Senior Manager of Cyber Security

Turtle and HughesClark, NJ
$120,000 - $140,000Hybrid

About The Position

The Sr. Manager of Cyber Security is a hands-on technical manager responsible for executing and managing Turtle’s day-to-day cybersecurity operations, program compliance, and team performance. Reporting to the Chief Technology and Information Security Officer (CTISO), this role bridges tactical security operations with programmatic oversight—actively working within security toolsets, leading incident response, managing the organization’s Managed Security Service Provider (MSSP) relationship, and owning the compliance posture across ISO 27001, NIST CMMC Level 2, and the organization’s aspirational ISO 9001 program. The Director leads a team with dedicated coverage across Governance, Risk, and Compliance (GRC) and technical security operations, and drives continuous improvement across people, process, and technology. This is a USA based position. The Director of Cyber Security is expected to travel to the Corporate headquarters in Clark, NJ as needed, approximately 1–2 times per quarter. Additional travel to USA branch locations will be required on occasion. The role requires availability for after-hours response in the event of a security incident.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field; equivalent work experience strongly considered in lieu of degree.
  • 5–7 years of progressive, hands-on cybersecurity experience, with at least 2 years in a leadership or team management capacity.
  • Demonstrated hands-on experience administering and operating security technologies including SIEM, EDR/XDR, vulnerability management platforms, and MFA/identity protection.
  • Working knowledge of and operational experience with ISO 27001 and NIST frameworks (CMMC Level 2 / SP 800-171); direct experience owning or managing compliance to these standards is required.
  • Experience managing MSSPs and security technology vendors, including SLA oversight, performance management, and contract review.
  • Proven ability to lead incident response end-to-end
  • Experience directing or working within a GRC function; familiarity with audit coordination, risk register management, and nonconformance processes.
  • Familiarity with Good Documentation Practices (GDP) and quality management framework alignment (ISO 9001 exposure a plus).
  • Familiarity with AI governance frameworks and emerging AI risk principles; ability to assess AI tools for security, data privacy, and compliance implications in an enterprise context.

Nice To Haves

  • Relevant certifications are not required, but are beneficial to the candidate, including CISSP, CISM, or relevant GIAC certifications.

Responsibilities

  • Manage the organization’s security operations function, serving as a hands-on practitioner across the security toolset; accountable for threat monitoring, vulnerability management, and incident response from detection through post-incident review.
  • Maintain and continuously improve security controls and tooling configurations across endpoint, network, email, and identity environments, in coordination with the MSSP and technical staff.
  • Own the phishing simulation program and enforce associated security policies, coordinating outcomes with HR and department management as required.
  • Support and manage the MSSP relationship end-to-end; direct day-to-day service activities, hold the provider accountable to SLAs, and ensure threat detection and incident escalation protocols meet organizational requirements.
  • Manage security vendor relationships across the technology portfolio and oversee the vendor risk register.
  • Enforce the organization’s compliance posture for ISO 27001 and NIST CMMC Level 2; direct the GRC function across evidence maintenance, risk register management, policy governance, and audit readiness.
  • Provide framework ownership for the organization’s ISO 9001 program; owns the GDP framework alignment and cross-functional coordination, while operational teams retain ownership of document content and process definitions.
  • Ensure all internal and external audit activity is effective through the GRC Program Manager, for nonconformance tracking, root-cause analysis, and findings closure.
  • Represent Cyber Security’s independent role in Turtle’s three-party AI governance model, serving as the security and risk voice alongside the CTO (AI strategy, budget, and vendor governance) and Data Services & Enterprise Architecture (AI roadmap execution) to evaluate, approve, and monitor AI tool adoption across the organization.
  • Own the AI security risk function, including model and data leak security across AI platforms, shadow AI detection and unsanctioned LLM governance, third party AI vendor risk assessments, and enforcement of AI acceptable use policy for all deployed systems.
  • Lead, develop, and retain the cybersecurity team; establish operating cadences, manage performance, and define training and certification roadmaps aligned to role requirements.
  • Define and report team KPIs covering security posture, compliance status, and program health to the CTISO; serve as the primary escalation point and cross-functional liaison for cybersecurity matters across the organization.
  • Own the Security Awareness Training program—including onboarding, annual refreshers, role-based content, and phishing simulations—track outcomes and enforce policy requirements in coordination with HR and department managers.

Benefits

  • 401(k) plan
  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Paid holidays
  • Vacation
  • Employee negotiated discounts
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service