Back to search
MODEC America, Inc. Linkedin · Posted 5d ago

IT Cybersecurity Manager

Houston, Texas, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

The IT Cybersecurity Manager is responsible for leading MODEC's cybersecurity program, strategy, governance, and operational security initiatives across the global enterprise. This role develops and executes a comprehensive cybersecurity roadmap that aligns business objectives, regulatory requirements, and industry best practices. The manager serves as a strategic advisor to IT leadership and business stakeholders, ensuring the confidentiality, integrity, and availability of MODEC's information systems, cloud services, and digital assets. The position oversees security operations, risk management, vulnerability management, incident response, security architecture, awareness programs, and compliance initiatives while driving continuous improvement of the organization's cybersecurity maturity. The role partners closely with global IT teams, business leaders, vendors, and external partners to establish a resilient cybersecurity posture and ensure security is embedded in technology, operational, and business processes.


DUTIES AND RESPONSIBILITIES:


Cybersecurity Leadership & Governance

  • Develop, maintain, and execute MODEC's cybersecurity strategy, roadmap, and security governance framework.
  • Establish security policies, standards, procedures, and controls aligned with NIST Cybersecurity Framework (CSF), ISO 27001, CIS Controls, and applicable regulatory requirements.
  • Provide strategic guidance to executive leadership regarding cybersecurity risks, emerging threats, and recommended mitigation strategies.
  • Lead cybersecurity program maturity initiatives and continuous improvement efforts across the organization.
  • Develop and maintain cybersecurity metrics, KPIs and KRIs, including dashboards and executive reporting to track program maturity and risk exposure over time.

Risk Management & Compliance

  • Conduct enterprise security risk assessments and facilitate remediation planning.
  • Lead cybersecurity audits, assessments, and compliance activities.
  • Identify, assess, prioritize, and communicate cyber risks to senior leadership.
  • Ensure security controls are implemented and operating effectively.
  • Support third-party risk management, vendor security reviews, and technology acquisition processes.
  • Maintain awareness of evolving regulatory requirements, security standards, and industry best practices.
  • Own or coordinate data privacy compliance requirements (e.g., GDPR, LGPD where applicable), ensuring legal and regulatory data protection obligations are identified and met.
  • Maintain a comprehensive inventory of IT assets, software, and data repositories to support risk-based decision-making.

Security Operations

  • Oversee security monitoring, threat detection, vulnerability management, and incident response activities.
  • Lead investigations into cybersecurity incidents and coordinate containment, remediation, recovery, and post-incident reviews.
  • Ensure effective operation of security technologies including:
  • SIEM platforms
  • Endpoint Detection & Response (EDR)
  • Identity and Access Management (IAM)
  • Multi-Factor Authentication (MFA)
  • Email Security
  • Security Awareness Platforms
  • Vulnerability Management Solutions
  • Network Security and Firewalls
  • Cloud Security Controls
  • Ensure timely remediation of vulnerabilities and management of cybersecurity risks.
  • Manage contracts, SLAs and performance of Security Service Providers and Tools, including renewal cycles, licensing and vendor performance reviews.

Security Architecture & Technology

  • Collaborate with infrastructure, cloud, application, and operational technology teams to ensure security-by-design principles are incorporated into solutions.
  • Evaluate and recommend new cybersecurity technologies, tools, and services.
  • Provide architectural guidance for cloud platforms, SaaS applications, networks, endpoints, and identity solutions.
  • Support implementation of Zero Trust security principles and modern security architectures.
  • Establish and oversee application security practices, including secure software development lifecycle (SDLC), code review standards and application vulnerability testing with risk-based.

Business Continuity & Resilience

  • Support cybersecurity aspects of business continuity, disaster recovery, and crisis management programs.
  • Participate in tabletop exercises and incident response simulations.
  • Ensure appropriate recovery processes exist for cyber-related disruptions.

Security Awareness & Training

  • Develop and maintain security awareness and training programs.
  • Foster a security-conscious culture across the organization.
  • Ensure employees understand their security responsibilities through ongoing education and communications.

Leadership & Team Development

  • Lead, mentor, and develop cybersecurity personnel.
  • Manage performance, training, and career development of team members.
  • Foster collaboration across global IT and business teams.
  • Manage cybersecurity projects and initiatives within budget and schedule expectations.


QUALIFICATIONS & EXPERIENCE:


  • Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or related field.
  • 8+ years of cybersecurity experience.
  • 5+ years of cybersecurity leadership or management experience.
  • Experience developing and managing enterprise cybersecurity programs.
  • Experience with cloud security technologies and modern security architectures.
  • Experience leading incident response, vulnerability management, and risk management activities.
  • Experience managing cybersecurity tools, vendors, and service providers.
  • Experience working within global and geographically distributed environments.


Preferred Certifications:

  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CISA (Certified Information Systems Auditor)
  • CCSP (Certified Cloud Security Professional)
  • CRISC (Certified in Risk and Information Systems Control)
  • GIAC Certifications
  • TOGAF or SABSA
  • Security+
  • Azure Security Engineer Associate
  • Microsoft Cybersecurity Architect Expert


Technical Knowledge


Strong understanding of:

  • NIST Cybersecurity Framework (CSF)
  • NIST 800-53
  • ISO 27001/27002
  • CIS Critical Security Controls
  • Zero Trust Architecture
  • Security Operations Centers (SOC)
  • Incident Response
  • Vulnerability Management
  • Identity & Access Management
  • Cloud Security (Azure, AWS, Microsoft 365)
  • Endpoint Security
  • Network Security
  • Data Protection and Data Loss Prevention
  • Operational Technology (OT) Security


MODEC America, Inc. is an Equal Opportunity Employer.


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search