
Manager, Cybersecurity Services
TenHats
Job description
About the Role
We are seeking a Manager, Cybersecurity Services to lead cybersecurity operations, managed security service delivery, and cybersecurity consulting for an established and growing managed services organization.
This is a hands-on leadership role for someone who has already led operationally in cybersecurity, managed services, consulting, or a regulated technology environment. The role requires practical cybersecurity depth, strong communication, attention to detail, sound judgment, and the ability to turn security requirements into repeatable operating practices and practical client recommendations.
The right candidate will be comfortable working across technical teams, clients, vendors, external partners, and executive leadership. This is not a purely strategic role and not a purely compliance role. It requires someone who can manage service delivery, support technical escalations, improve processes, coach team members, and provide cybersecurity advisory services that help clients reduce risk and make informed technology decisions.
Key Responsibilities
-
Lead day-to-day cybersecurity service operations and assigned team members.
-
Serve as the senior escalation point for cybersecurity alerts, incidents, vulnerabilities, security tool issues, and client risk concerns.
-
Oversee managed cybersecurity services, including endpoint detection and response, identity security, vulnerability management, SIEM/logging, email security, DNS filtering, security awareness, and related offerings.
-
Provide cybersecurity consulting and advisory services to clients, including risk reviews, security posture assessments, remediation planning, roadmap development, and executive-level recommendations.
-
Help clients understand cybersecurity risks, control gaps, service options, and practical next steps in clear business language.
-
Ensure client-facing cybersecurity recommendations are technically accurate, operationally supportable, and aligned with the organization’s managed services capabilities.
-
Review cybersecurity service performance, recurring issues, alert quality, remediation trends, and client risk patterns.
-
Coordinate vulnerability management, alert review, incident response support, remediation tracking, and security reporting.
-
Design and maintain cybersecurity standards, secure baseline configurations, hardening guidance, playbooks, escalation paths, and operating procedures.
-
Partner with Strategic Technology Advisors, Sales, and technical teams to identify cybersecurity risks, recommend appropriate services, and scope follow-up projects or remediation work.
-
Evaluate cybersecurity tools, vendor services, integrations, and platforms for technical fit, operational efficiency, supportability, and client value.
-
Maintain security policies, procedures, control documentation, access review processes, and evidence needed to support internal and client-facing security requirements.
-
Coach and develop existing cybersecurity and compliance staff while helping define future team needs.
Required Qualifications
-
7+ years of cybersecurity, security engineering, security operations, compliance, or IT risk experience.
-
Demonstrated experience leading cybersecurity operations, managed security services, technical delivery, consulting, or service-oriented security functions.
-
Strong working knowledge of endpoint security, identity security, vulnerability management, SIEM/logging, email security, DNS filtering, incident response, and cloud security.
-
Experience with Microsoft 365 security, Microsoft Entra ID, MFA, conditional access, Microsoft Defender, Azure security concepts, and identity controls.
-
Ability to create operational structure, define ownership, manage follow-through, and improve service consistency.
-
Ability to build and maintain policies, procedures, control mappings, remediation plans, security reports, executive summaries, and client-facing deliverables.
-
Ability to translate technical and security issues into clear business language.
-
Strong written and verbal communication skills, including client-facing presentation ability.
-
Strong critical thinking, intellectual curiosity, attention to detail, and sound judgment.
-
Ability to challenge weak assumptions, ask thoughtful questions, follow evidence, and make practical recommendations.
-
Ability to work cross-functionally with technical, operational, advisory, sales, vendor, and executive teams.
-
Comfortable operating in a hands-on leadership role.
Preferred Qualifications
-
CISSP, CISM, CISA, Security+, GIAC, Microsoft security certifications, or equivalent experience.
-
Experience in managed services, professional services, consulting, defense contractor, financial services, or other regulated environments.
-
Experience with building security programs, vulnerability management platforms, SIEM platforms, DNS security, phishing simulation tools, and documentation platforms.
-
Experience supporting compliance-aligned security programs such as SOC 2, HIPAA, NIST CSF, CIS Controls, CMMC, NIST SP 800-171, or similar frameworks.
-
Experience with vulnerability remediation tracking, access reviews, evidence collection, risk registers, incident documentation, and security reporting.
-
Experience improving or scaling a managed security service, security operations function, or client-facing cybersecurity program.
What Success Looks Like
The successful candidate will strengthen cybersecurity operations, improve managed security service consistency, create clear ownership, improve evidence quality, reduce recurring security issues, and help deliver client-facing cybersecurity services that are technically sound, operationally supportable, and aligned with real risk reduction.
They will bring operational discipline without unnecessary bureaucracy. They will notice details others miss, ask better questions, challenge assumptions, follow evidence, and help the organization make better cybersecurity decisions.