Overview:
If you’re looking for a purpose and not just a job, join the Smoothie King team and turn your purpose into a fulfilling passion!
We're not just the pioneers of the nutritional smoothie; we're the champions of inspiring people to live a healthy and active lifestyle. With over 1300 stores and counting, we’ve grown to become the largest nutritional smoothie bar in the nation, with a simple recipe for success: Hire the best people, use the best ingredients, and blend with a purpose.
At Smoothie King, we're serious about our clean ingredients and passionate about our guests' health and wellness journeys—but that doesn't mean we don't know how to have a good time. Here, you'll find work that's equal parts challenging and rewarding, all within a culture that's as amazing as our smoothies. We're committed to continuous improvement, achieving our goals, and fostering a supportive and collaborative environment where every team member can thrive.
General Overview:
The Manager, Cybersecurity is responsible for the day-to-day leadership and execution of Smoothie King’s cybersecurity program and security operations. This role independently assesses risk, establishes priorities, recommends appropriate courses of action, and drives security issues through remediation and closure.
The role requires sufficient technical depth to evaluate security findings, telemetry, vulnerabilities, architecture, and control gaps; provide informed direction to technical teams and vendors; and balance immediate risk reduction with longer-term program maturity.
Essential Functions:
- Own the identification, prioritization, remediation, validation, and closure of cybersecurity risks and findings, prioritizing immediate risk reduction while maintaining disciplined scope.
- Execute and continuously improve cybersecurity strategy, standards, policies, and procedures in alignment with business objectives and established risk tolerance.
- Provide technical and operational security leadership across Azure, identity, endpoint, network, infrastructure, vulnerability management, and security monitoring.
- Evaluate cybersecurity risk, determine appropriate courses of action, and escalate material risks with clear recommendations.
- Lead cybersecurity incident response and oversee SOC and managed security partners through investigation, containment, remediation, recovery, and corrective action.
- Lead cybersecurity compliance and assurance activities, including PCI DSS, security assessments, penetration testing, and remediation of identified gaps.
- Partner with technology and business teams to integrate appropriate security controls without unnecessarily impeding delivery.
- Manage cybersecurity vendors, third-party risk activities, and assigned budgets, holding partners accountable for performance and outcomes.
- Develop and communicate cybersecurity KPIs, risk metrics, material risks, and recommendations to leadership.
- Lead cybersecurity awareness initiatives and drive security projects to measurable outcomes with clear ownership and timelines.
- Stay current on emerging threats and technologies and translate relevant developments into practical security improvements.
Major Responsibilities / Specific Requirements:
- Strong understanding of cybersecurity frameworks and risk management practices, including NIST, CIS Controls, ISO 27001, and PCI DSS.
- Strong technical knowledge across Azure/Entra ID, identity, endpoint, network, vulnerability management, logging, monitoring, and threat detection.
- Ability to independently assess security findings, telemetry, attack paths, vulnerabilities, and control gaps.
- Strong risk-based judgment and bias for action, including the ability to make timely decisions under ambiguity, prioritize remediation, and escalate material risks with clear recommendations.
- Demonstrated experience leading incident response, vulnerability remediation, security assessments, penetration testing, and audit activities through closure.
- Experience managing cybersecurity vendors, SOC providers, third-party risk, budgets, and resources.
- Strong people leadership, execution discipline, and ability to drive multiple initiatives to measurable outcomes.
- Strong written and verbal communication skills with the ability to translate technical issues into clear business risk and recommendations.
- Ability to constructively challenge technical teams, vendors, and assumptions while maintaining effective cross-functional relationships.
- Proactive, accountable mindset focused on measurable risk reduction and operational execution.
- Education and Experience
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
- Seven or more years of progressive cybersecurity experience, including at least three years leading security operations, programs, significant initiatives, or teams.
- Demonstrated experience across security operations, incident response, vulnerability management, identity, endpoint, network and cloud security, security monitoring, and compliance.
- Experience working with SOC/MSSP providers, security vendors, auditors, penetration testing firms, and cross-functional technology teams.
- Experience in retail, restaurant, franchise, or another distributed multi-location environment is preferred.
- Relevant certifications such as CISSP, CISM, CCSP, Microsoft Security, or GIAC are preferred.
Education and Experience Requirements:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
- Seven or more years of progressive cybersecurity experience, including at least three years leading security operations, programs, significant initiatives, or teams.
- Demonstrated experience across security operations, incident response, vulnerability management, identity, endpoint, network and cloud security, security monitoring, and compliance.
- Experience working with SOC/MSSP providers, security vendors, auditors, penetration testing firms, and cross-functional technology teams.
- Experience in retail, restaurant, franchise, or another distributed multi-location environment is preferred.
- Relevant certifications such as CISSP, CISM, CCSP, Microsoft Security, or GIAC are preferred.
What We Offer:
Join our team and enjoy an unusually fun work environment with an upbeat atmosphere and great team members. It is our purpose to maintain an environment our team members can brag about, where our focus and belief are built on our core values: We Are Better Together, We Keep Evolving, We Live Our Mission, We Do the Right Thing, and We Focus and Finish. With our core values at the forefront of every decision we make, it allows for collaboration, passion, and a no-limits mindset when it comes to your future! We keep our team happy with our great benefits package, free smoothies, flexible work schedules, office lunches and parties, monthly fitness challenges, free gym access, and more fun activities to make Smoothie King a happy and healthy place to work.
Our Mission
Inspire people to live a healthy and active lifestyle.
Our Vision
We make the world a better place by nourishing healthy habits.
At Smoothie King, when we say inspire people, we mean everyone. We champion a diverse and inclusive workforce that is representative of the guests we serve. We blend the unique members of our organization, celebrating what is both common and different to grow better together and Rule the Day. The foundation of our diversity efforts is closely tied to our core values, which includes “We Are Better Together” and “We Do the Right Thing”. We are proud to be an equal opportunity employer and consider all qualified candidates, without regard to race, color, religion, sex, national origin, ancestry, age, genetic information, sexual orientation, gender identity, marital or family status, veteran status, or medical condition or disability. If you are a person with a disability and you need assistance in applying for a position with Smoothie King, please call our People Services Department at 214-935-8900 and direct assistance will be provided.