Cyber Security and Risk Manager

Red Oak Technologies

South Bend (IN)

On-site

USD 110,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Red Oak Technologies seeks a hands‑on Cyber Security & Risk Manager to lead the organization’s cybersecurity program and risk management efforts in South Bend, Indiana. You will drive strategic security initiatives, manage daily security operations, and champion a culture of security across the enterprise.

Responsibilities include incident response, vulnerability management, policy governance, and third‑party risk assessments, with collaboration across departments to mature CSF‑aligned security

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or a related field.
  • 5+ years of progressive cybersecurity experience, with demonstrated ability to independently manage cybersecurity initiatives, risk management activities, and security operations.

Responsibilities

  • Monitor security operations, alerts, logs, and events; lead incident response.
  • Develop, implement, and improve the organization’s cybersecurity program and risk management practices.
  • Coordinate vulnerability management and remediation with stakeholders within defined SLAs.
  • Lead third‑party risk management and vendor assessments; ensure ongoing compliance.
  • Provide guidance to leadership and drive strategic security initiatives using CSF.

Skills

Cybersecurity
Incident response
Risk management
Security governance
Communication
Leadership

Education

Bachelor's degree in Information Security or related field

Tools

SIEM
EDR
Vulnerability scanners
Cloud security tools

Job description

Since 1995, Red Oak Technologies has been a trusted partner in the tech industry, delivering innovative talent solutions that drive progress. We specialize in quickly acquiring and efficiently matching top-tier professional talent with clients in immediate need of highly skilled contract, permanent or project management based resources.

Title: Cyber Security & Risk Manager

Location: South Bend (Elkhart), Indiana

The Cybersecurity & Risk Manager is a hands‑on leader responsible for developing, implementing, and continuously improving the organization’s cybersecurity and risk management program. This role serves as the primary cybersecurity subject matter expert, driving strategic security initiatives while actively managing daily security operations, incident response, vulnerability management, compliance activities, vendor risk assessments, and security awareness programs.

The Cybersecurity & Risk Manager partners across the organization to identify and mitigate risk, align security practices with business objectives, and mature the cybersecurity program utilizing the NIST Cybersecurity Framework (CSF) and other applicable industry standards. As the organization’s security leader, this individual provides guidance to leadership, supports the protection of critical business and network infrastructure, and champions a culture of security throughout the enterprise.

Responsibilities
Security Operations & Monitoring
  • Monitor security alerts, logs, and events daily; investigate and respond to threats and anomalies in real time.
  • Track and refine cybersecurity KPIs to support trend analysis, improvements, and leadership reporting aligned with regulatory goals.
  • Lead all phases of incident response, maintain and improve the Incident Response Playbook, and ensure accurate documentation and preventive actions through structured tracking and analysis.
Policy Management
  • Draft, maintain, and enforce security policies; ensure accessibility and cross‑department compliance with corrective actions where needed.
Vulnerability Management
  • Analyze third‑party scan reports, maintain a vulnerability inventory, and coordinate remediation efforts with stakeholders within defined SLAs.
User Awareness & Training
  • Deliver and track security awareness programs and phishing simulations; adjust content based on performance and emerging threats.
  • Manage a repeat offender remediation program for users who repeatedly fail phishing simulations, including targeted training, awareness reinforcement, performance tracking, and coordination with management when necessary.
Information Security Risk Register
  • Maintain and update the organization’s Information Security Risk Register, ensuring timely tracking, ownership, and mitigation of identified risks.
  • Coordinate annual enterprise cybersecurity risk and NIST maturity assessments with third‑party security partners, document findings, evaluate business impact, and track remediation activities through resolution.
  • Develop and monitor risk treatment plans, ensuring identified risks are appropriately mitigated, transferred, accepted, or avoided based on organizational risk tolerance.
Project Management
  • Drive security initiatives, tool deployments, and improvements by tracking milestones, coordinating vendors, and reporting status to leadership.
Tabletop Exercises & Readiness Testing
  • Coordinate tabletop exercises with third‑party facilitators; document results and follow‑up actions to enhance preparedness.
Business Continuity & Disaster Recovery
  • Collaborate with external providers to maintain, test, and update BCP/DR plans; support internal drills and elevate identified risks.
Third‑Party Risk Management (TPRM)
  • Manage vendor risk assessments, track remediation of findings, and ensure due diligence during onboarding and renewals.
Security Strategy & Governance
  • Develop and maintain the organization’s cybersecurity strategy, roadmap, security initiatives, and governance standards aligned with business objectives and organizational risk.
  • Provide regular cybersecurity risk, compliance, and program maturity updates and recommendations to executive leadership.
  • Evaluate emerging threats, technologies, and regulatory requirements, recommending and prioritizing investments and remediation efforts accordingly.
  • Serve as the organization’s primary cybersecurity advisor, providing guidance on business, technology, infrastructure, cloud, and third‑party solution decisions.
Qualifications
Education & Experience
  • Bachelor’s degree in Information Security, Computer Science, or a related field.
  • 5+ years of progressive cybersecurity experience, with demonstrated ability to independently manage cybersecurity initiatives, risk management activities, and security operations.
Technical Skills
  • Certifications such as CISSP, CISM, or Security+ are highly desirable.
  • Strong technical skills in SIEM, EDR, vulnerability scanning, and cloud security tools.
  • Strong understanding and practical application of the NIST Cybersecurity Framework (CSF), including framework assessments, gap analysis, control implementation, and cybersecurity maturity planning.
  • Experience developing security metrics, risk registers, policies, standards, and executive‑level reporting.
Analytical & Soft Skills
  • Excellent written and verbal communication with a problem‑solving mindset.
  • Experience with agile methodologies and a collaborative work approach.

Red Oak Technologies is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity & Risk Manager
Senior Cybersecurity & Risk Manager

Red Oak Technologies • South Bend (IN)

On-site
USD 110,000 - 160,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Senior Cyber Risk Manager
Senior Cyber Risk Manager

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Senior IT Security Manager I
Senior IT Security Manager I

GoFormz • San Diego (CA)

On-site
USD 150,000 - 190,000
Senior Cyber Risk Management Engineer
Senior Cyber Risk Management Engineer

White Cap Supply Holdings, LLC. • United States

Hybrid
USD 110,000 - 170,000
Cyber Risk Consultant
Cyber Risk Consultant

NTT DATA, Inc. • Charlotte (NC), Northern (KY)

Hybrid
USD 140,000 - 180,000
Senior Cyber Risk Management Engineer
Senior Cyber Risk Management Engineer

White Cap Supply Holdings, LLC. • Northern (KY)

Hybrid
USD 90,000 - 130,000
Chief Information Security Officer
Chief Information Security Officer

Jobtailor • Kentucky

On-site
USD 180,000 - 240,000
CRO - Information Security & Risk Oversight Lead
CRO - Information Security & Risk Oversight Lead

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000