Director Cybersecurity

Be part of the team that drives our company forward, transforming ideas into real-world tools and platforms that support the business and spur innovation.

North Haven, CT


<p><strong>At Connection, our purpose is simple: we connect people with technology. From hardware&mdash;PCs, printers, servers, and more&mdash;to cutting-edge cloud, cybersecurity, and professional IT services, we design, build, and support the IT solutions that thousands of companies, schools, and government agencies rely on every day. We like to think of ourselves as the IT Department for our customers&rsquo; IT Department. Our company started out almost 40 years ago with two employees and a phone line. Today we&rsquo;re a Fortune 1000 IT solutions partner operating in 174 countries around the world&mdash;still driven by that startup mentality and guided by our original purpose.</strong></p>

keywords: position summary,position details,security,teamwork,risk management,support,reporting,analysis,compliance,experience,knowledge,education,certification

Full Time

$130,000.00/Yr. - $150,000.00/Yr.

Overview: <p>Connection has a fantastic opportunity working for a financial organization in North Haven, CT for an AVP. This is a full-time direct hire opportunity, offering a robust array of benefits to support your success. Enjoy strong benefits including a generous 401K matching program. Join us as we journey together toward personal and professional fulfillment.</p> <p>As the AVP Cybersecurity, you will be responsible for safeguarding the organization's information systems and data assets. You will play a key role in implementing and maintaining security measures to protect against cyber threats, ensuring the confidentiality, integrity, and availability of their systems. Oversees audits and evaluations of the cybersecurity environment. Manages the planning, documentation, testing, integration, and execution of cybersecurity projects including annual budgeting and coordination of vendor responsibilities.</p>
Responsibilities: <ul> <li>Deliver on cybersecurity initiatives at the credit union. Coordinates with internal teams and external vendors to ensure the cybersecurity resilience of the credit union is tested frequently.</li> <li>Stakeholder Collaboration: Collaborate with internal and external stakeholders, such as customs authorities, shipping partners, and regulatory bodies, to ensure security standards and trade compliance.</li> <li>Security Policies: Establish and enforce security policies, procedures, and guidelines to protect digital assets, sensitive trade data, and intellectual property.</li> <li>Risk Management: Conduct regular risk assessments and vulnerability scans to identify and address potential risks and develop risk mitigation plans to safeguard the organization against cyber threats and vulnerabilities. Be responsible for the business fraud investigation and mitigation.</li> <li>Incident Response: Create and maintain an effective incident response plan, ensuring timely and efficient recovery from security breaches and disruptions.</li> <li>Incident Investigation and Forensics: Carry out thorough research and investigation on security incidents. Work with internal teams and external vendors to conduct research and forensics.</li> <li>Regulatory Compliance: Ensure compliance with all related regulatory bodies.</li> <li>Security Awareness: Develop and oversee a security awareness program to educate employees, members, and stakeholders about best practices in cybersecurity.</li> <li>Vendor Security: Evaluate and monitor the security practices of third-party vendors, partners, and service providers.</li> <li>Conduct risk assessments, analyze security controls, and provide recommendations for improvements.</li> <li>Assist in the development and maintenance of our Risk Management Framework processes and documentation.</li> <li>Collaborate with the internal teams and external vendors to assess, document, and authorize information systems using the RMF.</li> <li>Develop and implement information security policies, procedures, and standards.</li> <li>Monitor and defend our systems against cyber threats. Provide incident detection, analysis, and response, helping to improve our overall security posture.</li> <li>Participate in conducting regular vulnerability assessments and penetration tests on our IT infrastructure, applications, and networks.</li> <li>Provide support in identifying vulnerabilities, reporting findings, and assisting with remediation efforts.</li> <li>Provide support in analyzing security incidents and breaches. Monitor security logs and respond to security incidents in a timely manner.</li> <li>Proactively search for threats and vulnerabilities within our environment. Conduct incident handling and coordination, ensuring a rapid and effective response to security events.</li> <li>Ensure that all cybersecurity activities are conducted in accordance with government policies, standards, and requirements relevant to national security systems.</li> <li>Collaborate with IT and development teams to integrate security measures into the design and implementation of systems.</li> <li>Maintain accurate records of all activities, including findings, actions taken, and recommendations for improvement.</li> <li>Contribute to the development of reports and documentation related to cybersecurity exercises.</li> <li>Stay informed about the latest security threats, technologies, trends and best practices.</li> <li>Conduct security awareness training for employees.</li> <li>Design and implement security controls for networks, systems, and applications.</li> <li>Reporting: Provide regular reports and updates to executive management and the board of directors on the state of cybersecurity and compliance.</li> </ul>
Requirements: <ul> <li>Bachelor's or Master's degree in Information Security, Computer Science, or equivalent and appropriate work experience.</li> <li>Industry-recognized certifications, such as CISSP, CISM, or CISA.</li> <li>Proficiency of threat/vulnerability analysis, penetration testing, and red-team/blue-team exercises.</li> <li>Proven experience as an Information Security Engineer or similar role.</li> <li>Strong knowledge of information security principles and best practices.</li> <li>Experience with security technologies, including firewalls, IDS/IPS, antivirus, and encryption.</li> <li>Familiarity with security frameworks and compliance standards (e.g., ISO 27001, NIST, GDPR).</li> <li>Hands-on experience with security tools and technologies.&nbsp;</li> <li>Proven experience in a leadership role in information security, with at least 5-8 years of relevant experience.</li> <li>In-depth knowledge of cybersecurity technologies, tools, and best practices.</li> <li>Experience with artificial intelligence (AI) and machine learning (ML) security.</li> <li>Experience with DevOps and security automation.</li> <li>Experience with security awareness training and education.</li> <li>Experience evaluating and managing cyber risk and working within industry-standard frameworks</li> <li>Knowledgeable of methodologies such as Cyber Kill Chain and Diamond Model of Intrusion Analysis models.</li> <li>Experience with cloud computing, networks, servers, operating systems and PCs is mandatory.</li> </ul> <br /><br /> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Min</h2> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text">USD $130,000.00/Yr.</div> </div> </div> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Max</h2> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text">USD $150,000.00/Yr.</div> </div> </div>