Cybersecurity Program Manager

Remote
Full Time

Alaska Power & Telephone (AP&T) is an employee-owned utility dedicated to serving more than 40 Alaskan communities with reliable electric, broadband, and telephone services. As a provider of critical infrastructure, cybersecurity is essential to maintaining the trust, reliability, and safety our customers depend on every day.

We are seeking a skilled and motivated Cybersecurity Program Manager to execute, maintain, and continuously improve AP&T's cybersecurity program. This role serves as the day-to-day owner of security operations, cyber risk management, incident response readiness, security awareness initiatives, vendor security coordination, and cybersecurity documentation.

The successful candidate will work across IT, telecommunications, and operational environments to strengthen AP&T's security posture while supporting business operations in a dynamic and geographically distributed setting.

Position Summary

The Cybersecurity Analyst is responsible for implementing and managing cybersecurity controls, monitoring security events, coordinating risk mitigation efforts, and ensuring compliance with cybersecurity policies and industry best practices. This position plays a key role in protecting AP&T's information systems, telecommunications infrastructure, operational technology (OT), and critical business services.

The ideal candidate combines strong technical cybersecurity knowledge with excellent communication, documentation, and problem-solving skills. Applicant must reside in Alaska, Washington, or Idaho for work.

Essential Duties and Responsibilities

Security Program Management

  • Maintain, administer, and continuously improve AP&T's cybersecurity program.
  • Develop, update, and maintain cybersecurity policies, procedures, standards, and supporting documentation.
  • Track cybersecurity initiatives, remediation efforts, and program objectives.
  • Support alignment with recognized frameworks and best practices, including NIST Cybersecurity Framework (CSF), CIS Controls, and CISA Cybersecurity Performance Goals.
  • Prepare reports, metrics, and risk summaries for leadership.

Security Operations

  • Monitor security alerts, events, and system activity across the organization's technology environment.
  • Investigate and respond to cybersecurity incidents and suspicious activity.
  • Maintain secure configurations and cybersecurity tools.
  • Coordinate with internal teams and external vendors to address identified security concerns.
  • Support endpoint, network, email, and cloud security initiatives.

Vulnerability and Patch Management

  • Conduct and coordinate vulnerability scanning activities.
  • Analyze findings and prioritize remediation based on business risk.
  • Track corrective actions through completion.
  • Monitor patch management and system hardening efforts.
  • Participate in external security assessments, penetration testing, and remediation planning.

Identity and Access Security

  • Administer and oversee access control processes.
  • Support privileged access management and least-privilege security practices.
  • Manage multifactor authentication (MFA) and identity security controls.
  • Conduct user access reviews and ensure appropriate account management practices.

Incident Response and Recovery

  • Maintain incident response plans, procedures, and supporting documentation.
  • Coordinate cybersecurity event response activities.
  • Facilitate incident response exercises and tabletop simulations.
  • Support disaster recovery, business continuity, and backup validation activities.
  • Assist in post-incident reviews and corrective action planning.

Risk, Compliance, and Vendor Security

  • Identify, assess, document, and track cybersecurity risks.
  • Support audits, compliance reviews, and cybersecurity assessments.
  • Review third-party and vendor cybersecurity practices.
  • Assist with cyber insurance submissions, questionnaires, and related requirements.
  • Maintain evidence and documentation supporting compliance activities.

IT, OT, and Critical Infrastructure Security

  • Support cybersecurity practices across information technology, telecommunications, and operational technology environments.
  • Assist in securing distributed systems supporting utility and broadband operations.
  • Coordinate security efforts involving critical infrastructure and field operations technologies.
  • Support cybersecurity requirements for remote and rural operational environments.

Security Awareness and Culture

  • Lead employee cybersecurity awareness and education efforts.
  • Coordinate phishing awareness campaigns and training activities.
  • Promote cybersecurity best practices throughout the organization.
  • Foster a culture of shared responsibility for information security.

Required Education

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; or
  • Equivalent combination of education, training, certifications, and relevant professional experience.

