INFORMATION SECURITY MANAGER

🏢 Catalyst Acoustics Group · all Catalyst Acoustics Group jobs
📍 United States
💰 USD 120,000 - 155,000 / annual
📅 Posted 2026-09-10 · via Himalayas
🏷 Information-Security-Manager,Cybersecurity-Management,IT-Security-Management,Security-Operations,Security-Governance,Information-Systems-Security-Manager,IT-Security-Manager,Information-Security-Risk-Manager,Information-Security-Compliance-Manager,Information-Security-Management,Cybersecurity-Manager
Apply on original site ↗

Department: Technology

Reports to: VP, Technology (David Crandall)

Direct reports: None initially (program is MSP-backed — Paragus co-managed SOC)

Primary location: Boston or Chicago metro preferred; Columbus, OH (Dublin/Kinetics hub), Remote

Travel: Occasional, across CAG's U.S. sites

Type: Permanent full-time employee

FLSA status: Exempt

Comp reference: $120,000–$155,000 base + up to 10% bonus

About Catalyst Acoustics Group

Catalyst Acoustics Group (CAG) is a mid-market manufacturer of noise-control and vibration control products, operating a family of brands (Kinetics Noise Control, Sound Seal, IAC Acoustics, Frasch, Lamvin, Noise Barriers, RealAcoustix, Madrid, CurbTech, and Riverbank Acoustical Laboratories) across roughly a dozen U.S. sites, with the Dublin, OH Kinetics campus as our technology hub. We run a cloud-first Microsoft 365 / Azure environment backed by a managed security provider (Paragus). Security is being established as its own dedicated function within Technology.

Role summary

We are seeking an Information Security Manager — a hands-on player-coach who will both run the security program and do the operational security work. This is the senior owner of CAG's information-security function: you set the roadmap, governance, and reporting, and you also personally respond to incidents, tune the tooling, and work the queue. It is a single-owner role (no direct reports at the outset), leveraging our managed provider (Paragus co-managed SOC) for scale rather than an internal team.

This role is the permanent successor to CAG's summer security internship, which concludes in August 2026. It assumes senior ownership of the three functions the intern ran day-to-day — security ticket triage, the KnowBe4 awareness program, and Huntress EDR response — and adds the program governance, risk/compliance, and leadership reporting that a manager owns. A clean handoff package from the intern will be available.

You will report to the VP, Technology and partner across IT, HR, Operations, and the brands, plus manage security vendors and the co-managed SOC relationship.

Scope covers IT and information security across CAG’s cloud-first Microsoft 365 / Azure environment; operational-technology (OT) systems on the plant floor are addressed in partnership with Operations.

Essential functions

Program ownership (the “manager” half)

- Own and drive CAG's information-security roadmap and priorities across all brands and sites.

- Develop and maintain security policy, standards, and governance; drive toward a defined baseline (e.g., change management, access governance, IR plan approved by the ELT).

- Own risk and compliance: risk register, control gaps, vulnerability-management program cadence, annual penetration-test coordination, and remediation tracking.

- Own the security awareness program (KnowBe4): training assignment/completion, monthly phishing-simulation campaigns, targeted remediation with HR, and metrics.

- Manage security vendors and tooling — including the Paragus co-managed SOC relationship, EDR, and email security — holding them to scope and outcomes.

- Report to leadership: regular security posture, KPIs, incident summaries, and risk readouts for the VP, Technology and the ELT.

- Lead security due diligence and integration for CAG acquisitions — assess acquired environments and fold them into CAG’s security baseline.

- Own cyber-insurance renewal attestations and respond to customer and contractual security questionnaires and audits.

- Own or co-own business continuity and disaster-recovery planning, including backup-integrity validation and recovery testing.

- Contribute the security lens to the multi-brand ERP consolidation and other major technology projects (access model, segregation of duties, secure design).

Hands-on operations (the “player” half)

- Incident response — lead investigation, containment, and resolution; own the IR runbooks and post-incident reviews; escalate to the

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you