Summary
The Manager, IT Security leads daily cybersecurity operations, overseeing security monitoring, incident response, vulnerability management, and identity security programs. This role partners with the Director of IT Security to transform strategic initiatives into operational plans, measurable outcomes, and high-quality security services. The position manages and develops a team of security professionals, collaborates with stakeholders across the organization, and drives continuous improvement in security processes, compliance readiness, and risk management. Ideal candidates are experienced security leaders who excel at protecting critical systems, mentoring teams, and strengthening organizational cybersecurity in a complex, regulated environment.
Moving operations to BCM requires replacing some practices and technologies - e.g., MS Teams will have an impact on legacy THI end users. The Manager will optimize security technologies across THI / BCM negotiating favorable cost to absorb THI into BCM footprint. Working with the Director, the Manager will manage budgeted operational spend for team, including outsourced Security Operations Center (SOC). The Leader will need to have solid communication skills as they may be called on to present updates to executives, stakeholders, faculty/staff as relates to project or incident status.
This Leader will conduct performance assessments and will support professional development for subordinates (and corrective action as needed). This position will coordinate project work of subordinates with broader IT Security team. Additionally, this Manager will lead Cyber Security Incident Response Teams (CSIRT) when the College is defending against cyber-attacks often coordinating efforts across team of 15-20.
Distinguished candidates will have experience in Security, Incident Response, Networking, Server Admin, IT Architecture, Controls authoring/auditing, Vulnerability Management, red/blue teaming, exposure for formal GRC platforms, experience working across matrixed teams, familiarity with formal project management structures. Familiarity with regulatory standards HIPAA, FERPA, GLBA, and GDPR highly desired. Additionally, advanced Excel and/or basic Power BI skills will be extremely helpful. Individual will serve as deputy to Information Security Office (ISO) when ISO is unavailable or needs to delegate authority.
Job Duties
- Leads daily cybersecurity operations, assigning and overseeing incident response, vulnerability remediation, threat monitoring, and security projects to ensure timely and effective service delivery.
- Directs cyber incident investigations and recovery efforts, maintains response playbooks, and drives lessons learned and process improvements.
- Oversees security monitoring tools, vulnerability management programs, and remediation activities across enterprise systems, networks, identities, and cloud environments.
- Develops operational procedures, performance metrics, security documentation, and status reporting to measure and improve program effectiveness.
- Partners with IT, compliance, privacy, legal, research, and clinical stakeholders to support risk assessments, audits, and regulatory compliance efforts.
- Provides leadership, coaching, mentoring, and performance management for security engineers, analysts, and other assigned staff.
- Manages security vendors, contracts, budgets, technology renewals, and continuous improvement initiatives for assigned security services.
- Serves as an operational leader for enterprise cybersecurity, safeguarding critical systems, data, and business operations in a highly regulated environment.
- Performs other job-related duties as assigned.
Minimum Qualifications
- Bachelor’s degree or four years of relevant experience may substitute for degree requirement.
- Five years of relevant experience.
Preferred Qualifications and Skills
- GIAC Security Essentials (GSEC), CISM — ISACA Certified Information Security Manager, CISSP — (ISC)²
Work Authorization Requirement:
This position is not eligible for visa sponsorship. Candidates must be legally authorized to work in the United States at the time of application and throughout the duration of employment.
Baylor College of Medicine is an Equal Opportunity/Affirmative Action/Equal Access Employer.