Since 1995, Red Oak Technologies has been a trusted partner in the tech industry, delivering innovative talent solutions that drive progress. We specialize in quickly acquiring and efficiently matching top-tier professional talent with clients in immediate need of highly skilled contract, permanent or project management based resources.
Title: Cyber Security & Risk Manager
Location: South Bend (Elkhart), Indiana
The Cybersecurity & Risk Manager is a hands‑on leader responsible for developing, implementing, and continuously improving the organization’s cybersecurity and risk management program. This role serves as the primary cybersecurity subject matter expert, driving strategic security initiatives while actively managing daily security operations, incident response, vulnerability management, compliance activities, vendor risk assessments, and security awareness programs.
The Cybersecurity & Risk Manager partners across the organization to identify and mitigate risk, align security practices with business objectives, and mature the cybersecurity program utilizing the NIST Cybersecurity Framework (CSF) and other applicable industry standards. As the organization’s security leader, this individual provides guidance to leadership, supports the protection of critical business and network infrastructure, and champions a culture of security throughout the enterprise.
Responsibilities
Security Operations & Monitoring
- Monitor security alerts, logs, and events daily; investigate and respond to threats and anomalies in real time.
- Track and refine cybersecurity KPIs to support trend analysis, improvements, and leadership reporting aligned with regulatory goals.
- Lead all phases of incident response, maintain and improve the Incident Response Playbook, and ensure accurate documentation and preventive actions through structured tracking and analysis.
Policy Management
- Draft, maintain, and enforce security policies; ensure accessibility and cross‑department compliance with corrective actions where needed.
Vulnerability Management
- Analyze third‑party scan reports, maintain a vulnerability inventory, and coordinate remediation efforts with stakeholders within defined SLAs.
User Awareness & Training
- Deliver and track security awareness programs and phishing simulations; adjust content based on performance and emerging threats.
- Manage a repeat offender remediation program for users who repeatedly fail phishing simulations, including targeted training, awareness reinforcement, performance tracking, and coordination with management when necessary.
Information Security Risk Register
- Maintain and update the organization’s Information Security Risk Register, ensuring timely tracking, ownership, and mitigation of identified risks.
- Coordinate annual enterprise cybersecurity risk and NIST maturity assessments with third‑party security partners, document findings, evaluate business impact, and track remediation activities through resolution.
- Develop and monitor risk treatment plans, ensuring identified risks are appropriately mitigated, transferred, accepted, or avoided based on organizational risk tolerance.
Project Management
- Drive security initiatives, tool deployments, and improvements by tracking milestones, coordinating vendors, and reporting status to leadership.
Tabletop Exercises & Readiness Testing
- Coordinate tabletop exercises with third‑party facilitators; document results and follow‑up actions to enhance preparedness.
Business Continuity & Disaster Recovery
- Collaborate with external providers to maintain, test, and update BCP/DR plans; support internal drills and elevate identified risks.
Third‑Party Risk Management (TPRM)
- Manage vendor risk assessments, track remediation of findings, and ensure due diligence during onboarding and renewals.
Security Strategy & Governance
- Develop and maintain the organization’s cybersecurity strategy, roadmap, security initiatives, and governance standards aligned with business objectives and organizational risk.
- Provide regular cybersecurity risk, compliance, and program maturity updates and recommendations to executive leadership.
- Evaluate emerging threats, technologies, and regulatory requirements, recommending and prioritizing investments and remediation efforts accordingly.
- Serve as the organization’s primary cybersecurity advisor, providing guidance on business, technology, infrastructure, cloud, and third‑party solution decisions.
Qualifications
Education & Experience
- Bachelor’s degree in Information Security, Computer Science, or a related field.
- 5+ years of progressive cybersecurity experience, with demonstrated ability to independently manage cybersecurity initiatives, risk management activities, and security operations.
Technical Skills
- Certifications such as CISSP, CISM, or Security+ are highly desirable.
- Strong technical skills in SIEM, EDR, vulnerability scanning, and cloud security tools.
- Strong understanding and practical application of the NIST Cybersecurity Framework (CSF), including framework assessments, gap analysis, control implementation, and cybersecurity maturity planning.
- Experience developing security metrics, risk registers, policies, standards, and executive‑level reporting.
Analytical & Soft Skills
- Excellent written and verbal communication with a problem‑solving mindset.
- Experience with agile methodologies and a collaborative work approach.
Red Oak Technologies is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life.