Cybersecurity Manager

Posted 1 hour ago USD 170,000 - 192,000 / year
Spencer Fane LLP

JOB TITLE: Cybersecurity Manager

FLSA STATUS: Exempt

SCHEDULE: M-F, 40 hrs./week

LOCATION: Any Spencer Fane Office Location

REPORTS TO: IT Security Director


POSITION SUMMARY:

Under direction of the IT Security Director, the Cybersecurity Manager leads the firm's cybersecurity operations, providing technical leadership across security engineering, architecture, incident response, and security platforms. The position oversees cybersecurity personnel and external service providers, directs the implementation and effectiveness of security controls, and partners with IT and business stakeholders to integrate security into the firm's technology environment. The role is accountable for operational security performance, incident response readiness, and the delivery of cybersecurity initiatives that protect firm systems and data.


COMPENSATION: At Spencer Fane, we carefully consider a wide range of factors when determining compensation, including but not limited to location, skillset, experience, training, licenses, certifications and other business or organizational needs. Compensation will be determined based on the above factors along with the requirements of the position. The salary range for this position will vary depending on location as shown below.


SALARY RANGE BY LOCATION:

Birmingham, AL; Hendersonville, TN; Kansas City, MO; Las Vegas, NV; Miami, FL; Nashville, TN; New Orleans, LA; Overland Park, KS; Palm Beach, Fl; Phoenix, AZ; Salt Lake City, UT; St. Cloud, MN; St. Louis-Clayton, MO; Tampa, FL; Tulsa, OK: $155,000.00 - $175,000.00

Austin, TX; Chicago, IL; Dallas, TX; Denver, CO; Galveston, TX; Houston, TX; Minneapolis, MN; Plano, TX; Sacramento, CA; Westlake Village, CA: $170,000.00 - $192,000.00

Bentonville, AR; Cape Girardeau, MO; Dakota Dunes, SD; Fayetteville, AR; Greenville, SC; Jefferson City, MO; Oklahoma City, OK; Omaha, NE; Santa Fe, NM; Springfield, MO; St. George, UT; Tallahassee, FL; Wichita, KS: $142,500.00 - $160,500.00

Santa Monica, CA; Washington, DC: $185,000.00 - $210,000.00

New York, NY; San Francisco, CA; San Jose, CA: $200,000.00 - $227,500.00


BENEFITS: Medical, Vision, Dental, PTO, 401k, Life, Disability


PRIMARY RESPONSIBILITIES:

Cybersecurity Operations Leadership

  • Lead daily cybersecurity operations, workload prioritization, escalations, and service delivery.
  • Supervise cybersecurity personnel, including assignments, coaching, cross-training, and performance management.
  • Establish documented ownership, procedures, metrics, service expectations, and backup coverage.


Incident Response and Resilience

  • Lead technical investigation, containment, eradication, recovery, and post-incident improvement.
  • Coordinate response activities with IT, Legal, Communications, firm leadership, and external providers.
  • Maintain and test incident-response plans, playbooks, escalation paths, and tabletop exercises.


Security Engineering and Architecture

  • Lead security reviews for network, endpoint, identity, cloud, data, AI, and business technologies.
  • Translate business requirements and security risks into practical technical designs and standards.
  • Validate access, integrations, logging, monitoring, segmentation, data protection, and recovery controls.


Security Platform Oversight

  • Maintain operational accountability for network, endpoint, identity, email, cloud, and privileged-access controls.
  • Ensure security platforms are properly configured, integrated, monitored, documented, and supported.
  • Monitor platform health, security coverage, service performance, and remediation of control gaps.


Security Transformation and Project Delivery

  • Lead cybersecurity initiatives from design through implementation, testing, transition, and measurement.
  • Manage scope, milestones, dependencies, risks, rollback plans, and stakeholder communications.
  • Build sustainable processes that reduce reliance on individuals, other IT teams, and external providers.


Detection and Vulnerability Management

  • Oversee vulnerability identification, validation, prioritization, remediation, exceptions, and reporting.
  • Direct development and tuning of security detections, alerts, use cases, and response playbooks.
  • Use incidents, testing, intelligence, and operational data to identify security improvements.


AI and Emerging Technology Security

  • Lead technical security assessments for AI platforms, agents, integrations, automation, and emerging technologies.
  • Evaluate permissions, data access, third-party connections, production impact, logging, and monitoring.
  • Translate governance requirements into practical technical safeguards and operating standards.


Vendor and Managed-Service Oversight

  • Manage operational relationships with security monitoring, incident-response, testing, and engineering providers.
  • Define responsibilities, service expectations, escalation procedures, deliverables, and performance measures.
  • Validate vendor work while retaining internal ownership of security decisions and operational knowledge.


Metrics and Reporting

  • Establish operational metrics for incidents, alerts, vulnerabilities, platforms, projects, and service performance.
  • Maintain dashboards and provide concise operational updates to the IT Security Director.
  • Identify recurring issues, control gaps, performance concerns, and improvement opportunities.


GRC, Audit, and Client Support

  • Provide technical evidence, control documentation, and subject-matter support to designated GRC personnel.
  • Support audits and client assessments through technical validation, evidence collection, and remediation.
  • Implement approved policies and escalate compliance concerns or control exceptions appropriately.


QUALIFICATIONS:

Requirements

  • Bachelor's degree in cybersecurity, information technology, computer science, or a related field preferred. In lieu of a degree, at least five years of directly relevant cybersecurity experience — gained at an organization with a minimum of 2,000 users and/or $500M in annual revenue — managing enterprise security operations, security engineering, architecture, or incident response.
  • Eight years of progressive IT and/or cybersecurity experience, including at least three years managing enterprise cybersecurity operations across network, endpoint, identity, cloud, and email security environments, with responsibility for security engineering, architecture, vulnerability management, and threat detection. At least three years must have been gained within a highly regulated industry — law firm experience preferred, or equivalent (e.g., healthcare, financial services, government).


