IT Security Manager
Milbank LLP · New York City, UNAVAILABLE, US
About this role
## IT Security Manager ### Overview The IT Security Manager is responsible for managing and overseeing the Firm’s information security program, including security operations, governance, risk management, compliance initiatives, security architecture reviews, incident response activities, and third-party security services. You’ll partner with IT leadership, business stakeholders, and external partners to protect the confidentiality, integrity, and availability of Firm information assets. ### Responsibilities - Manage security tooling and controls, including: Intruder Detection sensors, firewalls, Anti-Virus, Web Filtering, DLP, IPS/IDS, NAC, DDoS protection, third-party remote access, application whitelisting, and EDR solutions - Manage and investigate security events using SIEM systems - Investigate all security events until resolution - Manage privilege account management systems - Conduct technical security audits and risk assessments - Perform firewall, network, and systems configuration change audits - Run vulnerability scans across networks, servers, systems, and applications - Create weekly security reports and track security metrics - Work with consultants and third-party vendors supporting security services - Participate in project reviews for information security architectures - Research and test new security technologies - Maintain strong relationships with third-party security vendors (e.g., MSSP, SOC, and others) ### Location - **Remote** ### Compensation - Anticipated base salary range: **$165,000 to $1205,000** (final offer depends on experience, qualifications, degrees, location, and business needs) ### Qualifications - **8–10+ years** of hands-on information security experience in enterprise environments - **3–5+ years** in a leadership or management role - Strong knowledge of security frameworks: **NIST CSF, NIST 800-53, CIS Controls, ISO 27001, SOC 2** - Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field - **Required:** Significant hands-on experience with **Microsoft Azure** and Microsoft cloud security technologies, including: - Azure security architecture - Microsoft Entra ID - Microsoft Defender - Microsoft Sentinel - Azure networking - Cloud governance - Identity and access management - Cloud incident response - **Professional cybersecurity certification required**, such as: **CISSP, CISM, CISA, GIAC GSEC, PCNSE, AZ-500** - Candidates must have proven Microsoft Azure security experience **and** at least one relevant cybersecurity certification ### Skills & Experience (Additional) - Strong analytical problem-solving and solution development - Customer satisfaction-oriented mindset; ability to balance security with business objectives - Ability to manage multiple projects in a fast-paced environment - Ability to travel when necessary - Availability for off-hours support and emergency incident calls; weekend on-call rotation - Strong communication, documentation, and interpersonal skills - Root-cause analysis during incident investigations ### Technology Experience **Experience with (examples):** - Cisco network devices - Palo Alto firewalls (full feature set) - Micro-segmentation (e.g., Illumio) - SIEM (e.g., Microsoft Sentinel) - IDS/IPS (e.g., Vectra AI, Snort, Suricata, AlienVault) - Endpoint security (e.g., CB Application Control, ThreatLocker, Microsoft Defender for Endpoint) - Vulnerability scanning & testing (e.g., Nessus, Tenable, Rapid7 Nexpose
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.