IT Security Manager
Summary
A hands-on cybersecurity leader at a Michigan-based manufacturer who owns day-to-day security across Microsoft 365, Azure, and on-premises environments — administering identity and access controls, monitoring and responding to incidents, managing vulnerabilities, and running the security compliance program while coordinating external security vendors and building out the security function.
Job Summary
Main Duties & Responsibilities
- Own and perform day-to-day security administration across Microsoft 365, Azure, endpoints, servers, networks, applications, and other cloud and on-premises technology environments.
- Administer and continuously improve identity and access controls, including privileged access, role-based access, multifactor authentication, conditional access, least privilege, and periodic access reviews.
- Serve as the security and permissions owner for major business systems, including GSS, Procore, and Microsoft platforms, coordinating approvals, provisioning, changes, reviews, and removal of access with system owners.
- Monitor security events and findings; investigate alerts; coordinate containment, remediation, recovery, and lessons learned; and maintain incident response procedures and evidence.
- Manage vulnerability, configuration, endpoint, email, cloud, and network security activities, working directly with internal technology staff and external providers to reduce risk.
- Lead security compliance activities and maintain policies, standards, procedures, control documentation, risk records, audit evidence, and remediation plans aligned with applicable business, customer, regulatory, and contractual requirements.
- Conduct and document security risk assessments, control reviews, third-party security reviews, and periodic testing; track identified gaps through resolution.
- Manage relationships, service quality, deliverables, escalations, and performance for managed security providers, security consultants, technology vendors, and contracted security resources.
- Coordinate security awareness, phishing-resistance, and role-based training initiatives and provide practical security guidance to employees, managers, and technology teams.
- Evaluate new systems, projects, integrations, and vendor solutions for security and access-control requirements, and provide actionable recommendations that balance protection, usability, and business needs.
- Develop security metrics, dashboards, and regular updates for technology leadership, including risk trends, incidents, vulnerabilities, compliance status, vendor performance, and remediation progress.
- Help define the future security operating model and, as the function grows, supervise and develop a Security Analyst or other assigned security resources.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or equivalent professional experience.
- Typically five or more years of progressive information security experience, including substantial hands-on responsibility in Microsoft-centric cloud and on-premises environments.
- Demonstrated experience administering identity, privileged access, role-based permissions, security configurations, and access reviews for enterprise platforms; experience with Microsoft 365 and Azure is strongly preferred.
- Working knowledge of endpoint, email, network, server, cloud, vulnerability management, logging, monitoring, and incident response technologies and practices.
- Experience developing and maintaining security policies, standards, procedures, risk assessments, control evidence, audit documentation, and remediation plans.
- Experience supporting recognized cybersecurity or compliance frameworks such as NIST CSF, NIST SP 800-171, CMMC, ISO-based management systems, or comparable requirements.
- Demonstrated ability to manage managed security providers, consultants, contracted resources, and technology vendors, including accountability for scope, service quality, escalation, and follow-through.
- Ability to work independently, prioritize competing risks, perform technical work directly, and translate security requirements into practical business and technical actions.
- Strong written and verbal communication skills, sound judgment, attention to detail, and the discretion required to manage sensitive systems, investigations, and information.
- Relevant certifications such as CISSP, CISM, Security+, Microsoft security certifications, or equivalent are preferred but not required.
- Prior formal people-management experience is helpful but not required; the successful candidate must demonstrate the ability to lead work, coordinate external resources, and develop future team members.