Home › Companies › Cimgroup › Security Operations Manager
Security Operations Manager
Cimgroup · Phoenix, AZ · Hybrid · Active · Lever
Job facts
| Field | Value |
|---|---|
| Company | Cimgroup |
| Title | Security Operations Manager |
| Normalized title | - |
| Department / team | Technology and Operations / Information Technology |
| Location | Phoenix, AZ, United States |
| Work model | Hybrid / Hybrid |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | Lever |
| Posted / first seen | 2026-05-29 / 2026-05-30 |
| Changed / last seen | 2026-05-30 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Cimgroup. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through Lever. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Phoenix. | Open |
| Department jobs | Active postings in Technology and Operations. | Open |
| Work model jobs | Active Hybrid postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Cimgroup |
| Source | 46684017-47df-4b73-8e7e-95e7f8861395 |
| ATS provider | Lever |
Description
ABOUT CIM GROUP:
CIM is a community-focused real estate and infrastructure owner, operator, lender, and developer. Our team of experts works together to identify and create value in real assets, benefiting the communities in which we invest. Back in 1994, our three founders focused on projects in Southern California neighborhoods. Today, we are a diverse team of 900+ employees with projects across the Americas. Our projects have delivered jobs; created comfortable places to live, work, and relax; and provided necessary and sustainable infrastructure. Our focus on enhancing communities is unwavering, and we strive to make an even greater impact in the years to come. Join us and make an impact today!
POSITION PURPOSE:
The Security Operations Manager is accountable for CIMs’ readiness to prevent, respond to, and recover from cybersecurity incidents. This role is accountable for CIM’s cybersecurity posture by ensuring the appropriate controls are in place, our user population has the necessary cybersecurity training, and the day-to-day management of cybersecurity threats are handled appropriately. The Security Operations Manager partners closely with Engineering, Support, Compliance, and Product teams to ensure controls are effective, risks are actively managed, and operations support overall business continuity and resilience objectives.
This role plays a critical part in protecting our customers, employees, and operations, while enabling the business to grow securely and confidently.
WHAT CIM OFFERS:
At CIM, we believe our success stems from our collective efforts, and we are committed to providing well-rounded support and resources for our employees. In addition to a competitive compensation plan, CIM offers a comprehensive benefits program for employees to thrive both inside and outside of work. Eligible employees can enjoy a wide range of benefits, including:
A variety of Medical, dental, and vision benefit plans
Health Savings Account with a generous employer contribution
Company paid life and disability insurance
401(k) savings plan, with company match
Comprehensive paid time off, including: vacation days, 10 designated holidays, sick time, and bereavement leave
Up to 16 hours of volunteer time off
Up to 16 weeks of Paid Parental Leave
Ongoing professional development programs
Wellness program, including monthly and quarterly prizes
And more!
Actual base salary considers several factors including but not limited to geography, job-related knowledge, experience, and budget. The start of the salary range is typically associated with the minimum experience required.
#LI-BL1
HOW WE FEEL ABOUT DIVERSITY AND INCLUSION:
At CIM Group, we believe that the unique perspectives and backgrounds of our employees enhance everything we do. We are committed to fostering an inclusive environment where diversity is not only respected but celebrated. We strive to ensure that our workplace is free from discrimination and harassment, allowing everyone to contribute meaningfully and feel a sense of belonging. As an equal opportunity employer, we strictly prohibit any form of unlawful discrimination and adhere to the laws enforced by the EEOC. Our goal is to provide a safe and supportive environment where all employees can grow and make impactful contributions together.
*Applicants with disabilities may be entitled to reasonable accommodation under the terms of the Americans with Disabilities Act and certain state or local laws. A reasonable accommodation is a change in the way things are normally done which will ensure an equal employment opportunity without imposing undue hardship on CIM Group. Please inform our Talent team if you need any assistance completing any forms or to otherwise participate in the application process.
CIM is committed to maintaining the confidentiality and privacy of your personal and financial information. Please click here for our Privacy Policy.
CIM does not accept unsolicited resumes from Agencies. Any unsolicited resumes received from Agencies will be considered property of CIM and no fees will be due or paid. If you wish to become an approved Agency with CIM or any of its Affiliates, please contact a member of the CIM Talent Acquisition Team.
ESSENTIAL FUNCTIONS:
Security Operations & Incident Response
Ensure security alerts and anomalous activities are continuously monitored, accurately logged, and escalated in accordance with established procedures.
Lead and coordinate timely, effective response to cybersecurity incidents to minimize business impact.
Support restoration of affected systems and services following cybersecurity incidents, including leading forensic investigations as required.
Research emerging threats and attack vectors, and implement appropriate countermeasures to continuously strengthen the organization’s security posture.
Coordinate internal and external penetration testing activities to identify and remediate exploitable weaknesses.
Risk Management, Controls & Assurance
Ensure protective security controls are implemented and operating effectively to reduce risk exposure.
Coordinate with compliance and IT teams to design, implement, and maintain operational security controls.
Support asset cataloging and ownership alignment to ensure accountability for systems, data, and security controls.
Execute quarterly User Access Reviews across the application portfolio in an efficient manner.