Required Qualifications

Experience

  • Minimum of five (5) years of hands-on experience in information technology, systems administration, network administration, infrastructure management, cybersecurity, or related technical disciplines.
  • Minimum of three (3) years of cybersecurity-related experience.
  • Experience with:
    • Security operations
    • Network security
    • System administration
    • Endpoint protection and endpoint detection and response (EDR)
    • Identity and access management (IAM)
    • Vulnerability management
    • Backup and recovery solutions
    • Incident response and investigations
  • Experience developing policies, procedures, incident reports, risk assessments, and technical documentation.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Ability to manage sensitive and confidential information with discretion and sound judgment.
  • Proven ability to coordinate remediation efforts and drive issues to resolution.

Certifications

Current cybersecurity certification preferred, including but not limited to:

  • CompTIA Security+
  • CompTIA CySA+
  • ISC² SSCP
  • ISC² CISSP
  • ISACA CISM
  • GIAC GSEC
  • GIAC GCIH
  • GIAC GICSP
  • ISA/IEC 62443 Certification
  • Equivalent industry-recognized cybersecurity certification

Candidates with significant relevant experience who do not currently hold a certification may be considered but will be expected to obtain an approved certification within 6-12 months of hire.

Technical Knowledge

Working knowledge of:

  • NIST Cybersecurity Framework (NIST CSF)
  • CIS Critical Security Controls
  • CISA Cybersecurity Performance Goals (CPGs)
  • Security Operations Center (SOC) practices
  • Incident response lifecycle
  • Vulnerability management
  • Least privilege and access control
  • Multifactor authentication (MFA)
  • Endpoint security
  • Email security
  • Security logging and monitoring
  • Backup and disaster recovery best practices

Preferred Qualifications

  • Experience within a utility, telecommunications, broadband, energy, critical infrastructure, or highly regulated environment.
  • Experience supporting operational technology (OT), industrial control systems (ICS), SCADA environments, telecommunications networks, or field operations.
  • Experience with:
    • Microsoft Entra ID (Azure AD)
    • Microsoft Defender
    • Microsoft 365 Security
    • ESET
    • SIEM and log management platforms
    • Firewalls and VPN technologies
    • EDR/XDR solutions
    • Vulnerability scanning platforms
    • Backup and recovery systems
    • Network monitoring tools
  • Experience with vendor risk management and third-party security reviews.
  • Experience supporting audits, cybersecurity assessments, cyber insurance reviews, and regulatory compliance activities.
  • Experience developing security metrics, dashboards, reporting solutions, scripting, or automation tools.

Key Competencies

  • Information Security
  • Cybersecurity Operations
  • Risk Management
  • Incident Response
  • Vulnerability Management
  • Identity and Access Management (IAM)
  • Security Governance
  • Critical Infrastructure Protection
  • Analytical Thinking
  • Problem Solving
  • Technical Documentation
  • Communication Skills
  • Vendor Management
  • Project Coordination
  • Continuous Improvement

Physical Requirements

The physical demands described below are representative of those that must be met to successfully perform the essential functions of this position. Reasonable accommodations may be made for qualified individuals with disabilities.

  • Maintain a constant state of mental alertness.
  • Regularly sit, speak, hear, and use hands and fingers to operate computers, keyboards, mobile devices, and telephones.
  • Frequently perform work in a sedentary office environment with opportunities to move about.
  • Occasionally stand, walk, bend, stoop, reach, and lift or move items weighing up to 50 pounds.
  • Requires close vision, distance vision, peripheral vision, and the ability to adjust focus.
  • Occasional local and overnight travel by automobile or commercial aircraft may be required.

Why AP&T?

  • Employee-owned company through our ESOP program
  • Opportunity to secure critical infrastructure serving Alaska communities
  • Collaborative and mission-driven culture
  • Professional development and certification support
  • Competitive compensation and comprehensive benefits
  • Meaningful work with visible impact

Alaska Power & Telephone is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, genetic information, or any other status protected by applicable law.

ATS Keywords: Cybersecurity, Information Security, Security Operations, SOC, Incident Response, Risk Management, Vulnerability Management, Patch Management, Identity and Access Management, IAM, MFA, EDR, XDR, SIEM, NIST CSF, CIS Controls, CISA CPG, Microsoft Defender, Microsoft 365 Security, Entra ID, Azure AD, OT Security, ICS Security, SCADA Security, Critical Infrastructure, Network Security, Vendor Risk Management, Business Continuity, Disaster Recovery, Compliance, Governance Risk and Compliance (GRC).

Loading Job Application......