Cyber Security Manager

City of CharlotteCharlotte, NC
Hybrid

About The Position

The Cyber Security Manager is responsible for the development, implementation, and oversight of cybersecurity operations and risk management practices for the Charlotte Area Transit System (CATS). This position leads efforts to protect enterprise, operational, and infrastructure technology environments from cybersecurity threats while supporting reliable technology operations within a 24/7 transit environment. The role establishes security practices, coordinates incident response activities, and ensures technology systems align with organizational security standards and regulatory expectations. The Cyber Security Manager works collaboratively across Infrastructure & Operations, Applications & Development, and Strategy & Quality teams to integrate security into system design, operations, and governance processes. Working under limited direction, this position exercises independent judgment in identifying risks, prioritizing security initiatives, and guiding organizational cybersecurity maturity as CATS transitions toward increased operational independence. Employees hired into this role will remain City employees through December 31, 2026, and will transition to Metropolitan Public Transit Authority (MPTA) employment on January 1, 2027. Benefits and compensation will follow City provisions through 2026 and shift to MPTA provisions in 2027, with clear information shared in advance. Your core duties, reporting structure, and daily responsibilities will remain consistent, with no break in service. If anything delays the transition, your City employment, including compensation and benefits, will remain in place until the move to the MPTA occurs.

Requirements

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field; or equivalent combination of education and experience.
  • Six (6) years progressively responsible experience in cybersecurity or information security roles.
  • Experience managing or leading security initiatives or programs.
  • Knowledge of: Cybersecurity frameworks and best practices.
  • Threat detection and incident response methodologies.
  • Identity and access management concepts.
  • Infrastructure and network security principles.
  • Vulnerability management and risk assessment practices.
  • Security considerations for operational technology environments.
  • Regulatory and compliance concepts affecting public-sector technology systems.
  • Skill in: Evaluating cybersecurity risks and controls.
  • Leading incident response coordination.
  • Communicating technical risk to non-technical stakeholders.
  • Developing policies and operational procedures.
  • Analyzing security events and trends.
  • Facilitating cross-functional collaboration.
  • Ability to: Exercise independent professional judgment in risk-based decision making.
  • Balance operational continuity with security protections.
  • Influence organizational behavior without direct authority.
  • Anticipate emerging threats and adapt strategies accordingly.
  • Build organizational awareness and shared responsibility for cybersecurity.

Nice To Haves

  • Experience securing operational or infrastructure technology environments.
  • Experience supporting public-sector or transportation organizations.
  • Professional cybersecurity certifications (e.g., CISSP, CISM, Security+).
  • Experience developing cybersecurity programs or governance frameworks.

Responsibilities

  • Develop and maintain cybersecurity operational practices protecting infrastructure, applications, and operational technology systems.
  • Establish security priorities aligned with organizational risk tolerance.
  • Lead development of cybersecurity policies, procedures, and standards.
  • Promote security awareness across the organization.
  • Guide adoption of security-by-design principles.
  • Oversee monitoring of technology environments for security threats and vulnerabilities.
  • Coordinate investigation and response to cybersecurity incidents.
  • Direct containment, mitigation, and recovery activities.
  • Support implementation of monitoring and detection technologies.
  • Maintain incident response readiness.
  • Conduct risk assessments across enterprise and operational technology environments.
  • Identify vulnerabilities and recommend mitigation strategies.
  • Support compliance with applicable regulatory and organizational requirements.
  • Maintain security documentation and risk registers.
  • Coordinate security audits and assessments.
  • Partner with Network Infrastructure Manager and Solutions Architect to ensure secure system design.
  • Support secure configuration and hardening practices.
  • Review technology implementations for security alignment.
  • Promote least-privilege and identity governance practices.
  • Support secure integration of operational technology systems.
  • Evaluate cybersecurity posture of vendors and technology providers.
  • Support procurement reviews involving security considerations.
  • Monitor vendor compliance with security expectations.
  • Coordinate remediation of identified risks.
  • Serve as cybersecurity advisor to Technology leadership.
  • Support business units in understanding security risks and responsibilities.
  • Provide guidance during technology projects and system implementations.
  • Communicate risk posture and security priorities to leadership.
  • Develop cybersecurity improvement roadmaps.
  • Track emerging threats and evolving best practices.
  • Recommend enhancements strengthening organizational resilience.
  • Support development of long-term cybersecurity capabilities.

Benefits

  • Comprehensive benefits package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service