Cybersecurity Program Manager

🔥 7 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Alaska Power & Telephone Company

Alaska Power & Telephone Company

51 - 200 employees

Founded 1957

⚡ Energy

📡 Telecommunications

💰 $33M Grant - Alaska Power and Telephone on 2022-09

Energy • Telecommunications

Alaska Power & Telephone Company (AP&T) is an employee-owned utility providing power, broadband internet, and landline telephone services to over 40 remote Alaskan communities across 1,100 linear miles since 1957. AP&T operates fiber and microwave networks delivering up to 2. 5 Gbps to homes and businesses, and generates roughly 75% of its energy from renewable hydropower, supporting sustainable initiatives like heat pump and EV electrification. The company offers customer tools (SmartHub), live webcams, outage reporting, and business services, and actively invests in local community programs and energy incentives.

📋 Description

• Maintain, administer, and continuously improve AP&T's cybersecurity program. • Develop, update, and maintain cybersecurity policies, procedures, standards, and supporting documentation. • Track cybersecurity initiatives, remediation efforts, and program objectives. • Support alignment with recognized frameworks and best practices, including NIST Cybersecurity Framework (CSF), CIS Controls, and CISA Cybersecurity Performance Goals. • Prepare reports, metrics, and risk summaries for leadership. • Monitor security alerts, events, and system activity across the organization's technology environment. • Investigate and respond to cybersecurity incidents and suspicious activity. • Maintain secure configurations and cybersecurity tools. • Coordinate with internal teams and external vendors to address identified security concerns. • Support endpoint, network, email, and cloud security initiatives. • Conduct and coordinate vulnerability scanning activities. • Analyze findings and prioritize remediation based on business risk. • Track corrective actions through completion. • Monitor patch management and system hardening efforts. • Participate in external security assessments, penetration testing, and remediation planning. • Administer and oversee access control processes. • Support privileged access management and least-privilege security practices. • Manage multifactor authentication (MFA) and identity security controls. • Conduct user access reviews and ensure appropriate account management practices. • Maintain incident response plans, procedures, and supporting documentation. • Coordinate cybersecurity event response activities. • Facilitate incident response exercises and tabletop simulations. • Support disaster recovery, business continuity, and backup validation activities. • Assist in post-incident reviews and corrective action planning. • Identify, assess, document, and track cybersecurity risks. • Support audits, compliance reviews, and cybersecurity assessments. • Review third-party and vendor cybersecurity practices. • Assist with cyber insurance submissions, questionnaires, and related requirements. • Maintain evidence and documentation supporting compliance activities. • Support cybersecurity practices across information technology, telecommunications, and operational technology environments. • Assist in securing distributed systems supporting utility and broadband operations. • Coordinate security efforts involving critical infrastructure and field operations technologies. • Support cybersecurity requirements for remote and rural operational environments. • Lead employee cybersecurity awareness and education efforts. • Coordinate phishing awareness campaigns and training activities. • Promote cybersecurity best practices throughout the organization. • Foster a culture of shared responsibility for information security.

🎯 Requirements

• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; or Equivalent combination of education, training, certifications, and relevant professional experience. • Minimum of five (5) years of hands-on experience in information technology, systems administration, network administration, infrastructure management, cybersecurity, or related technical disciplines. • Minimum of three (3) years of cybersecurity-related experience. • Experience with: Security operations, Network security, System administration, Endpoint protection and endpoint detection and response (EDR), Identity and access management (IAM), Vulnerability management, Backup and recovery solutions, Incident response and investigations. • Experience developing policies, procedures, incident reports, risk assessments, and technical documentation. • Ability to communicate effectively with both technical and non-technical stakeholders. • Ability to manage sensitive and confidential information with discretion and sound judgment. • Proven ability to coordinate remediation efforts and drive issues to resolution. • Current cybersecurity certification preferred, including but not limited to: CompTIA Security+, CompTIA CySA+, ISC² SSCP, ISC² CISSP, ISACA CISM, GIAC GSEC, GIAC GCIH, GIAC GICSP, ISA/IEC 62443 Certification. • Equivalent industry-recognized cybersecurity certification. • Candidates with significant relevant experience who do not currently hold a certification may be considered but will be expected to obtain an approved certification within 6-12 months of hire. • Working knowledge of: NIST Cybersecurity Framework (NIST CSF), CIS Critical Security Controls, CISA Cybersecurity Performance Goals (CPGs), Security Operations Center (SOC) practices, Incident response lifecycle, Vulnerability management, Least privilege and access control, Multifactor authentication (MFA), Endpoint security, Email security, Security logging and monitoring, Backup and disaster recovery best practices.

🏖️ Benefits

• Employee-owned company through our ESOP program • Opportunity to secure critical infrastructure serving Alaska communities • Collaborative and mission-driven culture • Professional development and certification support • Competitive compensation and comprehensive benefits • Meaningful work with visible impact

Apply Now

Similar Jobs

🔥 15 minutes ago

dataSpring Inc.

51 - 200

🤝 B2B

📣 Marketing

☁️ SaaS

Senior AI Security Engineer at DataSpring securing AI-driven technology in healthcare. Leading security lifecycle for AI systems and ensuring compliance with regulations.

AWS

Azure

Cloud

Google Cloud Platform

🔥 1 hour ago

Alight Solutions

10,000+ employees

🤝 B2B

🏥 Healthcare

☁️ SaaS

Lead security and controls for AI adoption at Alight, focusing on AI governance and risk management. Collaborate with engineering and security teams to ensure safe AI systems implementation.

🇺🇸 United States – Remote

💵 $140k - $180k / year

💰 $22.5M Post-IPO Secondary - Alight Solutions on 2023-08

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

Cloud

Cyber Security

🔥 15 hours ago

KBR, Inc.

10,000+ employees

💼 Consulting

🎖️ Defense

📦 Logistics

Cybersecurity Architect designing and implementing secure enterprise architectures aligned with RMF standards for U.S. Department of War and Government software programs.

Azure

Cloud

Cyber Security

🕒 Yesterday

rockITdata

11 - 50

🤖 Artificial Intelligence

💼 Consulting

Security Control Assessor supporting federal healthcare modernization initiatives with cybersecurity assessment and authorization activities. Collaborating with stakeholders to meet federal security requirements.

Cyber Security

🕒 2 days ago

AECOM

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Transit Safety Security Specialist coordinating risk management projects across the U.S. at AECOM, delivering safety and security solutions for public transportation systems.