Arnold Magnetic Technologies

Information Security Manger

Information Security Manger
Notice info
LocationRochester, NY
Job Typefull time
Salary$115,000-$140,000
On-site
Mining

About This Job

- About Arnold Magnetic Technologies Arnold Magnetic Technologies is a global leader in the engineering and manufacturing of high-performance permanent magnets, magnetic assemblies, precision thin metals, and engineered materials. With more than 125 years of innovation, Arnold serves a wide range of industries, including aerospace, defense, medical, energy, and automotive. The company partners with customers worldwide to deliver mission-critical solutions that enable advanced technologies and drive progress. Position Summary The Information Security Manager will build, lead, and mature Arnold’s enterprise-wide security and compliance program across all systems, environments, data, and locations. This is a hands-on leadership role responsible for developing strategy, managing day-to-day security operations, leading compliance initiatives, and ensuring readiness for multiple audits per year. This position reports directly to the CIO and is a player-coach role with two direct reports, requiring both hands-on execution and leadership. This role owns the full security lifecycle, including governance, risk, compliance, security operations, incident response, disaster recovery, business continuity, data protection, identity and access, physical security systems integration, and security architecture. The ideal candidate balances strategic vision with practical execution and can communicate risk and requirements to both technical and executive stakeholders. Key Responsibilities

- Security Leadership & Strategy-

Own and lead the information security program roadmap, budget, staffing, and maturity.-

Develop, publish, and maintain security policies, standards, procedures, and guidelines.-

Establish security metrics and present regular updates on risk, compliance, and program status to leadership.-

Lead cross-functional security initiatives across departments and business units.-

Foster a culture of security awareness and accountability throughout the organization.Governance, Risk & Compliance-

Pursue and lead certification of CMMC, ISO 27001, and Cyber Essentials+.-

Implement and maintain ongoing compliance with SOX ITGC, NIST 800-171r2, and DFARS 252.204-7012 requirements, including SSPs, POA&Ms, and SPRS scoring.-

Oversee adherence to ITAR/EAR for export-controlled data and technology.-

Ensure compliance with GDPR, Swiss FADP, and other privacy regulations, including data subject rights, DPIAs, and breach notification processes.-

Coordinate and lead multiple audits per year (parent company, certification bodies, customers, and external third parties).-

Manage remediation plans and track progress with stakeholders.Security Operations-

Oversee and mature core security technologies and controls (e.g., SIEM, EDR/XDR, email security, MDM, DLP, secure DNS, vulnerability management, identity protection).-

Oversee vulnerability management, remediation SLAs, and executive-level reporting.-

Coordinate with infrastructure, networking, and applications teams to ensure secure architecture and segmentation.-

Ensure centralized logging and monitoring across all environments.-

Ensure timely monitoring and investigation of security alerts, coordinating response efforts, and performing hands-on analysis for high-severity incidents as needed.-

Drive proactive threat hunting activities, leveraging internal resources or external partners.-

Maintain log retention, integrity, and accessibility for investigations and compliance.Incident Response, DRP, and BCP-

Develop, maintain, and lead the Incident Response (IR) program, including runbooks, detection, escalation, and forensics coordination; act as incident commander during significant events.-

Conduct post-incident reviews and drive continuous improvement.-

Own and coordinate disaster recovery (DRP) and business continuity (BCP) strategies, documentation, and testing in collaboration with IT and business owners.-

Lead tabletop exercises for incident preparation.Security Architecture & Project Consulting-

Define and approve security requirements for new systems, applications, and integrations, ensuring we implement secure designs.-

Conduct threat modeling and provide design guidance to reduce risk.-

Embed security checkpoints into project and change management processes.-

Ensure secure configurations across cloud, on-premise, and hybrid environments by establishing standards, guiding implementation, and validating control effectiveness.-

Implement and enforce encryption, retention, and secure data handling practices.-

Establish, maintain, and enforce secure configuration baselines.Physical Security Integration-

Oversee the management and implementation of physical security technologies (badge systems, access control, cameras) in coordination with facilities teams. -

Coordinate incident response efforts involving both cyber and physical security events.Vendor and Third-Party Risk Management-

Evaluate the security posture of third-party vendors and service providers.-

Lead security due diligence, contract/security reviews, and ongoing risk assessments.-

