IT Manager, Cyber Security Services

CapMetro

Norfolk (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hampton Roads Transit seeks a hands‑on Manager of Cyber Security Services to lead information security and compliance initiatives. You will define policies with CIO/CTO input, manage risk, and coordinate incident response, audits, and security training for staff.

The role requires extensive IT security experience, leadership, and a strong grasp of NIST, HIPAA, COBIT and ISO frameworks to protect systems and data.

Qualifications

  • Bachelor’s degree in computer science, information technology, or related field.
  • 10+ years of experience in IT security, including 5+ years in a management or lead role.
  • Certifications: CISM, CISSP or similar.
  • Experience with a diverse body of cyber tools and software.
  • In‑depth knowledge of cyber security principles and best practices.
  • Experience developing and implementing security policies and procedures.
  • Project management experience.
  • Certification in CompTIA Security+.

Responsibilities

  • Define, implement and maintain corporate information and operations technology security policies based on best practices.
  • Maintain awareness of new cyber threats, vulnerabilities, and technologies.
  • Conduct risk assessments to identify threats and vulnerabilities.
  • Monitor network activity for signs of intrusion or compromise.
  • Provide technical support for networks, including firewalls, patch management, and data security.
  • Own the IT audit process for SOC & PCI reporting across the enterprise.
  • Lead vulnerability audits, forensic investigations and mitigations.
  • Coordinate incident response and post‑event analysis.
  • Train employees on information security best practices.

Skills

Presentation skills
Multitasking
Written communication
Verbal communication
Leadership
Project management

Education

Bachelor's degree in CS/IT or related field

Tools

Windows security tools
Vulnerability assessment tools
Endpoint protection tools
Log aggregation tools
Network monitoring tools
OT/ICS security tools
Video surveillance systems

Job description

The Manager of Cyber Security Services (CSS) will be hands‑on and responsible for management of HRT’s information security and compliance related activities including the following:

  • Utilizing a risk‑based approach to manage information security related aspects of HRT’s operations.
  • Assuring compliance with information security, privacy, and industry standards and regulations.
  • Designing, establishing, and maintaining reasonable organizational cyber security and information privacy postures.
  • Implementing the NIST Cybersecurity Framework within the organization to improve cyber resilience.
  • In coordination with key stakeholders, this position communicates, prepares for, and responds to geopolitical, international, and national cyber threats from an Agency perspective.

This role is responsible for ensuring HRT’s systems are secure, are compliant as per established regulatory frameworks, and audited as per established cadence.

Essential Job Functions

(Duties listed are not intended to be all inclusive nor to limit duties that might reasonably be assigned.)

  • Works with CIO/CTO to define, implement and maintain corporate information and operations technology security policies, procedures, and guidelines based on industry best practices that are compliant with federal and state regulations.
  • Maintaining awareness of new cyber threats, vulnerabilities, and technologies to keep the organization secure.
  • Conducting risk assessments to identify potential security threats and vulnerabilities.
  • Monitoring network activity to identify signs of intrusion or compromise.
  • Providing technical support for computer networks, including firewalls, operating systems and applications, patch management, and data security best practices.
  • Manage HRT’s security tool suite in including endpoint protection, vulnerability assessment, log aggregation and analysis.
  • Training staff on information security best practices to ensure compliance with company policies.
  • Conducting audits to ensure security protocols are being followed by staff.
  • Providing training in information security best practices to employees.
  • Working knowledge with industry standards such as HIPAA, ITIL, NIST, SANS, COBIT, OWASP, and ISO.
  • Own the entire IT audit process for SOC & PCI reporting across the enterprise.
  • Responsible for leading vulnerability audits, forensic investigations, and mitigation procedures.
  • Responds immediately to security‑related incidents, leads response team, and provides post‑event analysis.
  • Evaluate new cybersecurity threat and IT trends and develop effective security controls.
  • Evaluate potential security breaches, coordinate response, and recommend corrective actions.
  • Monitor compliance with security policies and procedures.
  • Investigate security breaches and incidents.
  • Coordinate incident response activities.
  • Train and educate employees on security awareness.
  • Manage security vendors and service providers.
  • Take proactive role in procurement process from the cyber security perspective.
  • Manage department budget, take part in annual capital expenditures planning exercises.
  • Manage records created and received in compliance with the Hampton Roads Transit Records Management Policies and Procedures.
  • Performs all other related duties as assigned.
Required Knowledge, Abilities and Skills essential to Job Functions
  • Bachelor’s degree in computer science, information technology, or related field.
  • 10+ years of experience in IT security, including 5+ years in a management or lead role.
  • Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) Certification or similar certification.
  • Experience with a diverse body of technical cyber tools and software.
  • In‑depth knowledge of cyber security principles and best practices.
  • Experience developing and implementing security policies and procedures.
  • Demonstrated Experience in Network Engineering.
  • Project management experience.
  • Certification in CompTIA Security+.
  • Ability to effectively present information and respond to questions from senior management, groups of managers, clients, and internal and external customers.
  • Ability to handle multiple tasks simultaneously and meet multiple deadlines.
  • Excellent written and verbal communication skills.
Required Software Knowledge and Skills essential to Job Functions

