Manager / Senior Manager, Cybersecurity & Risk

Other Jobs To Apply

<h5><strong>Manager / Senior Manager, Cybersecurity & Risk</strong></h5> <p><strong>Status: </strong>Full-Time / Permanent<strong><br>Location:</strong> Remote<br><strong>Department:</strong> Information Technology<br><strong>Reports To:</strong> Director, Infrastructure & Operations<br><strong>Salary:</strong> $125,000-$150,000 per year, dependent on skillset and experience</p> <h5><strong>Position Summary</strong></h5> <p>SavATree is seeking a highly capable, hands-on cybersecurity leader to help strengthen and mature our enterprise cybersecurity program as the company continues to scale. This role will serve as the enterprise lead responsible for cybersecurity operations, risk management, policy development, incident readiness, and security architecture across a distributed, field-based organization.<br><br>Reporting to the Director, Infrastructure & Operations, this highly visible individual contributor role will partner closely across IT and the business to strengthen cybersecurity capabilities, reduce enterprise risk, and improve overall security posture. The role will work across infrastructure, applications, cloud, identity, data, and third-party environments to help ensure scalable and resilient cybersecurity practices.<br><br>The ideal candidate is technically strong, pragmatic, and comfortable operating in a lean environment where they will both define and help execute cybersecurity priorities. This individual must be capable of operating independently, influencing across teams, and helping build scalable cybersecurity capabilities that balance risk reduction with business enablement.</p> <h5><strong>Key Responsibilities</strong></h5> <h5>Cybersecurity Operations & Technical Leadership</h5> <ul> <li>Serve as the enterprise cybersecurity lead responsible for cybersecurity operations and risk management across infrastructure, endpoints, identity, cloud, applications, data, and third-party environments.</li> <li>Partner closely with Infrastructure & Operations to strengthen endpoint security, vulnerability management, patching, identity and access management, logging, monitoring, and incident detection and response capabilities.</li> <li>Provide technical cybersecurity leadership across Microsoft, cloud, SaaS, and enterprise platforms to improve overall security posture.</li> <li>Partner with enterprise application teams to ensure secure architecture, integrations, and data practices across core business platforms, including Microsoft technologies and enterprise applications.</li> <li>Lead cybersecurity incident response coordination, tabletop exercises, root cause analysis, and remediation planning.</li> <li>Evaluate emerging threats and recommend pragmatic, risk-based mitigation strategies aligned to business priorities.</li> <li>Monitor and assess cybersecurity posture across internal and third-party environments.</li> </ul> <h5>Cybersecurity Program Development</h5> <ul> <li>Help define and mature enterprise cybersecurity capabilities, operating processes, and governance appropriate for a growing organization.</li> <li>Develop and maintain cybersecurity policies, standards, procedures, and best practices.</li> <li>Build and maintain a practical cybersecurity roadmap focused on risk reduction, resiliency, and operational effectiveness.</li> <li>Establish cybersecurity metrics, scorecards, and reporting for IT leadership and executive stakeholders.</li> <li>Conduct risk assessments and partner with teams to prioritize remediation activities.</li> <li>Support security awareness and training initiatives.</li> </ul> <h5>Governance, Risk & Compliance</h5> <ul> <li>Support enterprise cybersecurity governance practices, including access controls, vendor risk management, data protection, and security awareness.</li> <li>Partner with stakeholders on cybersecurity-related audits, customer questionnaires, cyber insurance requirements, and compliance activities.</li> <li>Help mature incident response, disaster recovery, and business continuity capabilities.</li> <li>Establish practical, scalable controls appropriate for a fast-paced, growth-oriented organization.</li> </ul> <h5>Vendor & Partner Management</h5> <ul> <li>Serve as the primary point of coordination for cybersecurity vendors, MSSPs, penetration testing firms, and external security partners.</li> <li>Drive accountability, service quality, and measurable outcomes across third-party providers.</li> <li>Partner with Infrastructure & Operations leadership to establish cybersecurity priorities, remediation plans, and operational governance.</li> <li>Evaluate cybersecurity tools and recommend solutions aligned to business needs and organizational maturity.</li> <li>Establish a strong cybersecurity operating foundation and improve organizational resiliency through pragmatic controls and risk reduction.</li> <li>Improve visibility into cybersecurity risk through meaningful metrics and reporting.</li> <li>Enhance foundational controls across identity, endpoint security, vulnerability management, monitoring, and incident response.</li> <li>Establish practical cybersecurity policies, standards, and operating procedures.</li> <li>Strengthen vendor oversight and improve effectiveness across security partners.</li> <li>Develop a practical multi-year cybersecurity roadmap aligned to business priorities and company growth.</li> </ul> <h5><strong>Required Experience</strong></h5> <ul> <li>7+ years of progressive cybersecurity experience with increasing responsibility.</li> <li>Experience operating as a senior cybersecurity individual contributor or technical leader in a mid-sized enterprise environment.</li> <li>Strong technical understanding across IAM, EDR, vulnerability management, SIEM, Microsoft Security, Azure security, infrastructure/network security, incident response, and security architecture.</li> <li>Experience developing cybersecurity policies, standards, and procedures.</li> <li>Experience managing third-party cybersecurity vendors and managed service providers.</li> <li>Strong communication skills with the ability to explain technical risks in business-friendly language.</li> </ul> <h5><strong>Preferred Experience</strong></h5> <ul> <li>Experience in private equity-backed, multi-site, field-service, or distributed operations environments.</li> <li>Experience supporting geographically dispersed or branch-based organizations.</li> <li>Experience with Microsoft technologies including Azure, Microsoft 365, Defender, Intune, and Entra ID.</li> <li>Relevant certifications such as CISSP, CISM, Security+, Azure Security Engineer, or similar.</li> <li>Self-starter who operates independently and drives outcomes</li> <li>Technically credible and hands-on</li> <li>Builder mentality with comfort creating structure in a lean environment</li> <li>Pragmatic, business-minded, and execution-oriented</li> <li>Strong collaborator who can influence across teams without direct authority</li> <li>Strong sense of ownership and accountability</li> </ul>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...