Ensure vendor contracts include required security, confidentiality, audit, and compliance clauses and drive remediation when gaps are found.-

Define, monitor, and enforce SLAs, KPIs, and escalation paths with MSSPs and third-party service providers to ensure quality of security service delivery.-

Ensure vendors have incident response processes, notify us of security events, and participate in joint investigations as required.-

Define and enforce security requirements for third-party access to systems.-

Maintain shared responsibility matrices to clearly define internal vs. cloud provider security duties, ensuring we implement and monitor required controls to remain compliant on thirdparty systems.Training & Culture-

Develop and deliver enterprise-wide security awareness programs.-

Implement targeted role-based training for high-risk business functions.-

Conduct phishing simulations and measure program effectiveness.-

Ensure technical staff (e.g., system administrators, desktop support, developers) receive training on secure configuration, change management, and security responsibilities aligned to their operational roles.Leadership & Team Development-

Lead, mentor, and develop the security team, providing direction, coaching, and performance feedback while fostering growth and accountability.-

Define roles, responsibilities, performance metrics, and career development paths.-

Promote collaboration, accountability, and continuous learning.Qualifications Required-

Bachelor’s degree in Information Security, Computer Science, Information Systems, Engineering, or related field.-

Must hold at least one advanced security certification such as CISSP, CISM, CISA, CASP+/SecurityX, CRISC, ISO 27001 Lead Implementer/Auditor, or CMMC Certified Professional (CCP)-

5+ years of relevant leadership and security experience, including ownership of security operations and compliance programs.-

Familiarity with CMMC, ISO 27001, and Cyber Essentials+ or similar certification processes.-

Hands-on experience with SIEM, EDR/XDR, vulnerability management, identity/MFA, network/cloud security, and data protection.-

Proven incident response leadership and disaster recovery/business continuity experience.-

Strong stakeholder management and ability to communicate security risk in business terms.-

Experience leading or preparing for audits with internal and external auditors.-

U.S. Citizenship required due to ITAR/EAR and handling of controlled data. Preferred-

Demonstrated experience working with NIST 800-171r2 and SOX/ITGC.-

Additional professional certifications.-

Master’s degree in a relevant discipline. Working Conditions:-

Monday-Friday, 8AM-5PM, with the expectation of availability to address urgent alerts or issues outside regular business hours due to global operations (including nights, weekends, or holidays as needed).-

Primarily office-based role with extended periods of computer use and meetings.-

Some travel required for periodic visits to other sites, vendor offices, or industry events.-

May occasionally require entering manufacturing areas where personal protective equipment (PPE), including safety shoes and eye protection, must be worn in compliance with company safety policies. Hearing protection is available if desired.-

The employee may occasionally be required to lift and/or move up to 50 pounds. #ROCArnold Magnetic Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law.![](https://analytics.click2apply.net/v/1JEoNLIAGrn22h5MGUYlLl)

Salary: 115000 - 140000 yearlyPI278977374

Equal employment opportunity, including veterans and individuals with disabilities

[Apply Here](https://www.click2apply.net/1JEoNLIAGrn22h5MGUYlLl)

PI278977374

Similar Jobs

company-logo

Information Security Manger

Arnold Magnetic Technologies
Job Typefull time
Salary
$115000 - $140000
Rochester, NY
3 days ago
company-logo

US Security Manager

Kinross Gold Corporation
Job Typefull time
 
Fairbanks, AK
23 days ago
company-logo

Manager, Digital Security

LCEC
Job Typepart time
 
North Fort Myers, FL
9 days ago
company-logo

Security Manager

NextDecade
Job Typefull time
 
Houston, TX
25 days ago
company-logo

Information Security Engineer

Innio
 
Remote
24 days ago
company-logo

Specialist Information Security

Independent Electricity System Operator (IESO)
Job Typefull time
 
Mississauga, ON
11 days ago
company-logo

Cyber Security Manager

Apex Clean Energy
Job Typefull time
 
Charlottesville, VA
29 days ago
company-logo

IT Security Specialist

Sunbridge Energy Services
Job Typefull time
 
Tarzan, TX
2 days ago
company-logo

Security Services Officer

Valero
 
San Antonio, TX
9 days ago
HM

Information Security Engineer III

Hudson Manpower
Job Typefull time
Salary
$93600 - $120640
Dallas, TX
7 days ago
company-logo