Proficiency in using computer systems and the listed software applications associated with performance of assigned work is essential. Basic problem‑solving skills associated with software applications used is expected. Software usage relevant to job duties will be evaluated.

Software applications:

  • Strong background in Windows security management and security architecture.
  • Background in application security analysis, design, and testing.
  • Experience in network traffic flow monitoring and analysis tools.
  • Experience in log aggregation and analysis tools.
  • Experience with vulnerability assessment tools.
  • Experience with endpoint protection tools.
  • Experience with Internet of Things / Operational Technology security.
  • Experience with a diverse suite of cyber and network tools.
  • Experience with physical security access control systems and video surveillance systems.
Safety Responsibility

Perform all job duties and responsibilities in a safe manner to protect one’s self, fellow employees, and the public from injury or harm. Promote safety awareness and follow safety procedures and policies. Take an active part in reporting unsafe conditions and any hazards within the workplace to their Supervisor, Manager and/or the Safety Department.

Training and/or Education

BS or higher in Computer Science, Information Technology Systems, or related field.

Required Experience

5‑10 years in Information Technology field, 2+ years in IT Security Lead role, Leadership/ Management experience preferred.

Licenses or Certificates

Possess a valid Driver’s License. Acquire a Virginia Driver's License within 60 days after the date of hire (in instances when an out of state license is not the applicant's current state of residence).

Special Requirements

This position is classified as essential personnel.

FLSA Status

Non‑exempt

Physical Demands

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Unusual Demands

The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Work involves meeting multiple demands on a timely basis. Duties may require some overtime.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. System Administrator
Sr. System Administrator

CapMetro • Norfolk (VA)

On-site
USD 120,000 - 150,000
INFORMATION TECHNOLOGY MANAGER, CYBER SECURITY SERVICES
INFORMATION TECHNOLOGY MANAGER, CYBER SECURITY SERVICES

Quantum Strides LLC • Hampton (VA)

On-site
USD 100,000 - 130,000
Facilities Maintenance Supervisor
Facilities Maintenance Supervisor

Hampton Roads Transit • Norfolk (VA), Northern (KY)

Hybrid
USD 36,000 - 46,000
Executive Assistant (Planning & Development)
Executive Assistant (Planning & Development)

Hampton Roads Transit • Norfolk (VA)

On-site
Competitive wages
Excellent benefits
Operations Facility Equipment Technician
Operations Facility Equipment Technician

Hampton Roads Transit • Norfolk (VA)

On-site
USD 26,000 - 34,000
Electrical & Electronic Maintenance Technician
Electrical & Electronic Maintenance Technician

Hampton Roads Transit • Norfolk (VA)

On-site
Cyber Security Services Manager: Risk & Compliance
Cyber Security Services Manager: Risk & Compliance

CapMetro • Norfolk (VA)

On-site
USD 120,000 - 160,000
IT Technician
IT Technician

Hampton Roads Community Action Program • Newport News (VA)

On-site
USD 45,000 - 65,000
Annual leave
Sick leave
Birthday day off
+2
Strategic Planning Manager
Strategic Planning Manager

Hampton Roads Transit • Norfolk (VA)

On-site
USD 87,000 - 115,000
Contract Specialist
Contract Specialist

Hampton Roads Transit • Norfolk (VA)

On-site
USD 66,000 - 85,000