Full-Time

Information Security Manager

Deadline 8/1/27
Wisconsin Foundation & Alumni Association

Wisconsin Foundation & Alumni Association

No salary listed

Madison, WI, USA

Hybrid

Two days on-site per week required in Madison, WI.

Category
IT & Security (1)
Required Skills
Vulnerability Analysis
Risk Management
Penetration Testing
Requirements
  • Bachelor’s degree in Information Technology, Computer Science, or relevant experience that provides equivalent knowledge, skills, or abilities.
  • 7 + years of progressive experience in cybersecurity, security engineering, or a related field.
  • 3 + years of experience directly managing or leading technical security teams, including hiring, performance management, and staff development.
  • 5 + years of hands-on experience with enterprise security tools and technologies, including SIEM, EDR, IDS/IPS, firewalls, and endpoint protection platforms.
  • 5 + years of experience with security architecture, incident response, vulnerability management, and compliance programs.
  • Experience managing relationships with Managed Detection & Response (MDR) providers, security vendors, and other third-party security partners.
  • Demonstrated experience leading cross-functional security projects using established project management methodologies.
  • Demonstrated success driving security process improvements, automation, or operational optimization initiatives.
  • Familiarity with regulatory frameworks and compliance standards including HIPAA, PCI-DSS, and NIST.
  • Deep understanding of cybersecurity principles, protocols, architecture, and best practices.
  • Proven ability to lead, motivate, and develop technical security teams.
  • Strong understanding of regulatory frameworks, compliance standards, and enterprise risk.
  • Excellent analytical, problem-solving, and decision-making skills, with the ability to prioritize competing demands.
  • Ability to work under pressure and manage multiple complex initiatives simultaneously.
  • Strong communication, interpersonal, and stakeholder management skills, including the ability to present to senior leadership.
  • Ability to design, document, and maintain effective procedures, processes, and automations.
  • Capable of maintaining a high degree of confidentiality and responsibility regarding information related to WFAA and any affiliate organizations.
  • Energetic, motivated, service-oriented, and able to effectively manage multiple competing priorities.
  • Flexible to new situations and challenges, and an advocate for change.
  • Experience implementing or managing AI-enabled security operations, security automation frameworks, or SOAR platforms.
  • Ability to lead cross-functional projects using lightweight project management practices.
  • Ability to understand business needs and balance usability and security.
Responsibilities
  • Lead and oversee the compliance with regulatory frameworks and internal policy requirements including HIPAA, PCI-DSS, and NIST.
  • Ensure consistent application of security patches, vulnerability remediation, access controls, and configuration hardening across endpoints, servers, cloud workloads, and network environments.
  • Lead and oversee vulnerability management efforts, risk assessments, and compliance audits, ensuring findings are prioritized and remediated in alignment with business risk tolerance.
  • Oversee the development and maintenance of security policies, standards, and procedures across the organization.
  • Lead or oversee penetration testing efforts and coordinate remediation of identified vulnerabilities.
  • Oversee third-party risk management processes, ensuring vendor security practices are evaluated and contractual security requirements are enforced.
  • Promote a culture of security accountability and risk-informed decision-making across technical and business teams.
  • Lead and oversee the security awareness training program for the organization.
  • Partner with the Sr. Managing Director, Infrastructure & Security to define and execute the strategic roadmap for the organization’s security program.
  • Translate organizational and business priorities into actionable project plans, resourcing decisions, and operational standards.
  • Provide architectural and operational oversight for security initiatives, ensuring alignment with infrastructure standards, compliance requirements, and scalability needs.
  • Serve as an escalation point and primary liaison with external security vendors, Managed Detection & Response (MDR) providers, third-party security partners, overseeing service deliver, performance and SLA compliance.
  • Stay current with industry trends, emerging threats, threat intelligence, and vendor roadmaps to inform security strategy, tooling, and investment decisions.
  • Report on team performance, project status, capacity, security posture and risk to the Sr. Managing Director and other stakeholders, including budget and resourcing recommendations.
  • Drive cross-functional collaboration with other Infrastructure & Security teams on security requirements and shared initiatives.
  • Oversee the day-to-day operations of the Security team, ensuring a reliable, proactive, and high-performing security program across the organization’s technology environments.
  • Ensure timely triage, escalation, and resolution of security incidents, acting as an escalation point for complex or high-impact security events.
  • Review and approve security changes, ensuring adherence to change management practices and minimizing operational and security risk.
  • Oversee root cause analysis, post-incident reviews, and remediation planning for significant security incidents, breaches, or degradations.
  • Ensure incident response plans, disaster recovery procedures, and business continuity mechanisms are maintained and regularly tested in collaboration with cross-functional teams.
  • Champion automation, scripting and AI-enabled security tooling to reduce manual effort and improve operational efficiency across security operations.
  • Maintain oversight of technical documentation, security configuration standards, and monitoring/alerting baselines for all security systems.
  • Manage and prioritize the security project portfolio, ensuring projects are delivered on time, within scope, and aligned with business needs.
  • Work cross-functionally within the Infrastructure & Security team to identify and assist with operational optimization for other teams.
  • Lead, coach, and develop the security team including hiring, onboarding, performance management, and career development.
  • Set team goals, workload priorities, staffing plans, schedules, on-call rotations, and after-hours coverage to support reliable security operations.
  • Conduct regular one-on-ones, performance reviews, and development planning to build technical depth, bench strength, and succession readiness.
  • Foster a collaborative, accountable, service-oriented culture that emphasizes security excellence, customer engagement, documentation, continuous learning, innovation, and operational ownership.
  • Identify skills gaps and training needs and coordinate certifications and professional development opportunities for team members.
Desired Qualifications
  • CISSP
  • CISM
Wisconsin Foundation & Alumni Association

Wisconsin Foundation & Alumni Association

View

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A