Cybersecurity Program Manager

Alaska Power & Telephone Company

Ketchikan (AK)

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

ESOP employee ownership
Professional certification support
Competitive compensation
Equal opportunity employer

Job summary

Alaska Power & Telephone Company (AP&T) is seeking a skilled Cybersecurity Program Manager to own and improve the cybersecurity program across distributed environments in Alaska and neighboring states. The role focuses on security operations, risk management, incident response readiness, and documentation while coordinating with IT, OT, and field operations.

The ideal candidate will have broad cybersecurity expertise, strong communication, and the ability to drive remediation efforts in a

Qualifications

  • Minimum of five (5) years of hands-on experience in IT, systems administration, cybersecurity, or related technical disciplines.
  • Minimum of three (3) years of cybersecurity-related experience.
  • Experience developing policies, procedures, incident reports, risk assessments, and technical documentation.
  • Ability to communicate effectively with both technical and non-technical stakeholders.

Responsibilities

  • Maintain, administer, and continuously improve AP&T's cybersecurity program.
  • Monitor security events across the technology environment and coordinate risk mitigation.
  • Support vulnerability scanning, patch management, and system hardening efforts.
  • Oversee identity and access management, MFA, and least-privilege controls.
  • Coordinate incident response activities and tabletop exercises; support recovery planning.
  • Collaborate with IT, OT, and field operations to secure critical infrastructure.

Skills

Security operations
Network security
System administration
IAM
Vulnerability management
Incident response
EDR
MFA
Backup & recovery
Policy development

Education

Bachelor's degree in Cybersecurity / IT

Tools

SIEM
Firewalls
EDR tools
Azure AD
VPN

Job description

Alaska Power & Telephone (AP&T) is an employee-owned utility dedicated to serving more than 40 Alaskan communities with reliable electric, broadband, and telephone services. As a provider of critical infrastructure, cybersecurity is essential to maintaining the trust, reliability, and safety our customers depend on every day. This position will be seated in Alaska, Washington, Oregon, Idaho, or Texas. Must be located in one of these states or willing to relocate for this position. We are seeking a skilled and motivated Cybersecurity Program Manager to execute, maintain, and continuously improve AP&T's cybersecurity program. This role serves as the day-to-day owner of security operations, cyber risk management, incident response readiness, security awareness initiatives, vendor security coordination, and cybersecurity documentation. The successful candidate will work across IT, telecommunications, and operational environments to strengthen AP&T's security posture while supporting business operations in a dynamic and geographically distributed setting.

Position Summary

The Cybersecurity Analyst is responsible for implementing and managing cybersecurity controls, monitoring security events, coordinating risk mitigation efforts, and ensuring compliance with cybersecurity policies and industry best practices. This position plays a key role in protecting AP&T's information systems, telecommunications infrastructure, operational technology (OT), and critical business services.

The ideal candidate combines strong technical cybersecurity knowledge with excellent communication, documentation, and problem-solving skills. Applicant must reside in Alaska, Washington, or Idaho for work.

Essential Duties And Responsibilities
Security Program Management
  • Maintain, administer, and continuously improve AP&T's cybersecurity program.
  • Develop, update, and maintain cybersecurity policies, procedures, standards, and supporting documentation.
  • Track cybersecurity initiatives, remediation efforts, and program objectives.
  • Support alignment with recognized frameworks and best practices, including NIST Cybersecurity Framework (CSF), CIS Controls, and CISA Cybersecurity Performance Goals.
  • Prepare reports, metrics, and risk summaries for leadership.
Security Operations
  • Monitor security alerts, events, and system activity across the organization's technology environment.
  • Investigate and respond to cybersecurity incidents and suspicious activity.
  • Maintain secure configurations and cybersecurity tools.
  • Coordinate with internal teams and external vendors to address identified security concerns.
  • Support endpoint, network, email, and cloud security initiatives.
Vulnerability and Patch Management
  • Conduct and coordinate vulnerability scanning activities.
  • Analyze findings and prioritize remediation based on business risk.
  • Track corrective actions through completion.
  • Monitor patch management and system hardening efforts.
  • Participate in external security assessments, penetration testing, and remediation planning.
Identity and Access Security
  • Administer and oversee access control processes.
  • Support privileged access management and least-privilege security practices.
  • Manage multifactor authentication (MFA) and identity security controls.
  • Conduct user access reviews and ensure appropriate account management practices.
Incident Response and Recovery
  • Maintain incident response plans, procedures, and supporting documentation.
  • Coordinate cybersecurity event response activities.
  • Facilitate incident response exercises and tabletop simulations.
  • Support disaster recovery, business continuity, and backup validation activities.
  • Assist in post-incident reviews and corrective action planning.
Risk, Compliance, and Vendor Security
  • Identify, assess, document, and track cybersecurity risks.
  • Support audits, compliance reviews, and cybersecurity assessments.
  • Review third-party and vendor cybersecurity practices.
  • Assist with cyber insurance submissions, questionnaires, and related requirements.
  • Maintain evidence and documentation supporting compliance activities.
IT, OT, and Critical Infrastructure Security
  • Support cybersecurity practices across information technology, telecommunications, and operational technology environments.
  • Assist in securing distributed systems supporting utility and broadband operations.
  • Coordinate security efforts involving critical infrastructure and field operations technologies.
  • Support cybersecurity requirements for remote and rural operational environments.
Security Awareness and Culture
  • Lead employee cybersecurity awareness and education efforts.
  • Coordinate phishing awareness campaigns and training activities.
  • Promote cybersecurity best practices throughout the organization.
  • Foster a culture of shared responsibility for information security.
Required Education
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; or
  • Equivalent combination of education, training, certifications, and relevant professional experience.
Experience
Required Qualifications
  • Minimum of five (5) years of hands- on experience in information technology, systems administration, network administration, infrastructure management, cybersecurity, or related technical disciplines.
  • Minimum of three (3) years of cybersecurity-related experience.
  • Experience with:
  • Security operations
  • Network security
  • System administration
  • Endpoint protection and endpoint detection and response (EDR)
  • Identity and access management (IAM)
  • Vulnerability management
  • Backup and recovery solutions
  • Incident response and investigations
  • Experience developing policies, procedures, incident reports, risk assessments, and technical documentation.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Ability to manage sensitive and confidential information with discretion and sound judgment.
  • Proven ability to coordinate remediation efforts and drive issues to resolution.
Certifications

