OPERATING ADVISOR – CYBERSECURITY and TECHNOLOGY
7 days ago
Tenex most commonly hires those with strong records of accomplishment driving impact across multiple settings. The Operating Advisors (OA) have a hands-on approach to working with portfolio companies, their management and IT teams, and key stakeholders to ensure disciplined execution against organizational and strategic deficiencies, which through actionable solutions the company will meet their overall goals. The OA will need to be able to make speedy, data-driven decisions, place emphasis and focus on scarce resources, and drive actions against company's largest performance improvement levers.
JOB SUMMARY:
The Cybersecurity and Technology Operating Advisor is principally responsible for leading the information security program for Tenex Capital Management and overseeing the information security programs for Tenex's portfolio companies such that all data, systems, and reputations are protected and ensuring that security strategies align with business goals. This position requires a blend of technical expertise, leadership skills, and a deep understanding of the evolving cybersecurity landscape. The Operating Advisor will also support other technological activities as directed.
KEY RESPONSIBILITIES (for both Tenex Capital Management and its Portfolio Companies)
- Incident Response
: Leads the response to security incidents and breaches, coordinates efforts to minimize damage and prevent future occurrences. Leads the development and refinement of incident response plans and participates in incident response exercises and real-world events to ensure effective containment, eradication, recovery measures and post-incident analysis. Accountable for appropriate and timely response to all Tenex and portfolio company incidents. - Security Monitoring/Analysis and Security Tool Management:
Oversees the implementation and management of security monitoring tools and processes. Promptly analyzes security events and alerts to identify then respond to potential threats and anomalies. Administers and maintains various security tools and technologies, ensuring their optimal performance and effectiveness and is the accountable point of contact for all managed security providers. - Threat Detection and Intelligence:
Stays abreast of emerging cyber threats, vulnerabilities, and attack vectors. Develops and maintains a threat intelligence program to proactively identify and mitigate potential risks. Monitors security systems and analyzes potential threats, vulnerabilities, and security incidents. Issues cybersecurity alerts when needed. - Vulnerability Management:
Conducts regular vulnerability assessments (and optionally penetration testing) to identify security weaknesses and recommend remediation strategies. Oversees the patching and hardening of systems and applications. - Security Awareness and Training:
Develops and delivers security awareness training programs to educate employees on security best practices and promotes a security-conscious culture and ensure all employees understand their roles in maintaining security. - Vendor Security Management:
Develops and implements processes for assessing and managing the security risks associated with third-party vendors and service providers. - 3rd Party Partners:
Evaluate and select appropriate 3rd party partners where needed for Tenex and its portfolio companies including cybersecurity and technology solution providers, MSPs and MSSPs. - Develop and Implement Cyber Resilience Strategies:
Responsible for designing, documenting, and implementing comprehensive cyber resilience strategies, policies, and procedures aligned with industry best practices and regulatory requirements (e.g., NIST CSF, ISO Effectively communicates cyber resilience concepts and strategies to both technical and non-technical stakeholders across Tenex and its portfolio companies and is responsible for their successful execution. - Business Continuity and Disaster Recovery Planning:
Leads the development, testing, and maintenance of business continuity plans (BCP) and disaster recovery plans (DRP) with a strong focus on cyber-related disruptions.Responsible for successful portfolio company implementation of testable plans. - Risk Assessment and Management:
Conducts security risk assessments to identify and evaluate potential threats and vulnerabilities. Develops remediation plans from the risk assessments and leads their execution until completion. Develops and implements risk mitigation strategies. Also assesses and manages risks associated with the use of Artificial Intelligence (AI). Conducts threat analyses when indicated. - Continuous Learning:
Stays current with the latest cybersecurity threats, trends, technologies, and best practices through continuous learning and professional development. - Strategic Leadership:
Develops and executes a comprehensive information security strategy aligned with the organization's business objectives and risk tolerance to ensure information assets and technologies are adequately protected. Provides strategic guidance to senior leadership including portfolio company IT leaders on security matters. - Collaboration, Communication and Reporting:
Collaborates effectively with IT teams, businesses, and external vendors on security-related matters. Defines and tracks key cyber resilience metrics, cybersecurity posture and provides regular reports to senior leadership and other stakeholders on each organization's resilience posture and improvement efforts. Effectively communicates security risks, incidents, program status and recommendations to senior leadership as well as to both technical and non-technical audiences. - Security Architecture and Implementation:
Provides security expertise and guidance in the design and implementation of IT systems and infrastructure including Artificial Intelligence (AI) to enhance their inherent resilience against cyberattacks. Evaluates and recommends security technologies and solutions and provide input into the security architecture and design of systems and infrastructure. - Security Policies and Procedures:
Develops, implements, maintains and enforces security policies, standards, and procedures in compliance with relevant regulations and industry best practices (e.g., ISO 27001, NIST Cybersecurity Framework, GDPR, HIPAA, PCI DSS, SEC Cybersecurity Rules, etc.) to safeguard the organization's information assets.
QUALIFICATIONS:
- 10 – 15+ years of Cybersecurity and IT experience, 5 years as a stand-alone leader, ideally with a track record of success in mid-sized companies with between $100 million and $2 billion of revenue.
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field required. Master's degree in Cybersecurity, Computer Science, Business Administration, or a related field highly preferred.
