Senior Cyber Security Manager

KeenfinityFairport, NY
Onsite

About The Position

The Senior Cyber Security Manager is responsible for defining, implementing, and operating a lean, pragmatic, and risk-based cyber security capability for the business unit. This role acts as the primary security interface between the business unit and the Central CISO Office, ensuring that local applications, platforms, data, vendors, and technology initiatives meet appropriate security, privacy, and compliance expectations. The role covers the wider IT landscape, including business applications, APIs, ERP, MDM, engineering tooling, back-office systems, cloud and SaaS services, data platforms, supplier environments, and business-critical integrations. The Senior Cyber Security Manager balances security rigor with business enablement, ensuring that cyber controls support transformation rather than slowing it down unnecessarily.

Requirements

  • 7+ years of experience in cyber security, information security, IT risk, security architecture or security operations roles.
  • Experience operating in modern cloud and SaaS environments, including security governance for third-party platforms and integrations.
  • Experience translating security policies, frameworks, and regulatory requirements into pragmatic controls.
  • Experience working with architects, business stakeholders, engineering teams, IT operations, and external vendors.
  • Experience with risk assessments, vulnerability management, penetration testing coordination, and incident response processes.
  • Experience in international, multi-site, or matrix organizations.
  • Strong understanding of identity and access management, secure integration patterns, and data protection expectations.

Nice To Haves

  • Experience in a federated CISO, BISO, security champion, or first-line security ownership model.
  • Experience with ISO 27001 implementation, audit readiness, control evidence, and remediation tracking.
  • Experience with NIS2, GDPR, and practical security governance in European operating environments.
  • Experience with cloud security in Azure and/or AWS, SaaS security governance, and enterprise platform security models.
  • Experience with API security, OAuth2/OIDC, API gateways, iPaaS, and secure integration layers.
  • Experience contributing to technology transformation programs such as CRM replacement, HubSpot implementation, ERP integration, cloud migration, application rationalization, post-M&A integration, or carve-out readiness.
  • Experience working in manufacturing, security technology, industrial technology, engineering, product, or connected-device environments.

Responsibilities

  • Define and implement a lean, risk-based cyber security strategy aligned with business priorities and Central CISO standards.
  • Translate group-level information security policies into practical business-unit controls, processes, and decision criteria.
  • Establish security governance rhythms for risk reviews, control follow-up, exception management, and leadership reporting.
  • Maintain a transparent view of the business-unit cyber risk posture, priorities, exceptions, and remediation progress.
  • Ensure that security becomes part of the normal IT operating model rather than a separate after-the-fact review activity.
  • Act as the primary security interface between the business unit and the Central CISO Office.
  • Own local cyber security execution in the first line of defense while escalating material risks to the appropriate governance forums.
  • Support the business in making risk-informed decisions, including risk acceptance, mitigation prioritization, and control design.
  • Coordinate business-unit security activities across commercial, engineering, back-office, product, operations, and data domains.
  • Ensure security requirements are practical, business-relevant, and aligned with risk appetite.
  • Collaborate closely with Enterprise Architecture, Solution Architecture, and Integration teams to embed secure-by-design principles.
  • Define security requirements for API-first solutions, customer portals, headless architectures, iPaaS integrations, and backend systems.
  • Ensure secure patterns for authentication, authorization, token-based security, OAuth2/OIDC, API gateways, and data exchange.
  • Review security implications of cloud, SaaS, ERP, MDM, CRM, engineering, and back-office platform decisions.
  • Help reduce point-to-point security complexity by encouraging reusable, documented, and governed security patterns.
  • Own and mature the business-unit identity and access management approach, including SSO, RBAC, least privilege, and access reviews.
  • Drive improvements in privileged access, role design, joiner-mover-leaver controls, and segregation of duties where relevant.
  • Partner with application owners and IT operations to ensure access rights remain appropriate and auditable.
  • Support cloud and SaaS access governance across business-critical platforms.
  • Promote consistent identity standards across new implementations and transformation initiatives.
  • Plan and execute cyber risk assessments for applications, platforms, integrations, vendors, and change initiatives.
  • Translate ISO 27001, NIST CSF, ISO 27005, NIS2, GDPR, and EU AI Act expectations into pragmatic controls and actions.
  • Support ISO 27001 readiness and evidence collection, including control ownership, documentation, and remediation tracking.
  • Define and maintain data protection and information classification expectations in cooperation with legal, privacy, and data stakeholders.
  • Prepare clear leadership reporting on risks, control gaps, remediation progress, compliance status, and security KPIs/KRIs.
  • Coordinate vulnerability management, penetration testing, remediation tracking, and security testing follow-up.
  • Act as escalation point for security incidents, suspected breaches, and high-risk operational events.
  • Support monitoring, alerting, incident response, and post-incident lessons learned with central and external security teams.
  • Ensure incidents and near misses are converted into practical control improvements and risk reduction actions.
  • Contribute to business continuity and resilience planning for critical applications and technology services.
  • Define cyber security requirements for external implementation partners, SaaS vendors, managed service providers, and suppliers.
  • Support security and privacy reviews for contracts, Data Processing Agreements, architecture decisions, and vendor onboarding.
  • Assess vendor security posture and ensure appropriate remediation or compensating controls where needed.
  • Embed security requirements into sourcing, implementation, and operational handover processes.
  • Monitor key supplier-related risks and escalate material exposures through governance.
  • Act as a trusted security partner to business and IT stakeholders.
  • Translate technical and regulatory security requirements into clear, business-relevant guidance.
  • Promote secure behaviors through targeted awareness, practical guidance, and role-based training.
  • Support project teams with early security input to avoid late-stage rework.
  • Balance security controls with speed, scalability, usability, and business adoption.
  • Convert the cyber security elements of the IT strategy into a concrete execution roadmap.
  • Ensure cyber security contributes to risk reduction, business continuity, regulatory readiness, and buyer-readiness.
  • Support application rationalization, vendor optimization, and cloud/SaaS governance through security input.
  • Track and report measurable improvement in cyber maturity, control effectiveness, and remediation progress.
  • Help move the organization from ad hoc security support to permanent security capability ownership.

Benefits

  • medical, dental, vision, disability, and life insurance
  • 401(k) plan
  • paid time off
  • sick leave programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service