Sr. Manager, Enterprise Cybersecurity & Information Security
BU1 North Texas Tollway Authority
Job description
Job Description
JOB SUMMARY: **This role provides strategic and operational leadership for NTTA's enterprise cybersecurity, information security, cyber risk management, and regulatory compliance programs. This position is responsible for developing and executing a comprehensive cybersecurity strategy that protects organizational assets, critical infrastructure, customer information, and technology resources while enabling business objectives. The role serves as NTTA's senior cybersecurity leader, partnering with executive leadership, business stakeholders, and technology teams to manage cyber risk, ensure regulatory compliance, strengthen organizational resilience, and promote a culture of security awareness across the enterprise.
DUTIES, FUNCTIONS, AND RESPONSIBILITIES:**
-
Essential duties and functions, pursuant to the Americans with Disabilities Act, may include the following. Other related duties may be assigned.
-
Develop, implement, and maintain NTTA's enterprise cybersecurity and information security strategy, roadmap, policies, standards, and governance framework aligned with organizational objectives while ensuring effective oversight, accountability, and alignment with business priorities and risk tolerance.
-
Lead Cybersecurity Operations, threat detection, incident response, vulnerability management, and cyber resilience activities to protect critical business systems and infrastructure.
-
Establish and maintain an enterprise cyber risk management program, including risk assessments, mitigation strategies, and reporting on cybersecurity risks and trends.
-
Ensure compliance with applicable cybersecurity, privacy, and regulatory requirements, including PCI DSS, NIST Cybersecurity Framework, SOC controls, and other relevant standards.
-
Lead cybersecurity awareness, education, and training initiatives to strengthen organizational security culture and reduce human risk factors.
-
Develop and present cybersecurity metrics, risk assessments, program maturity updates, and incident reporting to senior leadership, executive and board.
-
Direct third-party cybersecurity risk management activities, including security assessments, vendor reviews, contractual requirements, and ongoing monitoring of critical service providers.
-
Partner with business and technology leaders to integrate security requirements into enterprise architecture, project delivery, cloud initiatives, data management, and operational processes.
-
Lead and develop high-performing cybersecurity teams through recruitment, coaching, performance management, succession planning, and employee development while fostering a culture of innovation, accountability, collaboration, continuous improvement, and operational excellence.
** SUPERVISORY/LEADERSHIP RESPONSIBILITIES:** **Responsible for the full range of supervisory activities including selection, training, evaluation, coaching, employee development, performance management, and recommendation for corrective action or dismissal. Establishes departmental goals and objectives, manages resource allocation and budgets, and promotes a culture of accountability, innovation, collaboration, and continuous improvement
KNOWLEDGE, SKILLS, AND ABILITIES:**
-
Business Insight / Ensures Accountability: Knowledge of cybersecurity governance, regulatory compliance, privacy requirements, and industry frameworks, including NIST, PCI DSS, SOC, ISO 27001, CIS Controls, and applicable federal, state, and local regulations.
-
Tech Savvy / Business Insight: Knowledge of enterprise cybersecurity operations, including security architecture, cloud security, identity and access management, threat intelligence, vulnerability management, incident response, and business continuity practices.
-
Strategic Mindset / Drives Vision and Purpose: Ability to develop and execute enterprise cybersecurity strategies, roadmaps, and governance programs that align with organizational priorities and support long-term business objectives.
-
Decision Quality / Strategic Mindset: Skill in evaluating cyber risks, emerging threats, and technology trends and developing practical, risk-based solutions that strengthen organizational security and resilience.
-
Manages Complexity / Courage: Skill in analyzing complex business, technology, and security challenges, exercising sound judgment, and making effective decisions in dynamic and evolving environments.
-
Communicates Effectively / Persuades: Skill in communicating cybersecurity risks, strategies, and program performance effectively to executive leadership, the Board of Directors, stakeholders, and technical audiences.
-
Collaborates / Organizational Savvy: Skill in building strategic partnerships and fostering collaboration across departments, vendors, government agencies, and external stakeholders to advance organizational security objectives.
-
Drives Vision and Purpose / Cultivates Innovation: Ability to lead organizational change, promote a culture of security awareness and accountability, and evaluate emerging technologies and threats to improve organizational security posture.
-
Drives Results / Resourcefulness: Skill in managing financial, technology, vendor, and human resources to achieve cybersecurity objectives and maximize operational effectiveness
-
Develops Talent / Builds Effective Teams: Ability to lead, coach, mentor, and develop high-performing teams through performance management, workforce planning, succession planning, and employee development
-
Manages Complexity / Drives Results: Ability to manage multiple priorities, navigate ambiguity, and adapt to evolving business, regulatory, and threat environments while maintaining focus on strategic outcomes and operational excellence.
-
Drives Results / Decision Quality: Skill in directing cybersecurity incident response, crisis management, and recovery efforts while balancing operational continuity, regulatory obligations, and organizational risk.
** MINIMUM QUALIFICATIONS:** ** Education:**
- Bachelor's degree in in computer science, information technology, business administration, engineering, or related field.
Years of Experience:
- A minimum of six (6) years[JH2.1] of progressively responsible experience leading cybersecurity, information security, IT risk management, security operations, compliance, or related technology teams and functions, including supervisory or management experience.
PREFERRED QUALIFICATIONS:
-
Master’s degree
-
CISSP, CISM, CRISC, GIAC certifications and Certified Information Systems Auditor (CISA)
NTTA is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability or veteran status.