- Recommended industry certifications include at least one of the below:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
COMPETENCIES
- Technical Expertise
: Deep knowledge of layered security controls, network security, cloud security, endpoint protection, threat hunting, and incident response. Must be familiar with the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework to effectively respond to incidents. - Cyber Resilience
: Demonstrated track record of success in developing an organization's ability to successfully prevent, respond and recover from cyberattacks including the integration of incident response, disaster recovery and business continuity processes. - Strategic Thinking
: Ability to align cybersecurity initiatives with business objectives and risk tolerance. - Leadership & Communication
: Strong ability to lead cross-functional teams, communicate with executives, and influence organizational culture. - Risk Management
: Proficiency in conducting risk assessments, threat modeling, and managing AI-related risks. - Security Architecture
: Experience designing secure systems and infrastructure, including AI integration. - Regulatory Compliance
: Familiarity with frameworks and regulations such as NIST CSF, ISO 27001, GDPR, HIPAA, PCI DSS, and SEC rules. - Incident Response & Threat Intelligence
: Proven ability to lead investigations and develop threat intelligence programs. - Vendor Risk Management
: Experience assessing third-party security posture and managing contractual obligations.
-
Junior Cybersecurity Analyst
1 week ago
New York, New York, United States Agency Cybersecurity Full time $20 - $25Location: On-Site in Flatiron, NYCPosition Type: Hourly, Full-Time Experience Level: Entry-levelCompensation: $20-25 per hourJob Summary:As a junior cybersecurity analyst at Agency, you will be crucial in bridging the gap between technology, our customers, and our internal business operations. You will work closely with multiple stakeholders to provide...
-
Strategic Sales Executive
4 days ago
New York, New York, United States CXO Advisor Full timeAbout UsISMG is a leading B2B media and intelligence organization, serving the cybersecurity and enterprise technology space with a collaborative ecosystem of industry news, strategic education, and professional advisory services. We've recently launchedCXO Advisor, a pioneering consultative practice designed to help mid-size companies tackle their most...
-
Senior Cybersecurity Advisor, Public Sector
5 days ago
New York, New York, United States Google Full time $132,000 - $194,000Minimum qualifications:Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.5 years of experience assessing and developing cybersecurity solutions across multiple security domains.3 years of experience in cyber threat management, cyber risk management, security operations,...
-
New York, New York, United States Agency Cybersecurity Full time $40,000 - $60,000 per yearAbout Agency CybersecurityAgency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance. Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently. We're backed by top tier investors like Y...
-
Cybersecurity Management Consultant
1 week ago
New York, New York, United States Wavestone Full time $120,000 - $180,000 per yearCompany Description Wavestone is a global consulting firm with over 5,500 professionals across 17 countries, dedicated to helping organizations navigate complex business and technology challenges. We combine deep industry expertise with a comprehensive portfolio of transformation services—including business strategy, data strategy, cybersecurity, and...
-
Senior Manager, Security Engineering
1 week ago
New York, New York, United States GenuineXs - Cybersecurity Experts Full time $120,000 - $200,000 per yearPosition OverviewAs the Senior Manager of Security Engineering and Operations, you will build and manage a team of direct, indirect, and outsourced resources for the delivery of enterprise security operations services. You will provide operational leadership in the delivery of security services and the ability to adjust priorities based on changing...
-
Consultant, Cybersecurity
1 day ago
New York, New York, United States West Monroe Full timeAre you ready to make an impact?West Monroe is searching for an Experienced Consultantto join our growing Cybersecurity practice and focus on IT security advisory and solutions delivery for clients across various industries Projects may include security controls analysis, risk/compliance assessments, and/or strategy & roadmap development. This is an exciting...
-
Operations Manager, Care Advisor
5 days ago
New York, New York, United States Wayoh Full time $110,000 - $140,000 per yearInstitution:Healthcare TechnologyRole:Operations Manager, Care Advisor TeamLocation:New York City (1-2 days onsite, Gramercy)Our client, a Healthcare Technology provider, is looking to hire anOperations Managerfor their Care Advisor team. This client offers a direct-to-consumer cancer screening service that leverages MRI and Artificial Intelligence (AI) to...
-
Cybersecurity Analyst Critical Assets
1 week ago
New York, New York, United States Metropolitan Transportation Authority Full time $95,929 - $153,731 per yearJob ID: 12375Business Unit: MTA HeadquartersLocation: New York, NY, United StatesRegular/Temporary: RegularDepartment: IT Cyber SecurityDate Posted: Nov 3, 2025DescriptionJob InformationJob Title: Cybersecurity Analyst Critical Assets & Incident Response CERT Levels 3-5Salary Range: Level 3: $95,929 - $127,050Level 4: $102,760 - $139,755Level 5: $114,537 -...
-
Senior Cybersecurity Analyst
1 week ago
New York, New York, United States S-RM Full time $120,000 - $180,000 per yearSENIOR CYBERSECURITY ANALYST (SOC)US Region (Remote / Hybrid)WHO WE ARES-RM is a global intelligence and cyber security consultancy. Since 2005, we've helped some of the most demanding clients in the world solve some of their toughest information security challenges.We've been able to do this because of our outstanding people. We're committed to developing...