Sr Manager of Cybersecurity
Oklahoma City, OK, US, 73120
Req ID: 487407
Benefits: * Fuel Your Growth with Love's - company funded tuition assistance * Paid Time Off * 401(k) – 100% Match up to 5% * Medical/Dental/Vision Insurance after 30 days * Competitive Pay * Career Development *
The Senior Cybersecurity Manager is responsible for leading and advancing enterprise cybersecurity programs that protect Love's information assets, technology platforms, operational technology environments, and business operations. This position provides strategic and operational leadership for Identity & Access Management (IAM), Privileged Access Management (PAM), Governance, Risk & Compliance (GRC), Security Awareness, and Vulnerability Management. The Senior Cybersecurity Manager will establish cybersecurity strategy, oversee program execution, develop talent, manage vendors, and partner closely with Information Technology, Audit, Legal, HR, Retail Operations, Infrastructure, Networking, and business leaders to reduce risk while enabling business objectives. This role requires strong cybersecurity leadership, program management expertise, and the ability to translate technical risks into actionable business decisions. The role is also expected to identify opportunities to responsibly use automation, analytics, and AI-enabled security capabilities to improve productivity, strengthen risk management, enhance security operations, reduce manual work, and improve organizational effectiveness.
MAJOR RESPONSIBILITIES:
Cybersecurity Strategy, Governance, and Risk Management
• Develop and execute enterprise cybersecurity strategies, roadmaps, and initiatives aligned with business objectives, regulatory requirements, and organizational risk tolerance.
• Establish and maintain cybersecurity governance frameworks, policies, standards, risk management processes, and control oversight programs. PCI, SOC 2, GDPR, CCPA, etc..
• Lead cybersecurity risk assessments, maintain enterprise cyber risk registers, and facilitate risk acceptance decisions with business and executive leadership.
• Develop cybersecurity metrics, KPIs, KRIs, maturity measurements, and executive reporting used to communicate program effectiveness and risk posture.
• Partner with Internal Audit, External Audit, and Internal Controls teams to ensure cybersecurity programs remain audit-ready and compliant with applicable requirements.
• Use automation, analytics, and AI-enabled capabilities where appropriate to improve reporting, risk analysis, compliance monitoring, and operational efficiency.
Identity and Access Management
• Own the enterprise Identity & Access Management (IAM) program end-to-end — strategy, standards, and execution — across joiner/mover/leaver processes, entitlement management, and access certification.
• Establish standards, governance processes, and controls related to identity lifecycle management, privileged access management, access certifications, segregation of duties, and least-privilege access.
• Lead initiatives to modernize and automate identity management capabilities while reducing risk and improving audit readiness.
• Define and enforce enterprise-wide standards for account ownership, periodic access reviews, role-based access control (RBAC), and service account lifecycle management.
• Partner with application, infrastructure, and HR teams to integrate identity governance into onboarding, transfers, and terminations, minimizing standing access and orphaned accounts.
Security Awareness
• Own the enterprise security awareness and training program, including annual and role-based training curricula, new-hire onboarding content, and ongoing employee education.
• Lead phishing simulation and social engineering testing programs, analyzing results to target coaching and reduce click/report rates over time.
• Develop and distribute security communications, campaigns, and awareness materials (e.g., newsletters, posters, videos) in Love's branding to reinforce secure behaviors across the organization.
• Partner with HR, Communications, and business unit leaders to tailor awareness content for high-risk roles, including finance, executive, and OT/field personnel.
• Define and report on security awareness metrics — training completion, phishing susceptibility, and incident trends tied to human error — to executive leadership.
• Coordinate observance of Cybersecurity Awareness Month and other recurring engagement initiatives to sustain a security-conscious culture.
Vulnerability Management
• Lead enterprise vulnerability management programs, including governance, prioritization, remediation tracking, reporting, and executive escalation processes.
