IT Security Manager, Incident Response & Vulnerability Management
Overview
As the IT Security Manager at Baylor College of Medicine, you will lead daily cybersecurity operations, overseeing incident response, vulnerability management, and identity security programs for a large healthcare and research organization. You'll partner with the Director of IT Security to transform strategic initiatives into operational plans and measurable outcomes, managing a team of security engineers and analysts. This role also serves as deputy to the Information Security Office, coordinating incident response efforts across a team of 15-20 during cyber-attacks, and managing security vendors and budgets. You'll have a direct impact on the college's security posture in a highly regulated environment, with opportunities to mentor staff and drive continuous improvement.
What You'll Do9
- 1Lead daily cybersecurity operations, assigning and overseeing incident response, vulnerability remediation, and threat monitoring with SIEM and EDR tools.
- 2Direct cyber incident investigations and recovery efforts, maintaining response playbooks and driving lessons learned to improve CSIRT effectiveness.
- 3Oversee vulnerability management programs across enterprise systems, networks, and cloud environments, coordinating remediation with IT teams.
- 4Develop operational procedures, performance metrics, and security documentation to measure program effectiveness and support compliance audits.
- 5Partner with IT, compliance, privacy, and legal stakeholders to support risk assessments and regulatory compliance (HIPAA, FERPA, GLBA, GDPR).
- 6Lead and mentor a team of security engineers and analysts, conducting performance assessments and supporting professional development.
- 7Manage security vendors, contracts, and budgets, optimizing spend on outsourced SOC and security technologies during THI integration.
- 8Serve as operational leader for Cyber Security Incident Response during attacks, coordinating efforts across a team of 15-20.
- 9Present security updates and incident status to executives and stakeholders, ensuring clear communication and alignment across the organization.
Requirements9
- 15+ years of experience in cybersecurity, with a focus on incident response, vulnerability management, and security operations.
- 2Bachelor's degree in a relevant field or 4+ years of experience may substitute for the degree.
- 3Experience leading or managing a team of security professionals in a complex, regulated environment.
- 4Hands-on experience with security monitoring tools, SIEM platforms, and EDR solutions.
- 5Knowledge of regulatory standards: HIPAA, FERPA, GLBA, and GDPR.
- 6Familiarity with formal project management structures and ability to coordinate cross-functional projects.
- 7Strong communication skills, including presenting to executives and stakeholders on security matters.
- 8Preferred certifications: CISSP, CISM, or GSEC.
- 9Advanced skills in Excel and/or Power BI for security metrics reporting.
Salary Insight
$139 - $164k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Belcan, LLC
VerifiedCybersecurity Operations & Communications Lead
Own the security operations and communications strategy for a global enterprise, coordinating incident response across SIEM, SOAR, and EDR platforms. You lead a team of analysts, manage threat intelligence feeds, and craft executive-level briefings. This role sits at the intersection of technical operations and stakeholder communication, reporting directly to the CISO. You will drive the adoption of MITRE ATT&CK framework and NIST guidelines, shaping the organization's cyber resilience.
Health Care Service Corp.
VerifiedSr. Director Security Operations Center
HCSC seeks a Sr. Director leading the Cyber Fusion Center to deliver SLA driven cyber threat detection and escalation processes. The role ensures operational effectiveness within governance standards while collaborating with leadership to strengthen security posture.
Catholic Charities of Baltimore
VerifiedDirector IT Security & Technology Catholic Charities of Baltimore
Catholic Charities of Baltimore seeks a Director IT & Security to lead cybersecurity strategy protecting agency data while aligning with business goals. This hybrid role offers 3 days in office 2 days remote overseeing IT functions and compliance committees.
Pfizer
VerifiedThreat Remediation Lead Analyst, Cyber Defense
You will lead day-to-day threat remediation at Pfizer, owning the execution of remediation activities to protect digital assets across on-prem, cloud, and hybrid environments. Collaborating with the SOC, Cloud Services, and Engineering, you will coordinate efforts across threat detection, incident response, and vulnerability management to reduce exposure. Reporting to the Senior Manager, Threat Remediation, you will track progress, validate completion, and drive continuous improvement. This role stands out for its direct impact on regulatory compliance and security posture in a global pharmaceutical leader.
00100 LEIDOS, INC.
VerifiedCyber Infrastructure Support Lead 50-60 chars
Lead a team to enhance enterprise IT reliability performance and security across Windows and Linux platforms. Drive system improvements while maintaining compliance and mentoring staff. This role offers unique opportunities to shape security architecture and lead impactful initiatives.
Concert Golf Partners
VerifiedSenior Cybersecurity Manager, Enterprise Security Operations
You will own the daily operation and health of Concert Golf Partners' enterprise security platform across 40+ premier golf clubs. You will run EDR, SIEM, email security, and vulnerability management tools at scale, reporting to the VP of IT. You will set operating standards and lead technical initiatives with limited oversight. This role offers the chance to shape security operations for a multi-site enterprise, with travel to club locations.