Manager of IT and Security
Reports to: CISO
FLSA: Full-time, Salaried Exempt
Primary Work Location: Remote
Make an Impact at Advanced IT Concepts
Join Advanced IT Concepts (AITC) as a Security Systems Administrator and be the frontline of IT support for our growing team in Orlando, FL, Reston, VA, and across the globe. Your expertise will keep our people connected, secure, and ready. From deploying laptops for new employees to safeguarding systems that power critical operations, you’ll ensure our technology runs seamlessly so our teams can focus on delivering solutions that matter.
COMPANY OVERVIEW
Advanced IT Concepts (AITC) is a fast-growing Information Technology company specializing in Network and Systems Engineering, Integration, Professional Services, Medical Simulation, Test and Training Systems, and End-to-End Product and Technology Solutions. We deliver expert support in Information Systems Design and Cybersecurity, Strategic Planning, Program and Project Management, Security Risk Assessment, and Logistics for Federal, State and Local Government
The Manager of IT and Security is responsible for leading enterprise IT operations and cybersecurity programs that protect organizational systems, data, endpoints, identities, and regulated information. This role combines hands-on technical leadership with program ownership across identity and access management, vulnerability management, endpoint security, incident response, Microsoft 365 security, privileged access management, compliance, risk assessment, and security policy development. The ideal candidate will have deep experience administering modern Microsoft security platforms, supporting regulated environments, and translating security requirements into practical operational controls.
-
Support IT operations work by deploying infrastructure and services, maintaining operational readiness, and automating and streamlining user support processes to improve service delivery and consistency.
-
Lead IT security operations, including identity and access management, endpoint security, vulnerability management, incident response, data protection, and security compliance activities.
-
Develop, implement, and maintain information security policies, standards, procedures, system security documentation, and related compliance artifacts.
-
Manage Microsoft Entra ID, Conditional Access, Active Directory, multifactor authentication, and privileged access controls to enforce least-privilege principles and secure authentication practices.
-
Administer Microsoft Intune and endpoint management policies, including device compliance, configuration baselines, application deployment, endpoint security controls, and secure device lifecycle management.
-
Oversee Microsoft Defender, Microsoft Purview, email security controls, data loss prevention policies, and related Microsoft 365 security technologies to protect users, endpoints, and sensitive information.
-
Own the enterprise vulnerability management process, including scan configuration, credentialed assessments, CVE analysis, risk-based prioritization, remediation coordination, validation, and reporting.
-
Support security compliance initiatives aligned with NIST SP 800-171, NIST SP 800-172, CMMC, organizational policies, and customer or regulatory requirements.
-
Coordinate preparation and maintenance of System Security Plans, assessment evidence, control documentation, remediation plans, and continuous monitoring activities.
-
Investigate suspicious authentication activity, endpoint detections, malware alerts, data loss prevention alerts, and other security events; coordinate containment, remediation, and lessons learned.
-
Collaborate with infrastructure, applications, help desk, compliance, and business teams to integrate security requirements into daily operations and technology projects.
-
Evaluate software, systems, and technology requests for security risk, operational impact, and compliance alignment before approval and deployment.
-
Create technical documentation, knowledge base articles, operating procedures, security guidance, and end-user communications to improve consistency and security awareness.
-
Mentor IT and security staff, provide escalation support, and promote a culture of accountability, risk reduction, and continuous improvement.
-
Prepare reports, dashboards, and briefings for leadership on security posture, vulnerability status, compliance readiness, incident trends, and operational risks.
-
Minimum of 8 years of progressive experience in information security, cybersecurity, IT operations, systems administration, endpoint management, or related technical roles.
-
Demonstrated experience leading or managing IT security programs, security operations, compliance initiatives, or cross-functional technical projects.
-
Hands-on experience with Microsoft Entra ID, Active Directory, Microsoft Intune, Microsoft Defender, Microsoft Purview, Conditional Access, and Microsoft 365 security administration.
-
Strong working knowledge of vulnerability management tools and processes, including scan administration, CVE analysis, remediation tracking, and risk-based prioritization.
-
Experience supporting NIST SP 800-171, CMMC, or similar cybersecurity compliance frameworks in a regulated or security-sensitive environment.
-
Knowledge of privileged access management, identity governance, multifactor authentication, endpoint protection, DLP, email security, incident response, and security monitoring practices.
-
Ability to develop clear documentation, policies, procedures, compliance evidence, technical guides, and executive-level security reporting.
-
Strong analytical, troubleshooting, communication, and stakeholder management skills.
-
Ability to manage competing priorities, coordinate remediation across teams, and make sound risk-based decisions.
-
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent professional experience may be considered.
-
CompTIA Security+, CompTIA CySA+, CISSP, CISM, CISA, or related cybersecurity certification.
-
Experience with Rapid7, Cortex XDR, CrowdStrike Falcon, Trellix/McAfee, CyberArk, SolarWinds SEM, RSA, Wireshark, N-Central, PowerShell, SCC/STIG Viewer, Azure Virtual Desktop, or similar enterprise security and IT operations tools.
-
Experience preparing for or supporting third-party assessments, audits, customer security reviews, DCMA DIBCAC assessments, or CMMC certification activities.
-
Experience supporting environments that process or protect Controlled Unclassified Information or other sensitive data.
-
Prior experience managing or mentoring IT support, systems administration, endpoint, or security operations personnel.
-
Cybersecurity program management
-
Identity and access management
-
Endpoint security and device compliance
-
Vulnerability management and remediation coordination
-
Incident response and security investigation
-
Microsoft 365 security administration
-
Privileged access management
-
Security compliance and audit readiness
-
Risk assessment and risk-based decision-making
-
Policy, procedure, and documentation development
-
Cross-functional leadership and stakeholder communication
-
Process improvement and operational reporting
This position may require coordination across multiple business units, technical teams, vendors, and geographically dispersed users. The Manager of IT and Security should be comfortable operating in a fast-paced environment, supporting incident response or urgent remediation activities when required, and communicating technical risk clearly to both technical and non-technical audiences.
AITC provides equal employment opportunity (EEO) to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability status, genetic information, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable federal, state, and local laws and offers equal opportunity for VEVRAA Protected Veterans. AITC will not discriminate against employees and job applicants who inquire about, discuss, or disclose compensation information.
uss, or disclose compensation information.