Cole Haan Logo

Cole Haan

Senior Manager, Cybersecurity Operations & Risk Management (Remote)

Reposted 4 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Greenland, NH
155K-185K Annually
Senior level
In-Office or Remote
Hiring Remotely in Greenland, NH
155K-185K Annually
Senior level
Lead and improve cybersecurity operations, incident response, vulnerability management, and technical risk reduction. Coordinate cross-functional remediation, manage security technologies and vendors, develop metrics and playbooks, and communicate risks to stakeholders and leadership.
The summary above was generated by AI
Job Summary & Responsibilities

Reporting to the Senior Director, Cybersecurity & Compliance, the Senior Manager, Cybersecurity Operations & Risk Management is responsible for the operational oversight and continuous improvement of cybersecurity operations, incident response, vulnerability management, and technical risk reduction activities. This is a senior manager-level individual contributor role that leads initiatives through influence, coordination, and cross-functional partnership rather than direct people management.

 

The role partners with IT teams, business stakeholders, vendors, and managed service providers to strengthen security controls, reduce risk, and drive timely remediation of security issues. As the operational lead for key cybersecurity functions, this position helps ensure threats, vulnerabilities, and control weaknesses are effectively identified, prioritized, and addressed.

 

The ideal candidate combines strong technical expertise, operational leadership, and communication skills with a demonstrated ability to drive measurable security improvements across a global environment

 

CORE ACCOUNTABILITIES:

 

Security Operations & Incident Response

  • Lead cybersecurity monitoring, investigations, and incident response activities
  • Serve as the operational lead and primary coordinator for cybersecurity incidents and investigations
  • Coordinate containment, recovery, stakeholder communications, and post-incident remediation activities
  • Develop and maintain incident response procedures, playbooks, and tabletop exercises
  • Partner with internal teams, vendors, and managed security service providers to investigate and resolve security events
  • Develop operational metrics and reporting related to threats, incidents, response effectiveness, and overall security posture
  • Develop and maintain operational dashboards and reporting that provide leadership visibility into critical vulnerabilities, remediation status, technology lifecycle risks, security incidents, and unresolved risk exposures

Vulnerability & Threat Management

  • Own vulnerability identification, risk-based prioritization, remediation tracking, exception management, reporting and stakeholder engagement processes. Establish remediation expectations, monitor adherence, remediation SLAs, and escalate aging risks to appropriate technology and business leaders
  • Maintain visibility into end-of-life (EOL) and end-of-support (EOS) technology risks. Partner with Infrastructure, Applications, and Architecture teams to ensure replacement, upgrade, or risk mitigation plans are established and tracked before expiration dates
  • Partner with technology teams to drive timely remediation of vulnerabilities and security weaknesses
  • Develop vulnerability metrics and reporting to measure remediation performance, risk reduction, and program effectiveness
  • Manage vulnerability exceptions and ensure risk acceptance decisions are documented and periodically reviewed
  • Assess emerging threats and organizational exposure to inform remediation priorities
  • Partner with Security Architecture to align remediation efforts with security standards and long-term risk reduction objectives

Security Technology & Operations Improvement

  • Serve as the operational owner for cybersecurity technologies and services, ensuring they effectively support threat detection, incident response, vulnerability management, and risk reduction objectives
  • Continuously improve security monitoring, detection, response, and reporting capabilities
  • Administer and continuously improve endpoint privilege management (EPM) controls to support least-privilege access, application control, and endpoint risk reduction
  • Design and optimize operational workflows, dashboards, alerts, and automation opportunities
  • Partner with Security Architecture and Infrastructure teams to implement and operationalize new security controls and technologies
  • Support onboarding, integration, and optimization of security technologies across the enterprise
  • Manage cybersecurity vendor and service provider relationships, ensuring effective service delivery, operational performance, issue resolution, and alignment with security objectives

 

