INFORMATION SECURITY MANAGER

Sound Seal IncAgawam, MA
$150,000 - $155,000Hybrid

About The Position

Catalyst Acoustics Group (CAG) is seeking an Information Security Manager to be the senior owner of its information-security function. This is a hands-on player-coach role responsible for running the security program, setting the roadmap, governance, and reporting, as well as performing operational security tasks such as incident response, tooling tune-ups, and queue management. The role will leverage a managed security provider (Paragus co-managed SOC) for scale. This position is the permanent successor to a summer security internship, taking over day-to-day responsibilities for security ticket triage, the KnowBe4 awareness program, and Huntress EDR response, while adding program governance, risk/compliance, and leadership reporting. The scope includes IT and information security for CAG's cloud-first Microsoft 365 / Azure environment, with operational technology (OT) systems addressed in partnership with Operations. The role reports to the VP, Technology and collaborates with IT, HR, Operations, and various brands, while also managing security vendors and the co-managed SOC relationship.

Requirements

  • 5+ years in information security with a mix of hands-on operations and program/leadership responsibility — able to both run the program and do the work directly. (Hands-on technical depth is weighted over policy-only backgrounds, per leadership direction.)
  • Direct experience with incident response and EDR tooling (Huntress, Microsoft Defender, CrowdStrike, SentinelOne, or similar).
  • Microsoft 365 / Entra (Azure AD) security depth: MFA/Conditional Access, privileged access, Defender.
  • Email security administration (Mimecast, Proofpoint, or similar).
  • Vulnerability management and remediation experience.
  • Experience owning or heavily contributing to a security awareness program (KnowBe4 or similar).
  • Ability to set policy/governance and to report security posture to executive leadership.
  • Strong written and verbal communication; can translate risk for non-technical stakeholders.
  • Authorization to work in the United States.
  • Bachelor’s degree in cybersecurity, information systems, computer science, or a related field, or equivalent experience.

Nice To Haves

  • Security certifications (CISSP, CISM, GIAC, or CompTIA Security+/CySA+)
  • Experience managing a co-managed SOC / MSSP relationship.
  • Manufacturing or multi-site / multi-entity (incl. post-acquisition) environment.
  • Familiarity with our stack: Huntress, Mimecast, KnowBe4, Microsoft Defender/Entra, Zoho Desk, Intune.

Responsibilities

  • Own and drive CAG's information-security roadmap and priorities across all brands and sites.
  • Develop and maintain security policy, standards, and governance; drive toward a defined baseline (e.g., change management, access governance, IR plan approved by the ELT).
  • Own risk and compliance: risk register, control gaps, vulnerability-management program cadence, annual penetration-test coordination, and remediation tracking.
  • Own the security awareness program (KnowBe4): training assignment/completion, monthly phishing-simulation campaigns, targeted remediation with HR, and metrics.
  • Manage security vendors and tooling — including the Paragus co-managed SOC relationship, EDR, and email security — holding them to scope and outcomes.
  • Report to leadership: regular security posture, KPIs, incident summaries, and risk readouts for the VP, Technology and the ELT.
  • Lead security due diligence and integration for CAG acquisitions — assess acquired environments and fold them into CAG’s security baseline.
  • Own cyber-insurance renewal attestations and respond to customer and contractual security questionnaires and audits.
  • Own or co-own business continuity and disaster-recovery planning, including backup-integrity validation and recovery testing.
  • Contribute the security lens to the multi-brand ERP consolidation and other major technology projects (access model, segregation of duties, secure design).
  • Incident response — lead investigation, containment, and resolution; own the IR runbooks and post-incident reviews; escalate to the VP, Technology as appropriate; available for reasonable after-hours response to high-severity incidents.
  • EDR (Huntress) — monitor and triage the alert queue, validate and classify alerts, respond to standard types, tune detections, and drive novel/high-severity cases to closure.
  • Email security (Mimecast) — administer the platform, manage quarantine and policy, and respond to email-borne threats.
  • Identity & M365 security — MFA/Conditional Access, privileged-access and elevated-permission governance, Defender/Entra security posture, and account-compromise response.
  • Phishing response — own end-user phishing reports and “is this safe?” triage in Zoho Desk, applying and improving the playbooks.
  • Vulnerability management — run/coordinate regular scans, prioritize findings, and drive patching/remediation to closure.

Benefits

  • Up to 10% bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service