Information Security Program Manager
Information Security Program Manager (Hybrid)
The role – what you’ll do
Barr is seeking an experienced information security program manager to join our Minneapolis, Minnesota, team. In this hybrid role, you will lead Barr’s information security program and work cross-functionally across teams, focusing on continuous improvement as the security threat environment evolves. This is a hands on role and reports to the director of information systems.
A successful person in this role is an analytical problem-solver with exceptional attention to detail and a passion for continuous learning. They are highly organized and leverage their technical expertise to implement robust security measures that safeguard system integrity and reliability. They also dig deep when needed, maintaining a broad strategic perspective on the business. The ideal candidate has a high degree of self-initiative, proactively leading security improvement and governance efforts, while also enjoying collaboration with technical and non-technical colleagues, always with a client-service mindset.
Your impact – key responsibilities
• Security program administration and maintenance: oversee and continuously improve Barr’s information security program. Ensure that security measures are integrated across systems and that protective controls support the company’s needs for performance, stability, and high availability.
• Cybersecurity subject matter expert: provide insight into developing and executing the company’s security strategy. Stay current on emerging threat intelligence and cybersecurity trends, and advise the organization on mitigating new threats.
• Security governance and compliance: develop and maintain information security policies, standards, and procedures to ensure alignment with industry best practices and frameworks such as the NIST Cybersecurity Framework, ISO 27001, and NIST SP 800-171.
• Crisis management: plan, prepare for, and respond to security incidents or breaches, helping to coordinate containment, investigation, and recovery efforts to minimize damage and downtime. Support the company’s Crisis Response Team in planning and response activities that relate to or rely on technology.
• Security monitoring and optimization: continuously monitor the IT environment for signs of security issues or vulnerabilities using appropriate tools and resources.
• Escalation-level technical support: serve as the first escalation point for potential security incidents.
• Vulnerability and patch management: lead proactive vulnerability management by conducting regular security scans and ensuring that processes and automated systems for the timely application of patches and/or upgrades are effective.
• Documentation and training: develop and maintain internal security documentation and provide technical training and guidance for IT staff and end users on security best practices.
• Audit support: maintain required documentation, perform internal security testing, and coordinate responses to audit findings or external audit requests.
• Security assessments: respond to external security questionnaires, assessment tools, and client security surveys.
• Program metrics and continuous improvement: track key security program metrics and use these insights to drive ongoing program improvements.
About the opportunity
• Hybrid: a hybrid work arrangement may be considered for this position. A hybrid work arrangement refers to splitting time worked between a Barr office and a home office. This position is based out of Barr’s Minneapolis, Minnesota, office.
• Travel requirement: ability to travel to other offices and sites across the US and Canada if necessary.
About you – required core competencies
• Education: bachelor’s degree in computer science, information technology, or a related field or equivalent practical experience.
• Experience: 10+ years of related IT infrastructure or information security experience.
o Working knowledge of corporate network environments and technologies such as VMware virtualization, Microsoft Windows Server, Active Directory, and Group Policy management.
o Experience with cloud platforms such as Microsoft Azure, Microsoft 365, or Amazon Web Services (AWS) administration and support.
o Experience working with SIEM / SOC tools including follow-up investigations and response.
o Familiarity with scripting and automation tools (e.g., PowerShell, Python, Ansible) for system administration or security automation.
• Willingness and ability to perform off-hours administrative changes and respond to emergencies or urgent issues outside of regular hours if needed.
• Must be legally authorized to work in the United States without the need for sponsorship by Barr, now or in the future.
Helpful additional experience (not required)
• Recognized security certifications demonstrating expertise and commitment to the field.
• Experience supporting external audits and compliance assessments (such as SOC2 audits, ISO 27001 certification processes, NIST 800-series compliance, or CMMC).
Compensation: Anticipated range of $115,000 to $135,000 annually. Compensation will vary based on relevant experience, education, skill level, and other compensable factors. Employees in this position may also be eligible for a discretionary cash bonus based on team and individual performance.
#LI-Hybrid
Responsibilities
- Partner directly with senior leadership on future planning
- Influence security strategy during org-wide transformation
- Serve as the primary InfoSec SME
- Lead security governance and program coordination
- Documentation & training
- Security monitoring, optimization, some on call support
Desired Skills and Experience
- BS/BA in MIS / IT / Computer Engineering or equivalent experience in lieu of degree
- Demonstrated ability to support distributed teams and field staff
- 8 years + of information security / related IT infrastructure experience required
- Experience with Azure is a plus
- Any external audit / compliance assessments (SOC2 / ISO 27001 / NIST) is a plus
Submit Your Resume
ABOUT SKYWATER SEARCH
Start with your Short List
Led by a group of seasoned search industry professionals, SkyWater Search Partners brings new focus to a novel concept, “Short List Search.” Our purpose is to leave a lasting impression on the clients we serve by providing individuals who will make a measurable difference in their business. We strive to consistently deliver great results to our clients in a very timely manner.
Practice Areas
Our practice areas are led by highly experienced executive recruiters who take great care in fully understanding client requirements and candidate qualifications.
• Accounting and Finance
• Information Technology
• Operations
• Engineering
• Sales
• Marketing
• Human Resources
• Legal
• Construction
• Supply Chain
• Consumer Package Goods (CPG)
Founded on long-standing relationships and hundreds of successful placements throughout the Twin Cities business community, SkyWater Search Partners is a proven resource for clients and candidates looking to quickly and confidently explore their “short list” of best choices. Count on us to find the best people – and the best fit.