INFORMATION SECURITY MANAGER

Catalyst Acoustics Group

Columbus (OH)

Hybrid

USD 150,000 - 170,000

Full time

4 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Catalyst Acoustics Group seeks an Information Security Manager to own and run the security program. This hands-on leader acts as a player-coach, setting governance, responding to incidents, and guiding tooling with support from a co-managed SOC for scale.

The role reports to the VP, Technology and collaborates across IT, HR, Operations, and brands. It covers US sites with remote work options and an eventual security-program expansion across sites.

Qualifications

  • 5+ years in information security with a mix of hands-on operations and program/leadership responsibility.
  • Direct experience with incident response and EDR tooling.
  • Microsoft 365 / Entra (Azure AD) security depth.
  • Email security administration.
  • Vulnerability management and remediation experience.
  • Experience owning or heavily contributing to a security awareness program.
  • Ability to set policy/governance and to report security posture to executive leadership.
  • Strong written and verbal communication; authorized to work in the United States.
  • Bachelor’s degree in cybersecurity, information systems, CS, or related field.

Responsibilities

  • Own and drive CAG's information-security roadmap and priorities across all brands and sites.
  • Develop and maintain security policy, standards, and governance; drive toward a defined baseline.
  • Own risk and compliance: risk register, control gaps, vulnerability-management program cadence, annual penetration-test coordination, and remediation tracking.
  • Own the security awareness program (KnowBe4): training assignment/completion, phishing-simulation campaigns, remediation with HR, and metrics.
  • Manage security vendors and tooling — including the Paragus co-managed SOC relationship, EDR, and email security.
  • Report to leadership: regular security posture, KPIs, incident summaries, and risk readouts for VP, Technology and ELT.
  • Lead security due diligence and integration for acquisitions; fold acquired environments into baseline.
  • Own cyber-insurance renewal attestations and respond to security questionnaires and audits.
  • Own or co-own business continuity and disaster-recovery planning and testing.
  • Contribute security perspective to ERP consolidation and major tech projects.

Skills

InfoSec leadership
Incident response
EDR tooling
M365 / Entra security
Email security
Vulnerability management
Security awareness program
Policy governance
Communication skills
US work authorization
Bachelor's degree in cybersecurity

Education

Bachelor's degree in cybersecurity

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

INFORMATION SECURITY MANAGER

Full Time Professional Agawam, MA, US

Salary Range: $150,000.00 To $155,000.00 Annually

Department:Technology

Reports to:VP, Technology (David Crandall)

Direct reports:None initially (program is MSP-backed — Paragus co-managed SOC)

Primary location:Boston or Chicago metro preferred; Columbus, OH (Dublin/Kinetics hub), Remote

Travel:Occasional, across CAG's U.S. sites

FLSA status:Exempt

Comp reference:$120,000–$155,000 base + up to 10% bonus

About Catalyst Acoustics Group

Catalyst Acoustics Group (CAG) is a mid-market manufacturer of noise-control and vibration control products, operating a family of brands (Kinetics Noise Control, Sound Seal, IAC Acoustics, Frasch, Lamvin, Noise Barriers, RealAcoustix, Madrid, CurbTech, and Riverbank Acoustical Laboratories) across roughly a dozen U.S. sites, with the Dublin, OH Kinetics campus as our technology hub. We run a cloud-first Microsoft 365 / Azure environment backed by a managed security provider (Paragus). Security is being established as its own dedicated function within Technology.

Role summary

We are seeking an Information Security Manager — a hands-on player-coach who will both run the security program and do the operational security work. This is the senior owner of CAG's information-security function: you set the roadmap, governance, and reporting, and you also personally respond to incidents, tune the tooling, and work the queue. It is a single-owner role (no direct reports at the outset), leveraging our managed provider (Paragus co-managed SOC) for scale rather than an internal team.

This role is the permanent successor to CAG's summer security internship, which concludes in August 2026. It assumes senior ownership of the three functions the intern ran day-to-day — security ticket triage, the KnowBe4 awareness program, and Huntress EDR response — and adds the program governance, risk/compliance, and leadership reporting that a manager owns. A clean handoff package from the intern will be available.

You will report to the VP, Technology and partner across IT, HR, Operations, and the brands, plus manage security vendors and the co-managed SOC relationship.

Scope covers IT and information security across CAG’s cloud-first Microsoft 365 / Azure environment; operational-technology (OT) systems on the plant floor are addressed in partnership with Operations.

