Program Manager, Cybersecurity Operations
Sleep Number CorporationAbout the role
Company Overview
Sleep Number is a sleep wellness technology leader. For nearly four decades, we have placed sleep at the center of wellbeing, improving over 15 million lives with our Sleep Number smart beds. We are guided by our purpose – to improve the health and wellbeing of society through higher quality sleep. This is exemplified through our 4,000+ mission-driven team members who passionately innovate to drive value creation through our vertically integrated business model, owning the process from start to finish, including selling in our over 650 stores nationwide.
Our team members are encouraged to bring their whole selves to work, sharing their unique perspectives, backgrounds and skills with Sleep Number every day. Whether you are entering, returning or experienced in the workforce, we have a place for you. We hope you join us in creating the future through higher quality sleep.
Position Purpose
This individual contributor position plays a key role in shaping and maturing Sleep Number’s cybersecurity operations (“SOC”), cyber investigations, and incident response strategy by leading the Security Operations, Cyber Investigations and Incident Response capability within Sleep Number’s Information Security organization, including closely overseeing third party-managed services. This role possesses an elevated level of communication and relationship-building acumen (all audiences, including executives and non-technical stakeholders), a strong technical background, and deep field-relevant experience.
Primary Responsibilities
Develop and implement strategies to enhance the SOC's effectiveness, threat detection, and incident response capabilities with other technology teams.
Provide coaching and feedback to third party security operations staff (responsible for level 1-2) and account manager(s). Ensure KPIs are maintained. Escalate non-compliance to contractual agreement(s).
Lead development and maintenance of quality SOC playbooks (direct third-party team and contribute as needed).
In the event of a cyber incident, will execute CSIRT (Cyber Security Incident Response Team) playbooks as Cyber Incident Commander which includes adhering directly to CSIRT playbooks and navigating the event(s) with confidence which includes VP+ level executives and mobilizing cross-functional teams.
Lead cybersecurity investigations and incident handling activities and coordinate with other in-house experts based on the nature of the event, notable or incident.
Develop and conduct incident response tabletop exercises and simulations at least twice annually (may or may not include engaging a third party to conduct the exercise)
Analyze security incidents to identify root causes and recommend and/or implement corrective actions.
Develop and implement threat detection and monitoring strategies in partnership with platform owners who may reside on other teams across the company.
Communicate effectively and confidently with executive leadership (VP and above) on the status of cybersecurity operations and incidents.
Partner closely with security engineers and other technology teams to advise and help implement improvements to detections, monitoring platforms and workflow platforms.
Provide regular updates and reports to senior management and relevant stakeholders.
Drive prioritization and ownership of improvements needed in alignment with overall cybersecurity and technology strategies, make thoughtful recommendations to leadership and when required, make well-crafted pitches for resources, technologies.
Key Performance Indicators
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s