Haystack
← Back to Jobs
Administrative

Information Security Manager

Spartanburg CountySpartanburg, SC🇺🇸United StatesPosted 5 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Please apply here:

POSITION SUMMARY
Leads Spartanburg County''s information security program and establishes governance, risk management, security operations, incident readiness, security awareness, data protection coordination, and executive reporting. The position serves as the County''s internal cybersecurity owner while coordinating 24x7 managed SOC/MDR services and collaborating with County Risk Management, Legal, Internal Audit, Human Resources, public safety, elected offices, and technology vendors.

ESSENTIAL DUTIES
• Develops, implements, and maintains the County''s information security strategy, roadmap, policies, standards, procedures, risk register, and performance measures.
• Leads the Cybersecurity Stabilization & Resilience Program''s security workstreams and translates technical findings into prioritized executive decisions.
• Supervises, coaches, and evaluates assigned information security staff; establishes operating cadence, duty coverage, professional development, and performance expectations.
• Oversees MDR/SOC, incident-response, vulnerability-management, security-assessment, and other cybersecurity vendors; defines service levels, escalation paths, reporting, and accountability.
• Coordinates preparation for and response to cybersecurity incidents, including triage, executive notification, evidence preservation, vendor coordination, after-action review, and remediation tracking.
• Establishes and governs vulnerability management, privileged access, identity security, logging/SIEM, endpoint security, cloud security, network security, and third-party access practices.
• Coordinates risk assessments for critical systems, departments, elected offices, vendors, and technology projects; documents residual risk and escalates material risks.
• Partners with the County Risk Management Director on enterprise risk matters while retaining responsibility for information-technology security risk.
• Develops executive dashboards and delivers regular cybersecurity status, risk, incident, remediation, and investment reports.
• Leads security awareness, phishing simulation, role-based training, tabletop exercises, and cybersecurity communications.
• Participates in procurement, contract review, cyber-insurance support, audit response, regulatory/legal coordination, and business continuity planning.
• Maintains professional relationships with law enforcement, state and federal partners, peer governments, and information-sharing organizations.
• Works collaboratively with County Administration, department heads, elected officials, IT staff, vendors, and external partners.
• Communicates professionally, respectfully, and clearly with technical and nontechnical stakeholders.
• Protects confidential, security-sensitive, personnel, legal, and operational information.
• Supports a customer-service culture focused on partnership, accountability, timely communication,
documentation, and continuous improvement.

KNOWLEDGE, SKILLS AND ABILITIES
• Cybersecurity governance, risk management, incident response, security architecture,
identity/access management, vulnerability management, data protection, and third-party risk.
• Leadership, staff development, vendor governance, policy development, budget planning, and
executive communication.
• Ability to remain composed during incidents, make risk-based decisions with incomplete
information, and maintain confidentiality.

PHYSICAL REQUIREMENTS
Primarily office and computer-based work with periodic travel to County facilities. May require work
outside normal business hours for projects, maintenance, exercises, or incidents. Must be able to
use standard office and computing equipment and communicate effectively in person, by
telephone, and through electronic collaboration tools. HR should finalize physical requirements and
any on-call language using the County''s standard job-description format.

EDUCATION AND EXPERIENCE
• Bachelor''s degree in cybersecurity, information systems, computer science, business, public
administration, or a related field.
• Seven years of progressively responsible information security, infrastructure security, risk, audit, or
security-operations experience, including at least two years of lead, supervisory, programmanagement,
or vendor-management responsibility.
• Equivalent combinations of education, training, certifications, and directly relevant experience may
be considered.
• Experience leading cybersecurity in local government, public safety, courts, public utilities,
healthcare, finance, or another regulated/mission-critical environment.
• CISSP, CISM, CRISC, CISA, GIAC, or comparable certification.
• Experience with NIST Cybersecurity Framework, incident command, managed SOC/MDR,
vulnerability management, Microsoft security, Fortinet, SentinelOne or comparable EDR/XDR,
SIEM, PAM, and disaster recovery.
• Demonstrated ability to communicate risk effectively to executives, elected officials, auditors,
attorneys, and nontechnical department leaders.

LICENSE, CERTIFICATIONS, AND OTHER REQUIREMENTS
• All regular full-time and part-time employees of Spartanburg County are required by state law to
participate in the South Carolina Retirement System.
• Possession of a valid driver''s license issued in the state of South Carolina.

Similar jobs