Essential functions

Program ownership (the “manager” half)

  • Own and drive CAG's information-security roadmap and priorities across all brands and sites.
  • Develop and maintain security policy, standards, and governance; drive toward a defined baseline (e.g., change management, access governance, IR plan approved by the ELT).
  • Own risk and compliance: risk register, control gaps, vulnerability-management program cadence, annual penetration-test coordination, and remediation tracking.
  • Own the security awareness program (KnowBe4): training assignment/completion, monthly phishing-simulation campaigns, targeted remediation with HR, and metrics.
  • Manage security vendors and tooling — including the Paragus co-managed SOC relationship, EDR, and email security — holding them to scope and outcomes.
  • Report to leadership: regular security posture, KPIs, incident summaries, and risk readouts for the VP, Technology and the ELT.
  • Lead security due diligence and integration for CAG acquisitions — assess acquired environments and fold them into CAG’s security baseline.
  • Own cyber-insurance renewal attestations and respond to customer and contractual security questionnaires and audits.
  • Own or co-own business continuity and disaster-recovery planning, including backup-integrity validation and recovery testing.
  • Contribute the security lens to the multi-brand ERP consolidation and other major technology projects (access model, segregation of duties, secure design).

Hands-on operations (the “player” half)

  • Incident response — lead investigation, containment, and resolution; own the IR runbooks and post-incident reviews; elevate to the VP, Technology as appropriate; available for reasonable after-hours response to high-severity incidents.
  • EDR (Huntress) — monitor and triage the alert queue, validate and classify alerts, respond to standard types, tune detections, and drive novel/high-severity cases to closure.
  • Email security (Mimecast) — administer the platform, manage quarantine and policy, and respond to email-borne threats.
  • Identity & M365 security — MFA/Conditional Access, privileged-access and elevated-permission governance, Defender/Entra security posture, and account-compromise response.
  • Phishing response — own end-user phishing reports and “is this safe?” triage in Zoho Desk, applying and improving the playbooks.
  • Vulnerability management — run/coordinate regular scans, prioritize findings, and drive patching/remediation to closure.

Qualifications

Required

  • 5+ years in information security with a mix of hands-on operations and program/leadership responsibility — able to both run the program and do the work directly. (Hands-on technical depth is weighted over policy-only backgrounds, per leadership direction.)
  • Direct experience with incident response and EDR tooling (Huntress, Microsoft Defender, CrowdStrike, SentinelOne, or similar).
  • Microsoft 365 / Entra (Azure AD) security depth: MFA/Conditional Access, privileged access, Defender.
  • Email security administration (Mimecast, Proofpoint, or similar).
  • Vulnerability management and remediation experience.
  • Experience owning or heavily contributing to a security awareness program (KnowBe4 or similar).
  • Ability to set policy/governance and to report security posture to executive leadership.
  • Strong written and verbal communication; can translate risk for non-technical stakeholders.
  • Authorization to work in the United States.
  • Bachelor’s degree in cybersecurity, information systems, computer science, or a related field, or equivalent experience.

Preferred

  • Security certifications (CISSP, CISM, GIAC, or CompTIA Security+/CySA+) are a plus but not required.
  • Experience managing a co-managed SOC / MSSP relationship.
  • Manufacturing or multi-site / multi-entity (incl. post-acquisition) environment.
  • Familiarity with our stack: Huntress, Mimecast, KnowBe4, Microsoft Defender/Entra, Zoho Desk, Intune.

What success looks like (first 6–12 months)

  • Clean assumption of the three intern-run functions (ticket triage, KnowBe4, Huntress) with a clean transition from the intern’s coverage and interim arrangements in place as needed.
  • A published security roadmap and baseline policy set, with an ELT-approved incident-response plan.
  • A running cadence: vulnerability scans, awareness campaigns, and a monthly security readout to leadership.
  • The Paragus co-managed SOC relationship actively managed to defined outcomes.

EEO Statement: The Company is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

INFORMATION SECURITY MANAGER
INFORMATION SECURITY MANAGER

Sound Seal Inc • Agawam (MA)

On-site
USD 150,000 - 155,000
Information Technology Security Manager
Information Technology Security Manager

Catalyst Acoustics Group • Dublin (OH)

Hybrid
USD 120,000 - 160,000
Security Program Lead & Incident-Response Strategist Hybrid
Security Program Lead & Incident-Response Strategist Hybrid

Catalyst Acoustics Group • Dublin (OH)

Hybrid
USD 120,000 - 160,000
IT Security and Systems Engineer
IT Security and Systems Engineer

SilencerCo • West Valley City (UT)

On-site
USD 120,000 - 180,000
Senior Director Information Security
Senior Director Information Security

EverCommerce • Denver (CO)

Hybrid
USD 180,000 - 240,000
Wellness stipend
Udemy training
401k with company match
+2
Security Engineer - Corporate Security (Senior)
Security Engineer - Corporate Security (Senior)

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Senior Cybersecurity Manager
Senior Cybersecurity Manager

Concert Golf • Florida

On-site
USD 108,000 - 132,000
Medical, dental, vision benefits
401(k) plan with match
Paid time off and holidays
+1
Senior Security Engineer - Corporate Security
Senior Security Engineer - Corporate Security

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Competitive salary
Health benefits
Company cell phone plan
+2
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Northern (KY)

Hybrid
USD 140,000 - 180,000