Security Risk & Control Management

  • Conduct technical security assessments to identify cybersecurity risks, control weaknesses, and remediation opportunities across infrastructure, cloud, applications, and security technologies
  • Partner with Infrastructure, Cloud, Applications, and Security Architecture teams to develop remediation plans
  • Validate implementation and effectiveness of security controls
  • Provide technical expertise and evidence in support of cybersecurity audits, assessments, and compliance activities
  • Maintain remediation tracking, cybersecurity risk registers, technology lifecycle risk inventories, and operational security improvement plans. Drive regular review of outstanding risks with accountable technology leaders and facilitate escalation of overdue remediation activities
  • Assist with third-party security assessments and technical due diligence reviews

Leadership & Collaboration

  • Serve as a trusted cybersecurity subject matter expert across operational security initiatives.
  • Build strong relationships with technology teams, business stakeholders, vendors, and service providers
  • Drive accountability for remediation activities and security commitments
  • Foster a culture of operational excellence, continuous improvement, and proactive risk management
  • Communicate cybersecurity risks and recommendations to both technical and non-technical audiences
  • Establish and lead recurring cybersecurity operational review meetings focused on vulnerability remediation, technology lifecycle risks, exception management, and risk reduction progress across the enterprise
Preferred Qualifications

Education

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
  • Advanced degree preferred

Experience

  • 7+ years of cybersecurity experience, with demonstrated success in security operations, incident response, vulnerability management, and technical risk reduction initiatives
  • 3-5 years leading security operations, vulnerability management, or incident response functions.
  • Experience managing security incidents and coordinating cross-functional technical response activities
  • Experience working with SIEM, EDR/XDR, vulnerability management, and cloud security platforms
  • Experience prioritizing remediation efforts using business risk, exploitability, and threat intelligence
  • Experience presenting cybersecurity risks, trends, and operational metrics to leadership
  • Experience working with cybersecurity vendors, MSSPs, and technology partners

 

Preferred Areas of Expertise

 

  • Security Operations & Monitoring
  • Incident Response
  • Vulnerability Management
  • Threat Intelligence
  • SIEM & Security Analytics
  • EDR/XDR Platforms
  • Identity & Access Management
  • Privileged Access Management
  • Microsoft 365 Security
  • Cloud Security
  • Security Automation

 

Preferred Certifications

 

  • CISSP
  • CISM
  • GCIH
  • Security+
  • Microsoft Security Certifications

Base Salary/Hourly Range: From $155,000 to $185,000 annually*

Bonus Eligibility: Yes, eligible for annual target bonus based on company and individual performance

Benefits Offered: Health Insurance, Dental Insurance, Vision Care, Health Savings Account with Employer Contribution, Flexible Spending Accounts, 401(k) Retirement Plan with Employer Matching Contributions, Short-Term Disability Insurance, Life Insurance, Vacation Time, Sick Time, Paid Parental Leave, Adoption Assistance Program, Charitable Matching Gifts Program, Holidays and Cole Haan Discounts

Paid Time Off: Paid vacation days starting at 120 hours, 11 paid company and personal holidays, 3 volunteer days

Sick Leave: Eligible non-exempt employees earn one hour of sick time for every 30 hours worked. Eligible exempt full-time employees earn 2.67 hours of sick time each bi-weekly pay period

 

*Rate of pay dependent upon candidates’ relevant skills, experience, and location

Similar Jobs

6 Hours Ago
Remote or Hybrid
United States
142K-192K Annually
Expert/Leader
142K-192K Annually
Expert/Leader
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead complex real estate tax engagements, mentor teams, provide client advisory on tax strategies, and drive business growth through networking.
Top Skills: CpaJdLlmMstTax Technology Tools
6 Hours Ago
Remote or Hybrid
United States
106K-160K Annually
Senior level
106K-160K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Manage the insurance tax team, assist in client relationships and business development, oversee tax compliance, and support tax strategies.
Top Skills: AccountingInsurance TaxTax Compliance
6 Hours Ago
Remote or Hybrid
United States
107K-160K Annually
Senior level
107K-160K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Serve as a trusted advisor to behavioral health providers by reviewing financial reporting, preparing budgets/forecasts, analyzing KPIs, providing technical accounting support, identifying operational improvements, leading US and offshore engagement teams, and coaching staff to ensure high-quality deliverables and client service.
Top Skills: Bill.ComNetSuiteQuickbooks OnlineSage Intacct

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account