Jobs and Careers
SO

Manager, Cybersecurity Engineering

SoundExchange
Washington, United Statesfull_timeVerifiedPosted 7 May 2024

About the role

About SoundExchange

Since forming in 2003, we have established ourselves as the premier music tech organization with a mission of building a fairer, simpler, and creator‐focused industry. Through a combination of proprietary solutions, emphasis on data, and advocacy efforts, SoundExchange works with 3,600+ digital service providers to collect and distribute digital performance royalties – more than $10 billion – on behalf of over 650,000 creators and rights owners. 

Title: Manager, Cybersecurity Engineering 
Department: ITOps 
Job Location: Washington, DC or anywhere (Continental US)
Reports To: Senior Director, ITOps 
Supervisory Role: Yes
FLSA Status: Exempt

Position Summary:

Are you passionate about cybersecurity and motivated to lead a team that secures networks and technology in the music industry? We’re looking for an experienced Manager of Cybersecurity Engineering to support the end-to-end security of our infrastructure, endpoints, and applications. This is an ideal role for anyone who enjoys being a hands-on technical leader and continuous learning. You will be a member of IT Ops Leadership and report to the Senior Director of IT Ops. For DC-area applicants, this is a hybrid role, in-office once per week and as required for customer support and quarterly company onsite events. Remote applicants will be required to travel to the DC office for quarterly company onsite events at minimum.

Essential Functions:

  • Lead the Cybersecurity team of cybersecurity engineers responsible for securing SoundExchange infrastructure.
  • Stay current with known and emerging threats to determine, mitigate, and remediate risks against SoundExchange’s assets and infrastructure.
  • Ensure SoundExchange’s assets are effectively managed and monitored to meet security policies, standards, and criteria.
  • Maintain industry compliance with NIST Cybersecurity Framework guidelines.
  • Align with IT Ops leadership on the creation, maintenance, governance, and communication of security policies and standards across the technical environment.
  • Oversee the end-to-end security of our platforms, networks, and systems, provide risk analysis, implementation guidance and ensure that SoundExchange’s processes and solutions are securely maintained and that the confidentiality, integrity and availability of the company assets is always protected.
  • Update and enforce security policies, standards and plans to ensure the protection of corporate data against unauthorized use, access, modification, and destruction. Promote user awareness and ensure company-wide adherence with defined standards.
  • Assist in identifying, remediating, and mitigating vulnerabilities in our platforms, cloud environments, networks, and systems, perform forensic analyses and risk assessments, and ensure timely, appropriate, coordinated, properly communicated and contained incident responses.
  • Maintain, implement, and support incremental and full backups and restorations of network and cloud resources according to backup and data retention policies, disaster recovery plans, and business continuity plans.
  • Ensure that our users are sufficiently trained on the application of our security tools, practices, and policies, and properly and timely informed of the cybersecurity threats and risks that we face as a company.
  • Ensure that proper security logs are generated and sent to our outside monitoring vendors
  • Coordinate security audits and penetration tests and implement/coordinate remediation efforts as required.
  • Create, review, and present reports, position papers, assessment recaps to team, and other IT Ops leaders.
  • Interact with internal teams and external vendors on security-related requirements, projects, issues, and operational tasks.

Required Knowledge, Skills, Abilities (KSAs):

  • Expertise with incident response, assessing and managing security risks, threats, and vulnerabilities.
  • Experience working with security-related systems such as firewalls, IPS, IDS and web filters.
  • Experience with analyzing security event logs from Windows, UNIX, IPS, network and remote access solutions.
  • Experience with a mixed set of Windows, MacOS and Linux endpoints.
  • Experience with AWS is a must. Azure and Oracle Cloud experience is also desired.
  • Proficiency in creating conceptual, logical, and physical security diagrams.
  • Detailed understanding of TCP/IP and related communication protocols, Windows authentication mechanisms (Kerberos, NTLM, AD), networking technologies, software defined computing, containerization, routing and switching, and risk analysis and risk management me

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

SoundExchange

View company profile →