Current cybersecurity certification preferred, including but not limited to:

  • CompTIA Security+
  • CompTIA CySA+
  • ISC2 SSCP
  • ISC2 CISSP
  • ISACA CISM
  • GIAC GSEC
  • GIAC GCIH
  • GIAC GICSP
  • ISA/IEC 62443 Certification
  • Equivalent industry-recognized cybersecurity certification
Technical Knowledge

Working knowledge of:

  • NIST Cybersecurity Framework (NIST CSF)
  • CIS Critical Security Controls
  • CISA Cybersecurity Performance Goals (CPGs)
  • Security Operations Center (SOC) practices
  • Incident response lifecycle
  • Vulnerability management
  • Least privilege and access control
  • Multifactor authentication (MFA)
  • Endpoint security
  • Email security
  • Security logging and monitoring
  • Backup and disaster recovery best practices
Preferred Qualifications
  • Experience within a utility, telecommunications, broadband, energy, critical infrastructure, or highly regulated environment.
  • Experience supporting operational technology (OT), industrial control systems (ICS), SCADA environments, telecommunications networks, or field operations.
  • Experience with:
  • Microsoft Entra ID (Azure AD)
  • Microsoft Defender
  • Microsoft 365 Security
  • ESET
  • SIEM and log management platforms
  • Firewalls and VPN technologies
  • EDR/XDR solutions
  • Vulnerability scanning platforms
  • Backup and recovery systems
  • Network monitoring tools
  • Experience with vendor risk management and third-party security reviews.
  • Experience supporting audits, cybersecurity assessments, cyber insurance reviews, and regulatory compliance activities.
  • Experience developing security metrics, dashboards, reporting solutions, scripting, or automation tools.
Key Competencies
  • Information Security
  • Cybersecurity Operations
  • Risk Management
  • Incident Response
  • Vulnerability Management
  • Identity and Access Management (IAM)
  • Security Governance
  • Critical Infrastructure Protection
  • Analytical Thinking
  • Problem Solving
  • Technical Documentation
  • Communication Skills
  • Vendor Management
  • Project Coordination
  • Continuous Improvement
Physical Requirements

The physical demands described below are representative of those that must be met to successfully perform the essential functions of this position. Reasonable accommodations may be made for qualified individuals with disabilities.

  • Maintain a constant state of mental alertness.
  • Regularly sit, speak, hear, and use hands and fingers to operate computers, keyboards, mobile devices, and telephones.
  • Frequently perform work in a sedentary office environment with opportunities to move about.
  • Occasionally stand, walk, bend, stoop, reach, and lift or move items weighing up to 50 pounds.
  • Requires close vision, distance vision, peripheral vision, and the ability to adjust focus.
  • Occasional local and overnight travel by automobile or commercial aircraft may be required.
Why AP&T?
  • Employee-owned company through our ESOP program
  • Opportunity to secure critical infrastructure serving Alaska communities
  • Collaborative and mission-driven culture
  • Professional development and certification support
  • Competitive compensation and comprehensive benefits
  • Meaningful work with visible impact

Alaska Power & Telephone is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, genetic information, or any other status protected by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Program Lead – Critical Infrastructure
Cybersecurity Program Lead – Critical Infrastructure

Alaska Power & Telephone Company • Ketchikan (AK)

On-site
USD 120,000 - 180,000
ESOP employee ownership
Professional certification support
Competitive compensation
+1
Meter Programing Lead
Meter Programing Lead

Alaska Power & Telephone • Alaska

On-site
USD 83,000 - 96,000
Meter Programing Lead
Meter Programing Lead

Alaska Power & Telephone • Anchorage (AK)

Hybrid
USD 83,000 - 96,000
Medical/dental/vision
Employee stock ownership options
Annual travel reimbursement
+1
Meter Programing Lead
Meter Programing Lead

Alaska Power & Telephone Company • Anchorage (AK)

Hybrid
USD 83,000 - 96,000
Customer Service Representative
Customer Service Representative

Alaska Power & Telephone • Tok (AK)

On-site
USD 19,000 - 33,000
Medical insurance
Dental insurance
Vision insurance
+5
Customer Service Representative
Customer Service Representative

Alaska Power & Telephone Company • Wrangell (AK)

On-site
USD 27,000 - 39,000
Medical insurance
Dental insurance
Vision insurance
+1
Customer Service Representative
Customer Service Representative

Alaska Power & Telephone Company • Ketchikan (AK)

On-site
USD 29,000 - 39,000
Medical, dental, vision
401(k)
Medical travel reimbursement
+4
Customer Service Representative
Customer Service Representative

Alaska Power & Telephone Company • Tok (AK)

On-site
USD 48,000 - 52,000
Medical, dental, vision
401(k)
Travel reimbursement
+3
Customer Service Representative
Customer Service Representative

Alaska Power & Telephone • Wrangell (AK)

On-site
USD 27,000 - 39,000
Medical, dental, vision
401(k)
Medical travel reimbursement
+4
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)

RiseMe • New Jersey

On-site
USD 155,000 - 261,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
+7