IT Security Manager

Wolters KluwerBaltimore, MD
$118,300 - $207,400Remote

About The Position

Serves as the central authority for Global Cyber Command, acting as the focal point for continuous security event monitoring, triage, escalation, and coordinated incident response, while maintaining end-to-end accountability for the incident lifecycle from detection through post-incident review and reporting. Provides operational leadership and mentorship to Security Analysts, ensuring standard operating procedures, runbooks, documentation, and metrics are established and maintained to support effective, auditable operations and continuous improvement. Ensures that security events meeting defined thresholds are promptly escalated and managed in accordance with the Wolters Kluwer Incident Response policy and procedures, coordinating cross-functional response efforts across IT Security, IT, and business stakeholders as required. When appropriate, escalates and engages other functions across Wolters Kluwer to ensure appropriate technical expertise and communication is leveraged for incidents and requests. Wolters Kluwer Global Technology Solutions (GTS) is designed to provide services to the business units in the areas of technology, sourcing, procurement, legal, finance, and human resources. These global centers promote team collaboration using best practices around a specific focus area to drive results and enhance operational efficiencies. There is a constant endeavor to benchmark against best-in-class industry standards to improve the quality of deliverables, increase cost savings, enhance productivity, and reduce time to market for products and applications. We have an amazing opportunity for an IT Security Manager (Global Cyber Command), available within our Global Technology Solutions division! This position has been created due to growth! This role will be responsible for monitoring and responding to emerging security incidents and operational support for tools used by incident response, with a primary goal of protecting and enhancing the confidentiality, integrity, and availability of Wolters Kluwer assets. This position is US based and remote. As the IT Security Manager (Global Cyber Command), you will lead information gathering efforts during investigation into suspected and confirmed security incidents to protect personal and confidential information at WK. In this role, you will be required to demonstrate proficiency in incident analysis, data gathering and information synthesis in every area of IT security management. Your role will also include operational support for intelligence, EDR, DLP and other tools supporting the incident response function.

Requirements

  • Proficiency in incident analysis, data gathering and information synthesis in every area of IT security management.
  • Operational support for intelligence, EDR, DLP and other tools supporting the incident response function.
  • Experience with SIEM, SOAR, EDR/XDR, NDR, threat intelligence, and forensic platforms.
  • Experience conducting OSINT investigations.
  • Experience with system, network, cloud, endpoint, and malware data analysis.
  • Experience partnering with engineering, infrastructure, cloud, and application teams.
  • Experience maintaining operational runbooks, playbooks, dashboards, metrics, and incident records.
  • Experience delivering incident analysis and reporting to technical teams, business stakeholders, and leadership.
  • Experience driving post-incident reviews, lessons learned, and purple team exercises.
  • Knowledge of Wolters Kluwer enterprise policies, procedures, and applicable business and regulatory requirements.

Nice To Haves

  • Mentorship and development of team members through hands-on coaching, knowledge sharing, and guidance on investigation techniques, Blue Team tooling, and incident response best practices.

Responsibilities

  • Provide day‑to‑day operational leadership for security analysts and incident responders, setting priorities, maintaining investigative focus, and ensuring timely, disciplined execution during high‑severity incidents.
  • Mentor and develop team members through hands‑on coaching, knowledge sharing, and guidance on investigation techniques, Blue Team tooling, and incident response best practices to build depth and resilience within the team.
  • Foster a culture of accountability, collaboration, and continuous improvement by reinforcing standards, supporting professional development, and promoting repeatable, mature security operations aligned to business risk.
  • Ensure adherence to defined security operations SLAs and SLOs by tracking incident response timeliness, containment and remediation performance, and validating the effectiveness of corrective actions through metrics, trend analysis, and continuous operational improvement.
  • Serve as the primary escalation point for security events and incidents, owning the full incident response lifecycle including monitoring, detection, triage, investigation, containment, eradication, recovery, and post‑incident review.
  • Lead operational support and continuous improvement of Blue Team capabilities, including SIEM, SOAR, EDR/XDR, NDR, threat intelligence, and forensic platforms, ensuring platform health, reliable log ingestion, effective integrations, tuned detections, and automated response workflows.
  • Oversee security monitoring and detection effectiveness by driving alert tuning, use‑case development, false‑positive reduction, detection coverage validation, and alignment to evolving threat scenarios.
  • Coordinate and execute incident response activities by aggregating and analyzing system, network, cloud, endpoint, and malware data; conducting OSINT investigations; synthesizing root cause; and developing risk‑based response recommendations grounded in sound security principles.
  • Partner with engineering, infrastructure, cloud, and application teams to operationalize security tooling, onboard new data sources, remediate control gaps, and implement configuration changes arising from incidents, threat intelligence, and post‑incident findings.
  • Ensure accurate, timely documentation of all response activities, including maintaining operational runbooks, playbooks, dashboards, metrics, and incident records to support 24x7 operations, audit readiness, and regulatory requirements.
  • Deliver clear, consistent, and factual incident analysis and reporting to technical teams, business stakeholders, and leadership, providing actionable insights into impact, root cause, and remediation.
  • Drive post‑incident reviews, lessons learned, and purple team exercises to validate detection and response effectiveness and translate outcomes into measurable improvements across people, process, and technology.
  • Ensure all security operations activities comply with Wolters Kluwer enterprise policies, procedures, and applicable business and regulatory requirements.

Benefits

  • Medical, Dental, & Vision Plans
  • 401(k)
  • FSA/HSA
  • Commuter Benefits
  • Tuition Assistance Plan
  • Vacation and Sick Time
  • Paid Parental Leave
  • Bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service