Management & Oversight

  • At least three years of direct supervisory experience managing cybersecurity professionals, including workload prioritization, performance management, technical development, and operational coverage.
  • At least three years of experience directly managing managed security service providers (MSSPs) and third-party cybersecurity vendors, including responsibility for service-level performance, incident escalations, technical deliverables, and remediation of service deficiencies.
  • Security Budgeting, Capital Budget Planning and vendor financial contract management are a plus.


Technical Leadership

  • Demonstrated experience leading cybersecurity initiatives from technical design and implementation through testing and transition into ongoing operations, coordinating internal technical teams and cross-functional stakeholders.
  • Direct experience serving as technical lead during significant cybersecurity incidents — such as ransomware attacks, account compromises, unauthorized access, or data exfiltration — including directing investigations, containment, eradication, recovery, and post-incident corrective actions.


EXPERIENCE, SKILLS & COMPETENCIES:

  • Security Architecture & Engineering: Advanced knowledge of enterprise security architecture, engineering principles, and technical controls across network, endpoint, identity, cloud, email, and privileged-access environments. Capable of evaluating technical designs, validating security requirements, and identifying vulnerabilities and control deficiencies across interconnected systems.
  • Security Operations & Platform Management: Comprehensive understanding of enterprise security platforms, including endpoint detection and response (EDR), security information and event management (SIEM), identity and access management (IAM), privileged access management (PAM), and vulnerability management solutions. Technical knowledge of security platform integration, automation, and API-based connectivity, with the ability to evaluate platform configurations, monitoring coverage, operational effectiveness, and remediation requirements.
  • Incident Response & Threat Management: Advanced technical knowledge of incident investigation, threat detection, containment, eradication, and recovery procedures. Capable of directing technical response activities, evaluating threat intelligence and security telemetry, coordinating incident escalations, and identifying improvements to detection capabilities and response procedures.
  • Vulnerability Management & Risk Assessment: Expertise in evaluating vulnerabilities, assessing exploitability and potential business impact, prioritizing remediation, and validating corrective actions. Skilled in translating technical security risks into actionable remediation plans while balancing operational requirements and business priorities.
  • Technical Leadership & Decision-Making: Advanced technical judgment in evaluating security architecture, resolving complex cybersecurity issues, establishing operational priorities, and directing technical teams during critical incidents. Capable of assessing competing technical solutions, identifying implementation risks, and making informed decisions involving security effectiveness, operational resilience, and business continuity.
  • People Leadership & Development: Proven ability to manage cybersecurity professionals across multiple technical disciplines, establish clear performance expectations, evaluate technical capabilities, develop staff, and maintain operational accountability. Skilled in organizing team responsibilities, establishing escalation procedures, and developing processes that reduce reliance on individual personnel or external providers.
  • Cybersecurity Project Delivery: Skilled in managing cybersecurity implementations involving multiple security technologies, infrastructure dependencies, and cross-functional stakeholders. Capable of evaluating technical requirements, coordinating implementation activities, managing project risks, validating security controls, and ensuring successful transition into ongoing operations.
  • Vendor & Managed-Service Management: Ability to evaluate the technical performance of external security providers, establish service expectations and escalation procedures, validate security monitoring and incident-response deliverables, and address service deficiencies while maintaining internal accountability for cybersecurity operations.
  • AI & Emerging Technology Security: Knowledge of cybersecurity risks associated with AI platforms, automated agents, third-party integrations, and emerging enterprise technologies. Capable of evaluating access permissions, data exposure, system integrations, logging, and monitoring requirements to identify and implement appropriate technical safeguards.
  • Analytical & Problem-Solving Skills: Advanced analytical and troubleshooting capabilities to investigate complex cybersecurity incidents, evaluate security telemetry, identify systemic control weaknesses, and determine effective technical solutions. Sound judgment in prioritizing remediation activities based on security exposure, operational impact, and available resources.
  • Communication & Business Partnership: Skilled in communicating complex cybersecurity risks, technical findings, incident developments, and remediation recommendations to technical teams, business stakeholders, and senior leadership. Capable of coordinating cross-functional response activities, resolving competing operational priorities, and integrating security requirements into enterprise technology initiatives.


PREFERRED TECHNICAL EXPERIENCE AND CERTIFICATIONS:

  • Hands-on experience administering, implementing, or integrating one or more enterprise security platforms, including Microsoft security technologies, Palo Alto Networks, and CrowdStrike.
  • Experience developing security automation through scripting, APIs, and integrations between enterprise security platforms.
  • Experience implementing technical security controls for enterprise AI platforms, automated agents, and third-party AI integrations.
  • Professional certifications such as CISSP, CISM, GIAC, or relevant Microsoft, Palo Alto Networks, or CrowdStrike certifications.
  • Cybersecurity experience within legal services or other highly regulated, data-sensitive industries.


WORKING CONDITIONS:

  • Work is performed in a professional office or approved remote environment with regular interaction across the firm.
  • After-hours availability may be required for incidents, critical maintenance, or major implementations.
  • Occasional travel to firm offices, vendor meetings, conferences, or training may be required.


PHYSICAL REQUIREMENTS:

  • Ability to use computers and review detailed technical information for extended periods.
  • Ability to communicate effectively through written, verbal, and electronic methods.
  • Ability to occasionally lift equipment weighing up to 20 pounds and travel as required.


DISCLAIMER:

The above statements describe the general nature and level of work performed by individuals assigned to this position. They are not intended to be an exhaustive list of all duties, responsibilities, qualifications, or working conditions.

Login to Apply Now

Recommended Jobs