• Establish vulnerability remediation priorities, service level expectations, and accountability models across technology and business teams.
• Review security incidents, threat intelligence, and operational trends to identify opportunities for risk reduction and program improvement.
• Ensure security technologies and services remain aligned with business requirements, risk priorities, and operational objectives.
Leadership, Talent Development, and Vendor Management.
• Lead, mentor, coach, and develop cybersecurity managers, engineers, analysts, and program owners.
• Establish departmental goals, performance expectations, workforce planning strategies, and professional development initiatives.
• Manage cybersecurity vendor relationships, contracts, service providers, and strategic technology partnerships.
• Participate in recruiting, interviewing, hiring, succession planning, and employee performance management activities.
• Foster a culture of accountability, continuous improvement, operational excellence, innovation, and customer service.
Communication and Cross-Functional Partnership
• Serve as a trusted advisor to leadership on cybersecurity risk, strategy, investments, and organizational priorities.
• Present cybersecurity initiatives, risks, metrics, incidents, and remediation activities to leadership and governance committees.
• Collaborate with IT, Infrastructure, Networking, Retail Operations, Legal, Compliance, Privacy, and business stakeholders to ensure cybersecurity requirements are incorporated into projects and operational processes.
• Represent Information Security in enterprise initiatives, strategic planning efforts, vendor assessments, and organizational change programs.
Soft Skills
• Strategic leadership with the ability to align cybersecurity initiatives to business objectives.
• Strong executive presence and communication skills with technical and non-technical audiences.
• Ability to influence decisions and drive outcomes across multiple business functions.
• Critical thinking and risk-based decision making.
• Strong organizational, planning, and program management skills.
• Ability to lead through change, ambiguity, and competing priorities.
• Talent development, coaching, mentoring, and team building. • Ownership, accountability, and attention to detail.
• Strong collaboration and stakeholder relationship management.
• Continuous learning mindset with commitment to innovation and improvement.
Education & Experience
• Degree in business administration or a technology-related field, or equivalent work- or education-related experience
• Demonstrated experience and success in senior leadership roles in risk management and information security.
• Knowledge and understanding of relevant legal and regulatory requirements, such as: Payment Card Industry/Data Security Standard, HIPPA, State & Federal data privacy laws, and International data privacy laws
• Knowledge of common information security management frameworks, such as SOC 2, ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework
• Sound knowledge of business management and a working knowledge of information security risk management and cybersecurity technologies
• Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentials preferred • Identity and Access Management (IAM), Privileged Access Management (PAM), Identity Governance, and Zero Trust security principles.
• Cybersecurity risk management, risk assessments, control design, control testing, and audit readiness.
• Enterprise vulnerability management and remediation governance. • Security architecture concepts across network, cloud, infrastructure, application, and operational technology environments. • Cybersecurity metrics, reporting, dashboard development, and executive communications.
• Vendor management, contract oversight, budgeting, and strategic planning.
• Automation, AI-enabled security technologies, analytics platforms, and operational efficiency initiatives.
Physical Demands
• Requires prolonged sitting, bending and stooping.
• Occasional lifting up to 25 pounds.
• Manual dexterity sufficient to operate a computer keyboard and calculator.
• Requires normal range of hearing and vision.
• Possible on-call availability.
Our Culture:
Fueling customers' journeys since 1964, innovation leads the way for this family-owned and operated business headquartered in Oklahoma City. With nearly 40,000 team members, travel stops are the core business along with products and services that provide value for professional drivers, fleets, traveling public, RVers, alternative energy and wholesale fuel customers. Giving back to communities and an inclusive workplace are hallmarks of the award-winning culture.
Love's is an Equal Opportunity Employer. Veterans encouraged to apply.
Nearest Major Market: Oklahoma City
Nearest Secondary Market: Oklahoma
Job Segment:
Compliance, Strategic Planning, Risk Management, Cyber Security, Internal Audit, Legal, Strategy, Finance, Security