Haystack
← Back to Jobs
Administrative
TP

Lead Information Security Ops Lead

Top Prospect GroupNew Haven, CT🇺🇸United StatesPosted 15 Sept 2026

Why This Role Stands Out

This leadership role offers significant impact by enhancing cybersecurity operations and refining critical processes like RMF and threat analysis. You'll thrive here if you're a skilled security professional eager to drive innovation and protect vital information assets. Apply today to contribute to a leading organization with a competitive compensation package.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
New Haven, CT, United States
Posted
22 hours ago

Job Description

Information Security Operations Lead / Onsite / 150-160k
 
This is a hands-on leadership role that is responsible for the design, performance, planning, budgeting, securing, monitoring, and integration of Cybersecurity initiatives. You will play a crucial role in refining and creating processes related to the Risk Management Framework (RMF), threat/vulnerability analysis, penetration testing, and reporting exercises.
 
Your primary objective is to enhance cybersecurity capabilities and incident threat response processes to ensure they meet company requirements and industry standards. 
As the AVP of Information Security Operations, you will be responsible for safeguarding the organization's information systems and data assets. You will play a key role in implementing and maintaining security measures to protect against cyber threats, ensuring the confidentiality, integrity, and availability of their systems.
 
  • Deliver on cybersecurity initiatives. Coordinates with internal teams and external vendors to ensure the cybersecurity resilience of the is tested frequently.
  • Oversees audits and evaluations of the cybersecurity environment. Manages the planning, documentation, testing, integration, and execution of cybersecurity projects including annual budgeting and coordination of vendor responsibilities.
  • Stays informed about the latest security threats, technologies, trends and best practices.
  • Security Policies: Establish and enforce security policies, procedures, and guidelines to protect digital assets, sensitive trade data, and intellectual property. Design and implement security controls for networks, systems, and applications.
  • Risk Management: Assist in the development and maintenance of our Risk Management Framework (RMF) processes and documentation. Conduct regular risk assessments, vulnerability assessments and scans, and penetration tests on our infrastructure, applications, and networks to identify and address potential risks and develop risk mitigation plans to safeguard the organization against cyber threats and vulnerabilities. Be responsible for the business fraud investigation and mitigation. Analyze security controls and provide recommendations for improvements.
  • Incident Response: Proactively search for threats and vulnerabilities within our environment. Conduct incident handling and coordination, ensuring a rapid and effective response to security events. Create and maintain an effective incident response plan, ensuring timely and efficient recovery from security breaches and disruptions. Monitor security logs and respond to security incidents in a timely manner and defend our systems against cyber threats.
  • Incident Investigation and Forensics: Carry out thorough research and investigation on security incidents. Work with internal teams and external vendors to conduct research and forensics. Provide incident detection, analysis, and response, helping to improve our overall security posture.
  • Regulatory Compliance: Ensure compliance with all related regulatory bodies. Ensure that all cybersecurity activities are conducted in accordance and compliance with all regulatory and government policies, standards, and requirements.
  • Security Awareness: Develop and oversee a security awareness program to educate employees, members, and stakeholders about security awareness and best practices in cybersecurity.
  • Vendor Security: Evaluate and monitor the security practices of third-party vendors, partners, and service providers. Collaborate with the internal teams and external vendors to assess, document, and authorize information systems using the RMF.
  • Stakeholder Collaboration: Collaborate with internal and external stakeholders, such as customs authorities, shipping partners, and regulatory bodies, to ensure security standards and trade compliance. Collaborate with IT and development teams to integrate security measures into the design and implementation of systems.
  • Reporting: Provide regular reports and updates to executive management and the board of directors on the state of cybersecurity and compliance. Maintain accurate records of all activities, including findings, actions taken, and recommendations for improvement. Develop reports and documentation related to cybersecurity exercises and events.

Similar jobs