University of Miami - Miami, FL

posted 3 months ago

Full-time - Manager
Miami, FL
Educational Services

About the position

The University of Miami Health System (UHealth) is seeking a Manager for IT Security Incident Response to lead the organization's response to IT security incidents. This role is pivotal in ensuring the security and integrity of the IT infrastructure by overseeing incident response operations, monitoring, and incident response activities. The manager will be responsible for reviewing and updating incident response standards, policies, and procedures to align with best practices and regulatory requirements. This includes performing necessary investigations, analyses, and evaluations to determine project feasibility and documenting root cause analyses, security events, and incidents. In addition, the manager will develop and maintain the IT security incident response process, ensuring that all required supporting materials are in place. This involves creating functional requirements for roles involved in the Computer Security Incident Response Team (CSIRT) program and collaborating with business units, IT functions, and external providers to ensure mutual understanding and acceptance of responsibilities. The manager will act as a liaison between the security incident response team, enterprise IT services, and business units, initiating the IT security incident response process and executing decision authority as needed. The role also requires ensuring the execution of the incident response process to the resolution of incidents, maintaining and protecting required incident records, and organizing post-incident reviews for presentation to senior management. The ideal candidate will have extensive experience with Unix/Linux systems, OS internals, or file-level forensics, and will be expected to lead a team in a high-pressure environment while maintaining confidentiality and adhering to business and management principles.

Responsibilities

  • Lead the security incident response operations, monitoring, and incident response activities.
  • Review and update incident response standards, policies, and procedures.
  • Perform necessary investigation, analysis, and evaluation to determine project feasibility.
  • Document root cause analysis, security events, and incidents.
  • Develop and maintain the IT security incident response process, including all required supporting materials.
  • Develop functional requirements for roles involved in the CSIRT program.
  • Work with business units, IT functions, and external providers to ensure mutual understanding and acceptance of responsibilities.
  • Act as a liaison between the security incident response team, enterprise IT services, and business units.
  • Initiate the IT security incident response process and execute decision authority within that process.
  • Ensure execution of the incident response process to the resolution of the incident.
  • Ensure generation, maintenance, and protection of required incident records, such as investigator journals.
  • Organize, participate in, and chair post-incident reviews for presentation to senior management.

Requirements

  • Bachelor's degree in Computer Science, Mathematics, Statistics, or a related field; a Master's degree is highly desirable.
  • Certified Information Systems Security Professional (CISSP) preferred.
  • Certified Information Security Manager (CISM) or equivalent preferred.
  • Cloud Computing Security Certification preferred.
  • GIAC Certified Incident Handler (GCIH) preferred.
  • 12+ years of Information Security experience or equivalent combination of education and work experience.
  • Prior experience in a 24x7x365 SOC operations environment.
  • 5+ years' experience in incident response or similar role in a medium or large organization.
  • In-depth experience in security incident management processes and tools.
  • Prior people management/leadership experience with proven ability to lead, motivate, and direct a workgroup.
  • Strong project management, presentation, and communication skills.
  • Ability to maintain confidentiality.
  • Knowledge of business and management principles.
  • Knowledge of IT project management and change control principles.
  • Knowledge and expertise with the MITRE Attack framework.

Nice-to-haves

  • Experience in Healthcare is a plus.

Benefits

  • Competitive salaries
  • Comprehensive benefits package including medical and dental insurance
  • Tuition remission
  • Paid time off
  • Retirement savings plan options.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service