Cyber Risk Operations Manager

1 month ago


Other US Location Calix Full time

Calix provides the cloud, software platforms, systems and services required for communications service providers to simplify their businesses, excite their subscribers and grow their value.

We are seeking an experienced information security professional to run our new Risk Operations Center focused on operationalizing risk-based management.

This is a technical hands-on, program management role that will lead efforts in managing risk across Calix's entire attack surface, including risk-based management of vulnerabilities, insider risk and data loss detection/response, and effectively document/communicate the prioritized risk.

The hybrid nature of this role makes it ideal for candidates with strong hands-on technical skill looking to grow with more responsibilities such as ability to develop program documentation, using maturity models to grow security programs, pull data from APIs for metrics and dashboards, present briefings to leadership, collaborate and build strong relationships with other Calix teams. There are no immediate people leadership responsibilities for this role.

Responsibilities and Duties:

  • Develop and manage a comprehensive Risk Operations Center (ROC) to proactively manage risk-based prioritization and mitigation across Calix's attack surface.
  • Implement a risk-based vulnerability management program that reflects a strong understanding of the Vulnerability Management Lifecycle and industry best practices.
  • Develop playbooks using SOAR (Security Orchestration, Automation, & Response) or scripts to automate manually repetitive tasks.
  • Develop and automate repeatable etiquette for calculating, prioritizing, documenting, and communicating risk to various Calix teams and leadership.
  • Help mature the insider risk program, including the development of strategies, security tool configuration and tuning, and automation opportunities to deter, detect, and respond to insider risks and data loss.
  • Conduct investigations and analysis to identify and resolve insider risk alerts and potential data loss, including reviewing logs and network activity, analyzing user behavior, and forensic investigations.
  • Work closely with Legal, Privacy, and HR teams to provide support for e-discovery requests, including data collection, preservation, processing, and review, while ensuring confidentiality and discreet resolution of investigations.
  • Drive continuous improvements by staying current on industry trends and best practices in vulnerability management, insider risk, and other risk operations functions and adapt the programs accordingly.
  • Interface and coordinate with third-party DFIR partners.
  • Orchestrate technical tabletop exercises to help identify risks to our incident response and detection capabilities.
  • Develop and maintain documentation for ROC, insider threat, and vulnerability management programs including standards, processes, procedures.
  • Prepare and present formal and informal analysis and briefings to relevant stakeholders and executives.
  • Assist in developing business cases and project plans to implement new capabilities or mature existing toolsets for continual maturity of ROC.

Qualifications:

  • Required: Bachelor's degree in information systems, Computer Science or similar
  • 10+ years of experience in hands-on information security roles, preferably with 2-3 years in either Insider Risk or Vulnerability Management.
  • Hands-on technical demonstrated experience with security related technologies such as SIEM (Security Information and Event Management), SOAR (Security Orchestration, Automation, & Response), EDR (Endpoint Detection and Response), UEBA (User & Entity Behavior Analytics), DLP (Data Loss Prevention).
  • Hands-on investigation analysis and incident response of security alerts and incidents.
  • Familiarity with insider risk and data loss investigations.
  • Strong knowledge of methodologies and technologies in modern risk-prioritized vulnerability management programs.
  • Ability to communicate risk effectively while conveying highly technical concepts to both technical and non-technical stakeholders.
  • Familiarity with security reporting, dashboarding, and metrics.

Preferred Qualifications:

  • Relevant certifications such as CISSP (Certified Information Systems Security Professional), CISM, CRISC, or Insider Threat Program Manager (ITPM) are highly desirable.
  • Familiarity with unified vulnerability tools
  • Experience in an Insider Risk, Vulnerability Management, Incident Response, or similar role
  • Familiarity with FAIR methodology

#Remote-LI

Compensation will vary based on geographical location (see below) within the United States. Individual pay is determined by the candidate's location of residence and multiple factors, including job-related skills, experience, and education.

For more information on our benefits click here.

There are different ranges applied to specific locations. The average base pay range (or OTE range for sales) in the U.S. for the position is listed below.

San Francisco Bay Area Only:

145, ,600.00 USD Annual

National Major Cities plus, CA, CO, NY Metro area:

126, ,100.00 USD Annual

Regional plus NY:

113, ,100.00 USD Annual



  • Other US Location Bitsight Technologies Full time

    Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss.Built on over a decade of technological...


  • Other US Location Arctic Wolf Full time

    Arctic Wolf, with its unicorn valuation, is the leader in security operations in an exciting and fast-growing industry—cybersecurity. We have won countless awards for our excellence in security operations and remain dedicated to providing an industry-leading customer and employee experience.Our mission is simple: End Cyber Risk. We're looking for a...


  • Other US Location Eaton Full time

    Eaton's Corporate Sector division is currently seeking a Manager Enterprise Risk Management Assurance. As an Enterprise Risk Management Assurance position, this person plans, organizes and directs the daily activities of internal audits and advisory engagements of the Enterprise Risk Management (ERM) risks and special projects to evaluate the effectiveness...