Information Security Analyst

Eagle Creek Renewable Energy
Job Typefull time, volunteer
 
Badin, NC
10 days ago
company-logo

IT/OT Cyber Security Manager

Carmeuse
Job Typefull time
Salary
$130000 - $150000
Pittsburgh, PA
7 days ago
company-logo

Cybersecurity Manager

Florida Power & Light
Job Typefull time
 
Juno Beach, FL
9 days ago
company-logo

Cybersecurity Manager

NextEra Energy
Job Typefull time
 
Juno Beach, FL
10 days ago
company-logo

Security Officer

Oncor Electric Delivery
Job Typefull time
Salary
$50599 - $67465
Dallas, TX
17 days ago
company-logo

Security Officer

Kinross Gold Corporation
 
Round Mountain, NV
23 days ago
company-logo

Security Specialist

McDermott International, Ltd
Job Typefull time
 
Squamish, BC
9 days ago
company-logo

Security Architect Manager

American Electric Power
Job Typefull time
Salary
$132562 - $172331
Columbus, OH
10 days ago
company-logo

Cybersecurity Operations Manager

Motiva Enterprises LLC
Job Typefull time
 
Houston, TX
17 days ago
company-logo

IT Senior Security Engineer

DTE Energy
Job Typefull time
 
Detroit, MI
22 days ago

Trending Jobs

company-logo

Electrical Engineer

Dudley Staffing
Job TypeFull time
Salary
$55 - $75
Canonsburg, PA
9 months ago
company-logo

Division Order Analyst

Coronado Resources
Job TypeFull time
 
Dallas, TX
5 months ago
company-logo

Professional Landman

Penterra Services, LLC
Job TypeContract
 
Lovington, NM
4 months ago
company-logo

Business Analyst – Accounting

Permian Resources
Job TypeFull time
Salary
$110000 - $150000
The Woodlands, Texas
4 months ago
company-logo

Accounts Payable Clerk

LPR Energy
Job TypeFull time
Salary
$65000 - $65000
Dallas, TX
6 months ago
company-logo

Division Order Landman

R. Lacy Services, Ltd.
Job TypeFull time
 
Longview, TX
5 months ago
company-logo

Title Landman

Sustain Land Services
Job TypeFull time
 
Norman, OK
7 months ago
company-logo

contract landman

HPS Oil & Gas Properties
Job TypeFull time
 
Lafayette, LA
8 months ago
company-logo

Landman

Stockyards Energy Land Services
Job TypeContract
 
Akiachak, TX
10 months ago
company-logo

Oil and Gas Land and Title Analyst - SAM Associate II

Bank of America
Job TypeFull time
 
Dallas, TX
6 months ago
company-logo

Lead Software Engineer

Energy Hire
Job TypeFull time
Salary
$120000 - $180000
Dallas, Texas
3 months ago
company-logo

Attorney

Toeppich & Associates
Job TypeFull time
 
Houston, TX
over 1 year ago
company-logo

contract Landman

HPS Oil & Gas Properties
Job TypeFull time
 
Midland, TX
8 months ago
company-logo

Oil and Gas Title Attorney

Oliva Gibbs PLLC
Job TypeFull time
 
Houston, TX
6 months ago
company-logo

Title Reviewer

Innovation Land Services
Job TypeFull time
 
Pittsburgh, PA
8 months ago
company-logo

Data Analyst

River City Science Academy
Job TypeFull time
Salary
$20 - $45
Jacksonville, FL
7 months ago
company-logo

Electrical Designer

Dudley Staffing
Job TypeFull time
Salary
$45 - $60
Canonsburg, PA
9 months ago
company-logo

IT Director - Data Management

Energy Hire
Job TypeFull time
 
Midland, Texas
29 days ago
company-logo

Civil/Structural Designer

Dudley Staffing
Job TypeFull time
Salary
$30 - $60
Canonsburg, PA
9 months ago
company-logo

Application Developer

Energy Hire
Job TypeFull time
 
Midland, Texas
about 1 month ago