • Own vulnerability identification, risk-based prioritization, remediation tracking, exception management, reporting and stakeholder engagement processes. Establish remediation expectations, monitor adherence, remediation SLAs, and escalate aging risks to appropriate technology and business leaders
  • Maintain visibility into end-of-life (EOL) and end-of-support (EOS) technology risks. Partner with Infrastructure, Applications, and Architecture teams to ensure replacement, upgrade, or risk mitigation plans are established and tracked before expiration dates
  • Partner with technology teams to drive timely remediation of vulnerabilities and security weaknesses
  • Develop vulnerability metrics and reporting to measure remediation performance, risk reduction, and program effectiveness
  • Manage vulnerability exceptions and ensure risk acceptance decisions are documented and periodically reviewed
  • Assess emerging threats and organizational exposure to inform remediation priorities
  • Partner with Security Architecture to align remediation efforts with security standards and long-term risk reduction objectives

Security Technology & Operations Improvement

  • Serve as the operational owner for cybersecurity technologies and services, ensuring they effectively support threat detection, incident response, vulnerability management, and risk reduction objectives
  • Continuously improve security monitoring, detection, response, and reporting capabilities
  • Administer and continuously improve endpoint privilege management (EPM) controls to support least-privilege access, application control, and endpoint risk reduction
  • Design and optimize operational workflows, dashboards, alerts, and automation opportunities
  • Partner with Security Architecture and Infrastructure teams to implement and operationalize new security controls and technologies
  • Support onboarding, integration, and optimization of security technologies across the enterprise
  • Manage cybersecurity vendor and service provider relationships, ensuring effective service delivery, operational performance, issue resolution, and alignment with security objectives

 

Security Risk & Control Management

  • Conduct technical security assessments to identify cybersecurity risks, control weaknesses, and remediation opportunities across infrastructure, cloud, applications, and security technologies
  • Partner with Infrastructure, Cloud, Applications, and Security Architecture teams to develop remediation plans
  • Validate implementation and effectiveness of security controls
  • Provide technical expertise and evidence in support of cybersecurity audits, assessments, and compliance activities
  • Maintain remediation tracking, cybersecurity risk registers, technology lifecycle risk inventories, and operational security improvement plans. Drive regular review of outstanding risks with accountable technology leaders and facilitate escalation of overdue remediation activities
  • Assist with third-party security assessments and technical due diligence reviews

Leadership & Collaboration

  • Serve as a trusted cybersecurity subject matter expert across operational security initiatives.
  • Build strong relationships with technology teams, business stakeholders, vendors, and service providers
  • Drive accountability for remediation activities and security commitments
  • Foster a culture of operational excellence, continuous improvement, and proactive risk management
  • Communicate cybersecurity risks and recommendations to both technical and non-technical audiences
  • Establish and lead recurring cybersecurity operational review meetings focused on vulnerability remediation, technology lifecycle risks, exception management, and risk reduction progress across the enterprise
Preferred Qualifications

Education

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
  • Advanced degree preferred

Experience

  • 7+ years of cybersecurity experience, with demonstrated success in security operations, incident response, vulnerability management, and technical risk reduction initiatives
  • 3-5 years leading security operations, vulnerability management, or incident response functions.
  • Experience managing security incidents and coordinating cross-functional technical response activities
  • Experience working with SIEM, EDR/XDR, vulnerability management, and cloud security platforms
  • Experience prioritizing remediation efforts using business risk, exploitability, and threat intelligence
  • Experience presenting cybersecurity risks, trends, and operational metrics to leadership
  • Experience working with cybersecurity vendors, MSSPs, and technology partners

 

Preferred Areas of Expertise

 

  • Security Operations & Monitoring
  • Incident Response
  • Vulnerability Management
  • Threat Intelligence
  • SIEM & Security Analytics
  • EDR/XDR Platforms
  • Identity & Access Management
  • Privileged Access Management
  • Microsoft 365 Security
  • Cloud Security
  • Security Automation

 

Preferred Certifications

 

  • CISSP
  • CISM
  • GCIH
  • Security+
  • Microsoft Security Certifications

Base Salary/Hourly Range: From $155,000 to $185,000 annually*

Bonus Eligibility: Yes, eligible for annual target bonus based on company and individual performance

Benefits Offered: Health Insurance, Dental Insurance, Vision Care, Health Savings Account with Employer Contribution, Flexible Spending Accounts, 401(k) Retirement Plan with Employer Matching Contributions, Short-Term Disability Insurance, Life Insurance, Vacation Time, Sick Time, Paid Parental Leave, Adoption Assistance Program, Charitable Matching Gifts Program, Holidays and Cole Haan Discounts

Paid Time Off: Paid vacation days starting at 120 hours, 11 paid company and personal holidays, 3 volunteer days

Sick Leave: Eligible non-exempt employees earn one hour of sick time for every 30 hours worked. Eligible exempt full-time employees earn 2.67 hours of sick time each bi-weekly pay period

 

*Rate of pay dependent upon candidates’ relevant skills, experience, and location

Similar Jobs

23 Minutes Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
150K-190K Annually
Senior level
150K-190K Annually
Senior level
Marketing Tech • Real Estate • Software • PropTech • SEO
Build and scale the analytics foundation: own dbt projects and Snowflake warehouse, create trusted datasets and semantic layers for AI, build ELT pipelines from APIs, implement testing/observability and CI/CD, design reconciliation models, enable stakeholder self-service, and partner cross-functionally to drive data-driven decisions across GTM, Product, Finance, People, and Operations.
Top Skills: BigQueryCi/CdDbtDbt Semantic LayerGitMixpanelPosthogPythonRedshiftSalesforceSnowflakeSnowflake CortexSQL
42 Minutes Ago
Remote
USA
Senior level
Senior level
Aerospace • Hardware • Software • Virtual Reality • Defense
Lead C2-focused business development for military training markets: build and manage pipeline, shape requirements, capture funded programs, establish senior military relationships, and align cross-functional teams to transition AR/LVC training technologies into scalable DoD programs.
Top Skills: ArAtarsDistributed Mission TrainingIsrLvcModeling And SimulationXr
53 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
204K-290K Annually
Senior level
204K-290K Annually
Senior level
Big Data • Fintech • Mobile • Payments • Financial Services
Drive technical strategy and roadmap for Affirm's Online Storage platform. Design and build multi-region, highly available datastore solutions and control planes for hundreds of databases. Automate schema migrations, disaster recovery, sharding, and performance tuning. Collaborate with product, SRE, and infrastructure teams, own operations and on-call readiness, and mentor engineers while setting code and design standards.
Top Skills: AWSDistributed SqlDynamoDBKotlinKubernetesMySQLPgbouncerPostgresProxysqlPythonRds ProxyRedisSparkTidbVitess

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account