  • Other US Location Castleton Commodities International Full time

    Castleton Commodities International, a leading commodity trading and investment firm with headquarters in Stamford, CT is recruiting for an Insurance Risk Management professional. This role sits within the Treasury team and is responsible for managing the Company's portfolio of insurance coverage and maintaining relationships with its global...

  • Risk Mitigation Lead

    2 months ago


    Other US Location Block Full time

    Company DescriptionIt all started with an idea at Block in 2013. Initially built to take the pain out of peer-to-peer payments, Cash App has gone from a simple product with a single purpose to a dynamic ecosystem, developing unique financial products, including Afterpay/Clearpay, to provide a better way to send, spend, invest, borrow and save to our 47...


  • Other US Location Proofpoint Full time

    It's fun to work in a company where people truly BELIEVE in what they're doingWe're committed to bringing passion and customer focus to the business.Corporate Overview Proofpoint is a leading cybersecurity company protecting organizations' greatest assets and biggest risks: vulnerabilities in people. With an integrated suite of cloud-based solutions,...


  • Other US Location Fiserv Full time

    Calling all innovators – find your future at Fiserv.We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants, and consumers to one another millions of times a day – quickly, reliably, and securely. Any time you swipe your credit card,...

  • Senior Manager

    2 months ago


    Other US Location Allianz Full time

    Let's care for tomorrow.Your ambitions. Your dreams. Your tomorrow.At Allianz Commercial (AzC), we are the global leader for insuring corporate and specialty risks in the Allianz Group. Whether it's aircraft, satellites, the world's biggest ships and tallest building, cyber-attacks, or climate change impacts, AzC has the major risks covered when it comes to...


  • Other US Location CNA Full time

    You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.Individual contributor responsible for the overall risk control...

  • Site Manager

    2 months ago


    Other US Location Diné Development Corporation Full time

    Job Summary:NOVA-Dine is seeking a Program Manager to oversee and lead an IT and telecommunications team providing enterprise support at Picatinny Arsenal, NJ. The Program Manager will provide oversight across a broad spectrum of services from network, technical support, cyber security, IT operations, telecommunications, and Land Mobile Radio. The Program...


  • Other US Location Arete Full time

    SUMMARYThe Client Success Manager III (CSM III) is an integral part of the Managed Services team acting as one of the primary client interfaces and is the client advocate for service delivery. The CSM III adds value to their customers by serving as their advocate, always keeping an open line of communication to ensure a successful operational experience. The...


  • Other US Location GSK Full time

    The Operations Oversight Manager will critically review new and existing business processes to determine the need for and adequacy of key internal controls and be responsible for upward communication and reporting on the control framework. This role will provide both strategic and tactical insight to Commercial Operations teams as it relates to commercial...


  • Other US Location Rockwell Automation Full time

    Rockwell Automation is a global technology leader focused on helping the world's manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale,...


  • Other US Location Group 1001 Full time

    Group 1001 is a consumer-centric, technology-driven family of insurance companies on a mission to deliver outstanding value and operational performance by combining financial strength and stability with deep insurance expertise and a can-do culture. Group1001's culture emphasizes the importance of collaboration, communication, core business focus, risk...


  • Other US Location Proofpoint Full time

    It's fun to work in a company where people truly BELIEVE in what they're doingWe're committed to bringing passion and customer focus to the business.Corporate OverviewProofpoint is a leading cybersecurity company protecting organizations' greatest assets and biggest risks: vulnerabilities in people. With an integrated suite of cloud-based solutions,...

  • Senior Sales Engineer

    2 months ago


    Other US Location Arctic Wolf Full time

    Arctic Wolf, with its unicorn valuation, is the leader in security operations in an exciting and fast-growing industry-cybersecurity. We have won countless awards for our excellence in security operations and remain dedicated to providing an industry-leading customer and employee experience.Our mission is simple: End Cyber Risk. We're looking for an in...


  • Other US Location NCR Corporation Full time

    About NCR VOYIXNCR VOYIX Corporation (NYSE: VYX) is a leading global provider of digital commerce solutions for the retail, restaurant and banking industries. NCR VOYIX is headquartered in Atlanta, Georgia, with approximately 16,000 employees in 35 countries across the globe. For nearly 140 years, we have been the global leader in consumer transaction...


  • Other US Location Azenta Life Sciences Full time

    Azenta Inc.At Azenta, new ideas, new technologies and new ways of thinking are driving our future. Our customer focused culture encourages employees to embrace innovation and challenge the status quo with novel thinking and collaborative work relationships.All we accomplish is grounded in our core values of Customer Focus, Achievement, Accountability,...


  • Other US Location Green Thumb Full time

    The Role The Market Manager, Operational Compliance provides leadership over the Retail and Production compliance program including appropriate direction, oversight and support for all compliance functions and integration of compliance activities across Maryland. Responsibilities include ensuring all laws, regulations, and standards set by regulatory bodies,...


  • Other US Location Picus Security Full time

    Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so, read onAbout PicusPicus Security is a place where exceptional people gather to do their best work. We convert new ideas to exceptional solutions and great customer experiences. Bring passion and dedication to your job and there's no telling...