Information Security Lead
Department: Information Technology
Division: Corporate
Location: Remote/Home Office
Reports To: CIO
Job Summary
Senneca is seeking an Information Security Lead to own and mature the organization's cybersecurity program. This role is responsible for security governance, policy development, security awareness and training, risk management, compliance support, and the coordination of cybersecurity initiatives across the business.
The Information Security Lead will partner closely with IT Operations, Software Engineering, Data & Analytics, business leaders, and external security providers to strengthen the company's security posture while enabling business growth and operational excellence.
This is a hands-on individual contributor role with significant visibility and cross-functional influence. Reporting directly to the CIO, the Information Security Lead will play a critical role in protecting company assets, reducing organizational risk, and supporting the company's long-term cybersecurity strategy.
Why Join Us
Benefits
Company-Paid Benefits
Life Insurance
Short-Term Disability (STD)
Long-Term Disability (LTD)
3 Weeks Paid Time Off (PTO)
9 Paid Holidays
Paid Parental Leave
IND123
Additional Benefits
401(k) with Company Match
Medical, Dental, and Vision Coverage
Employee Discount Programs
Optional Supplemental Benefits
Career Development and Tuition Assistance
Diverse, Inclusive, and Welcoming Culture
Why This Opportunity
This is an opportunity to make a meaningful impact on the organization's security maturity and business resilience. You will help shape cybersecurity strategy, influence company-wide security practices, partner with executive leadership, and drive initiatives that protect critical systems, data, and operations. This role offers the autonomy to build programs, improve processes, and strengthen security across a growing organization.
Duties and Responsibilities
Security Governance & Risk
Develop, maintain, and communicate information security policies, standards, and procedures.
Conduct periodic security risk assessments and track remediation efforts.
Maintain cybersecurity metrics, risk registers, and executive reporting.
Assist with customer security questionnaires, audits, and compliance activities.
Security Awareness & Training
Own the company security awareness program.
Lead phishing simulations and user education campaigns.
Promote a security-conscious culture across the organization.
Develop training materials and deliver security awareness education to employees.
Security Program Management
Drive cybersecurity improvement initiatives and roadmap execution.
Partner with IT Operations and application teams to implement security controls.
Coordinate vulnerability remediation and risk mitigation activities.
Evaluate and support implementation of security technologies and services.
Vendor & MSSP Coordination
Serve as the primary liaison to external security providers, MSSPs, and security consultants.
Monitor service delivery, recommendations, investigations, and remediation efforts.
Assist with incident response coordination when security events occur.
Security Operations Oversight
Review security alerts, reports, trends, and recommendations from security partners.
Ensure timely follow-up on identified risks and vulnerabilities.
Track completion of corrective actions and security projects.
Required Experience
5+ years of cybersecurity, information security, or IT risk management experience.
Experience developing security policies, standards, and governance programs.
Experience leading cross-functional projects and influencing stakeholders without direct authority.
Strong written, verbal, and presentation skills.
Working knowledge of cybersecurity frameworks such as NIST CSF, CIS Controls, or ISO 27001.
Education
Bachelor's degree in Information Technology, Computer Science, Engineering, or a related field.
CISSP, CISM, or other relevant security certifications preferred.
Preferred Qualifications
CISSP, CISM, CRISC, Security+, or similar cybersecurity certification.
Experience working with MSSPs or managed security providers.
Experience in manufacturing, industrial, or multi-site business environments.
Familiarity with Microsoft 365, Microsoft Security solutions, Microsoft Entra ID, and endpoint security technologies.
Experience supporting security audits and compliance initiatives.
Knowledge of vulnerability management and security awareness programs.
Core Competencies
Information Security Governance
Cybersecurity Risk Management
Security Awareness & Training
Security Program Leadership
Vulnerability Management
Compliance & Audit Support
Incident Response Coordination
Cross-Functional Collaboration
Vendor & MSSP Management
Executive Communication & Reporting
Impact of the Role
The Information Security Lead directly contributes to company profitability by reducing cybersecurity risk, minimizing the likelihood of costly security incidents, and strengthening overall business resilience. Through proactive risk management, security governance, compliance oversight, and employee awareness initiatives, this role helps prevent operational disruptions, financial losses, regulatory penalties, and reputational damage. Additionally, the position enables secure business growth by implementing scalable security practices that protect critical assets while supporting operational efficiency.
Travel Requirements
Occasional travel may be required, up to 20%.
Physical Requirements
Ability to sit, stand, and walk for extended periods.
Ability to lift up to 20 pounds occasionally.
Our company provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics.
Please no Third-party candidates or phone calls
Work Location: In person