Cyber Security Manager
Salary: $132,310.00 - $190,195.04 Commensurate with Experience
Thank you for your interest in joining the team that keeps Charlotte moving, at a very exciting time for our organization. At the Charlotte Area Transit System (CATS), we’re committed to delivering safe, reliable, and innovative transit services for our growing community, and we value employees who bring professionalism, passion, and a commitment to public service.
This position is currently employed by CATS, a department of the City of Charlotte. With the passage of the PAVE Act and last year’s sales tax referendum, CATS is preparing to transition from a City department to the newly created Metropolitan Public Transit Authority (MPTA). The MPTA was established to strengthen regional transit governance, improve accountability, and support long‑term investment in mobility. It’s an important and exciting step forward for transit in our region.
Employees hired into this role will remain City employees through December 31, 2026, and will transition to MPTA employment on January 1, 2027. Benefits and compensation will follow City provisions through 2026 and shift to MPTA provisions in 2027, with clear information shared in advance. Your core duties, reporting structure, and daily responsibilities will remain consistent, with no break in service. If anything delays the transition, your City employment, including compensation and benefits, will remain in place until the move to the MPTA occurs.
The creation of the MPTA positions us for a more modern, sustainable, and efficient transit system, one that can better support the Charlotte region for decades to come. We’re excited about what’s ahead and appreciate your interest in being part of it.
SUMMARY
The Cyber Security Manager is responsible for development, implementation, and oversight of cybersecurity operations and risk management practices for the Charlotte Area Transit System (CATS). This position leads efforts to protect enterprise, operational, and infrastructure technology environments from cybersecurity threats while supporting reliable technology operations within a 24/7 transit environment.The role establishes security practices, coordinates incident response activities, and ensures technology systems align with organizational security standards and regulatory expectations. The Cyber Security Manager works collaboratively across Infrastructure & Operations, Applications & Development, and Strategy & Quality teams to integrate security into system design, operations, and governance processes.
Working under limited direction, this position exercises independent judgment in identifying risks, prioritizing security initiatives, and guiding organizational cybersecurity maturity as CATS transitions toward increased operational independence.
Major Duties and Responsibilities:
The following duties are standard for this position. The omission of specific statements of duties does not exclude them from the classification if the work is similar, related, or a logical assignment for this classification.
Cybersecurity Program Leadership
Develop and maintain cybersecurity operational practices protecting infrastructure, applications, and operational technology systems.
Establish security priorities aligned with organizational risk tolerance.
Lead development of cybersecurity policies, procedures, and standards.
Promote security awareness across the organization.
Guide adoption of security-by-design principles.
Security Operations and Monitoring
Oversee monitoring of technology environments for security threats and vulnerabilities.
Coordinate investigation and response to cybersecurity incidents.
Direct containment, mitigation, and recovery activities.
Support implementation of monitoring and detection technologies.
Maintain incident response readiness.
Risk Management and Compliance
Conduct risk assessments across enterprise and operational technology environments.
Identify vulnerabilities and recommend mitigation strategies.
Support compliance with applicable regulatory and organizational requirements.
Maintain security documentation and risk registers.
Coordinate security audits and assessments.
Infrastructure and Application Security Coordination
Partner with Network Infrastructure Manager and Solutions Architect to ensure secure system design.
Support secure configuration and hardening practices.
Review technology implementations for security alignment.
Promote least-privilege and identity governance practices.
Support secure integration of operational technology systems.
Vendor and Third-Party Security Oversight
Evaluate cybersecurity posture of vendors and technology providers.
Support procurement reviews involving security considerations.
Monitor vendor compliance with security expectations.
Coordinate remediation of identified risks.
Organizational Collaboration and Advisory
Serve as cybersecurity advisor to Technology leadership.
Support business units in understanding security risks and responsibilities.
Provide guidance during technology projects and system implementations.
Communicate risk posture and security priorities to leadership.
Continuous Improvement and Security Maturity
Develop cybersecurity improvement roadmaps.
Track emerging threats and evolving best practices.
Recommend enhancements strengthening organizational resilience.
Support development of long-term cybersecurity capabilities.
Core Competencies:
The position requires demonstrated competency in the following areas
Cybersecurity Leadership and Governance
Ability to establish and guide organizational cybersecurity practices balancing protection with operational needs.
Defines practical security controls.
