IT Cybersecurity & Compliance Manager
Escondido On-site
Salary not listedJobFig found this opening at its original source and checks that it remains available.
About the role
This role is responsible for coordinating day-to-day program execution, maintaining core controls and evidence, supporting cybersecurity and compliance initiatives, and partnering with internal IT teams, business stakeholders, vendors, and consultants to reduce risk while enabling business operations. This is a hands-on manager role for an early-to-mid level cybersecurity and compliance leader. The role does not have direct reports, but will manage vendor and consultant relationships, coordinate cross-functional work, and mentor aspiring cybersecurity and compliance talent within the IT Operations team through a dotted-line partnership.
What you'll bring
- At least 3 to 5 years of experience in cybersecurity, information security, compliance, IT risk management, security operations, or a closely related IT discipline.
- Practical experience supporting at least one cybersecurity or compliance framework, such as NIST Cybersecurity Framework, NIST SP 800-171, CMMC, CIS Controls, ISO 27001, or equivalent.
- Experience coordinating audits, assessments, evidence collection, control testing, vulnerability remediation, or security program initiatives.
- Experience working with cybersecurity tools, managed security providers, consultants, or external assessors.
- Working knowledge of identity and access management, endpoint security, vulnerability management, security monitoring, incident response, Microsoft 365 security, Entra ID, and cloud security concepts.
- Strong written and verbal communication skills, including the ability to explain security and compliance topics to technical and non-technical audiences.
- Strong organization, follow-through, judgment, discretion, and ability to manage competing priorities.
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
- Relevant certifications such as Security+, CySA+, SSCP, GSEC, CISM, CISSP, CRISC, Certified CMMC Professional, Certified CMMC Assessor, or equivalent.
- Experience with Microsoft Defender, Purview, Sentinel, Intune, Azure security services, or similar platforms.
- Experience developing cybersecurity awareness communications, training content, dashboards, scorecards, or leadership reporting.
- Experience in construction, engineering, manufacturing, government contracting, or other distributed operations environments.