22nd Century Technologies, Inc. logo

Cybersecurity Manager

22nd Century Technologies, Inc.

  • Saint Paul, MN
  • 2 days ago

    Highlights

    The Cybersecurity Manager leads daily security operations, overseeing Security Operations Center (SOC) monitoring, threat detection, and incident response while maintaining current procedures and response plans. Estimate Start Date: November 1, 2026 End Date: October 31, 2027 # of Hours Per Week 40 Work Location/Type: Remote with Quarterly on-site Narrative Description of Position:

    Numbers & Facts

    LocationSaint Paul, MN
    IndustryComputer/IT Services
    Company Size100 to 499 employees
    Year Founded1997
    Websitehttps://www.tscti.com/careers-0

    Description

    POSITION TITLE: IS Cybersecurity Manager
    Estimate Start Date: November 1, 2026
    End Date: October 31, 2027
    # of Hours Per Week 40
    Work Location/Type: Remote with Quarterly on-site
    Narrative Description of Position:
    The Cybersecurity Manager leads daily security operations, overseeing Security Operations Center (SOC) monitoring, threat detection, and incident response while maintaining current procedures and response plans. The role develops and updates cybersecurity standards, manages risk and vulnerability programs, supports audits and compliance, reviews vendor and access security, and directs security awareness efforts. They also provide regular reporting and strategic guidance to the CISO on program status, roadmap, and resource needs.

    Specifications of Position:
    Consultant will provide SOC Manager and Cybersecurity Manager services to the Metropolitan Council (the "Council "). Consultant will work under the direction of the Council's Chief Information Security Officer (CISO) or their designee. The Council keeps final decision-making authority over policy, budget, risk acceptance, and personnel matters.
    Duties and Responsibilities
    Consultant shall:
    1. SOC Operations: Manage daily Security Operations Center (SOC) operations and monitoring. Coordinate the work of Council security staff and keep SOC procedures and playbooks current.
    2. Threat Detection: Oversee monitoring across SIEM, EDR, network, email, identity, and cloud tools. Tune detections and perform threat hunting.
    3. Incident Response: Lead incident response under the Council's Cyber Incident Response Plan. Deliver incident reports and root cause analyses.
    4. Governance and Policy: Develop and update cybersecurity standards aligned with [NIST CSF / CIS Controls], and submit them for Council approval as needed.
    5. Risk and Vulnerability Management: Conduct risk assessments and help maintain the risk register. Manage vulnerability scanning, penetration testing coordination, and tracking of remediation. Recommend risk treatment to the CISO.
    6. Compliance and Audit: Assess whether controls meet applicable requirements. Support audits and track findings through to closure.
    7. Vendor and Access Oversight: Perform security reviews of vendors. Oversee access reviews, privileged access, and multi-factor authentication (MFA).
    8. Security Awareness: Manage security awareness training and phishing simulations.
    9. Reporting and Advisory: Report security metrics and program status to the CISO. Advise on the security roadmap, budget, and staffing needs.
    Performance Expectations
    Consultant shall:
    • Triage incidents within Service Levels.
    • Notify the CISO of Critical or High incidents.
    • Track vulnerabilities through remediation, or through formal risk acceptance by the Council.
    • Complete policy reviews and risk assessments.
    • Deliver reports and deliverables on the agreed schedule.
    • Handle all Council data according to the Minnesota Government Data Practices Act (Minn. Stat. Ch. 13) and Council security and data handling policies.
    • Give incident response priority over program activities during active security incidents.
    Specifications Descriptions of Specifications
    MINIMUM SPECIFICATION REQUIREMENTS: Must have to be accepted for consideration for this position.
    Level of Education B.S. or B.A. Degree
    Years of experience Five + years of experience in a Cyber Security
    Certification(s) CMMC Certificate
    Cyber Compliance experience Experience with compliance audits against CJIS, FTI, HIPAA and PCI
    Experience in Governance and Policy Experience creating and updating cybersecurity policies and standards aligned with NIST CSF / CIS Controls
    DESIRED SPECIFICATIONS: Not required, but desire experience in these specifications for this position.
    Communications Requirements Experience in the development of end user documentation.
    Work Environment Working independently and/or in a team environment may be required for some engagements.

    All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

    About Company

    22nd Century Technologies, Inc., is one of the fastest growing IT Service Integrator and Workforce Solution companies in the United States. Founded in 1997, 22nd Century Technologies is a Certified National Minority Business Enterprise with 6,000+ people including 600+ Cyber SMEs nationwide supporting our customers in all 50 states, Canada, and Mexico. With HQs in Somerset, NJ and Mclean, VA, 22nd Century has 14 offices throughout the United States. As part of our unrelenting focus on quality and compliance, 22nd Century Technologies’ delivery is based on Certified Matured Processes including CMMI L3 Dev & SVC, ISO 20000, ISO 27001, and ISO 9001 quality processes. With a strong focus on the public sector, 22nd Century currently holds government contracts with 14 out of 15 Federal Executive agencies including DoD, 37 other Federal agencies, 50 States, 115+ Local agencies, and 37 School Districts. In the last three years, we have expanded our services to Fortune 500 and other commercial clients and currently support 80+ commercial clients.

    Recognized among “Best Company to Work For” by Forbes, 22nd Century Technologies, Inc., consistently exceeds our clients’ expectations by focusing on their absolute satisfaction with jobs while keeping our employees motivated.

    All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

    Similar Jobs

    See more jobs