Aligns security with organizational risk tolerance.
Promotes accountability across technology domains.
Risk Evaluation and Decision Making
Ability to assess technical and operational risk in complex environments.
Identifies systemic vulnerabilities.
Prioritizes mitigation efforts.
Makes defensible risk-based recommendations.
Collaborative Technical Influence
Ability to integrate security into diverse technology environments through partnership and expertise rather than direct authority.
Builds trust across teams.
Influences system design decisions.
Encourages shared ownership of security outcomes.
Incident Leadership and Resilience
Ability to guide effective response during security events.
Maintains composure during incidents.
Coordinates cross-functional response.
Drives post-incident learning and improvement.
Supervision Given to:
Security Analyst(s)
Compliance and Risk Specialist
Minimum Qualifications:
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field; or equivalent combination of education and experience.
Six (6) years progressively responsible experience in cybersecurity or information security roles.
Experience managing or leading security initiatives or programs.
Preferred Qualifications:
Experience securing operational or infrastructure technology environments.
Experience supporting public-sector or transportation organizations.
Professional cybersecurity certifications (e.g., CISSP, CISM, Security+).
Experience developing cybersecurity programs or governance frameworks.
Knowledge, Skills and Abilities:
Knowledge of:
Cybersecurity frameworks and best practices.
Threat detection and incident response methodologies.
Identity and access management concepts.
Infrastructure and network security principles.
Vulnerability management and risk assessment practices.
Security considerations for operational technology environments.
Regulatory and compliance concepts affecting public-sector technology systems.
Skill in:
Evaluating cybersecurity risks and controls.
Leading incident response coordination.
Communicating technical risk to non-technical stakeholders.
Developing policies and operational procedures.
Analyzing security events and trends.
Facilitating cross-functional collaboration.
Ability to:
Exercise independent professional judgment in risk-based decision making.
Balance operational continuity with security protections.
Influence organizational behavior without direct authority.
Anticipate emerging threats and adapt strategies accordingly.
Build organizational awareness and shared responsibility for cybersecurity.
Working Environment and Physical Demands:
Work performed primarily in office environments with occasional visits to operational facilities.
Participation in cybersecurity incident response outside normal business hours may be required.
Requires prolonged computer use and analytical work.
Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.
CONDITIONS OF EMPLOYMENT
The City’s Background Check Policy requires background checks to be conducted on final internal or external candidate(s) applying for any position with the City of Charlotte. The type of information that will be collected as part of a background check includes, but is not limited to: reference checks, social security verification, education verification, criminal conviction record check, and, if applicable, a credit history check, sex offender registry and motor vehicle records check.
Background checks must be in compliance with all federal and state statutes, such as the Fair Credit Reporting Act (FCRA). The checks must be consistent with the guidelines set forth by these laws requiring organizations to obtain a candidate’s written authorization before obtaining a criminal background report, motor vehicle records check or credit report; and to properly store and dispose of information derived from such reports.
Final candidates must pass a pre-employment drug-screening test and physical examination. During the selection process, candidates may be asked to take a skills test, and/or participate in other assessments.
The City of Charlotte is an Equal Opportunity Employer and does not unlawfully discriminate on the basis of race, religion, color, sex, national origin, marital status, age, disability, sexual orientation, political affiliation or on the basis of actual or perceived gender as expressed through dress, appearance, or behavior.
Our culture is to serve the community honorably.
HOW TO APPLY
Apply online.
Federal law requires employers to provide reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job.
You are welcome to visit the City of Charlotte Human Resources Department lobby, where self-service application kiosks are available. They are located in our office at 700 East 4th Street, Suite 200, Charlotte, NC 28202. We are open Monday through Friday, from 9:30 a.m. to 3:30 p.m. (EST), excluding official City holidays.
For questions about your application or the hiring process, please email Careers@ci.charlotte.nc.us
The City of Charlotte is committed to making our services and programs accessible to all. Upon request, auxiliary aids, written materials in alternate formats, language access, and other reasonable accommodations or modifications will be provided. To make a request, please fill out the Innovation & Technology ADA request form or call 704.336.4120.
BENEFITS
The City of Charlotte provides a comprehensive benefits package to eligible employees.
Click here to learn more about the City of Charlotte’s benefits.
The City of Charlotte is a drug and alcohol-free workplace.