Respond to external audit and compliance questionnaires, providing accurate and timely security documentation and evidence.
Security Awareness & Enablement
Ensure employees, vendors and/or contractors with access to systems and data are appropriately trained in relevant security awareness and individual security responsibilities.
Design, manage, and enforce the organization’s security awareness program, including the execution of recurring phishing simulation campaigns.
Support the development, testing, and ongoing improvement of Disaster Recovery plans to ensure the organization can effectively respond to and recover from disruptive events, including cybersecurity incidents.
Serve as a trusted security advisor to internal teams, raising awareness and providing guidance to help protect products, systems, and services from known and emerging threats.
NON-ESSENTIAL FUNCTIONS:
Ability to produce executive reporting to illustrate Cybersecurity posture and areas for improvement.
Ability to communicate and present ideas and recommendations effectively to Technology management.
Ability to translate Cybersecurity information into a manner that end users can understand.
SUPERVISORY RESPONSIBILITIES:
None.
EDUCATION/EXPERIENCE REQUIREMENTS: (including certification, licenses, etc.)
Minimum 8 years of Cybersecurity analyst/management experience.
Bachelor’s Degree in a technical field required.
CISSP or CISM certification strongly preferred.
Formal training in Cybersecurity governance, risk, and compliance (GRC).
Understanding of Cybersecurity communities (OWASP).
Understanding of SOC 2, SOX, NIST, and GDPR compliance.
KNOWLEDGE, SKILLS AND ABILITIES:
Expert knowledge of information security principles, practices, and architectures.
Expert knowledge with Threat Detection, Email Security, DLP, Data Governance tools such as Proofpoint, MS Defender, or Mimecast.
Hands-on experience with the development of Cybersecurity Training and Phishing Campaigns.
Experience with leading Disaster Recovery programs.
Experience with Vulnerability Management Platforms such as Rapid7 and Qualys.
Experience with Patch Management platforms such as SCCM and Ivanti.
Understanding of supporting technology audits and testing technology controls.
Understanding of cloud environments such as Azure, SalesForce.com and Office365.
PERFORMANCE METRICS:
Regular reporting of key Cybersecurity metrics for the company to executive management.
Year over year Improvement of scores within the vulnerability management platform.
Meet all compliance requirements related to Cybersecurity.
Timely completion of preventive Cybersecurity measures such as User Access Reviews, End User Cybersecurity Training, and Phishing Campaigns.
Reduction of Cybersecurity issues uncovered by 3 rd party security testing and compliance audits.
Disaster Recovery readiness score.
Full job record
| Job ID | 32f70266a623236fefb0d065b753c6af019b0d6b |
| Org ID | c8b15639-da7d-4f0a-b9c7-d54ecd0edcdd |
| Source ID | 46684017-47df-4b73-8e7e-95e7f8861395 |
| Board ID | 46684017-47df-4b73-8e7e-95e7f8861395 |
| Provider | lever |
| Provider Job Key | a0a392b0-07c5-48ef-80c4-d2d59852f9dd |
| Title | Security Operations Manager |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Phoenix, AZ |
| Department | Technology and Operations |
| Team | Information Technology |
| Employment Type | Full Time |
| Workplace Type | hybrid |
| Remote Policy | hybrid |
| Country | United States |
| Region | AZ |
| City | Phoenix |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://jobs.lever.co/cimgroup/a0a392b0-07c5-48ef-80c4-d2d59852f9dd |
| Apply URL | https://jobs.lever.co/cimgroup/a0a392b0-07c5-48ef-80c4-d2d59852f9dd/apply |
| First Seen At | 2026-05-30 07:35:20Z |
| Last Seen At | 2026-06-06 20:05:04Z |
| Last Checked At | 2026-06-06 20:05:04Z |
| Last Changed At | 2026-05-30 07:35:20Z |
| Inactive At | — |
| Source Posted At | 2026-05-29 23:45:29Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=lever/board=cimgroup/date=2026-06-06/2026-06-06T20-05-02-395Z-27db39fbd9bee73f64aa40ba97eb5fea9df5de7eb3f6acb2fa7ff0b319a06c48.json |
Event Fields
{
"content_hash": "b7b7addfe47fd9f67d5372cca04eb222a1ab2cc0c2b1c14f93b70a08305b0bd1",
"source_hash": "a021cddd10e157fe1161b20c693b58de397ed029fdc5449ceea4f1a9dbc39292",
"last_changed_at": "2026-05-30T07:35:20.413Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Phoenix, AZ",
"city": "Phoenix",
"region": "AZ",
"country": "United States",
"is_remote": false,
"confidence": 0.9
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T20:05:04.054Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "Phoenix, AZ",
"city": "Phoenix",
"region": "AZ",
"country": "United States",
"is_remote": false,
"confidence": 0.9
},
"countries": [
"United States"
]
},
"remote_policy": "hybrid",
"salary_period": null,
"workplace_type": "hybrid",
"salary_currency": null
}Extensions
{}Native Structured
{
"lists": [
{
"text": "ESSENTIAL FUNCTIONS:",
"content": "<div>\n<p><strong>Security Operations & Incident Response</strong></p>\n\n<li>Ensure security alerts and anomalous activities are continuously monitored, accurately logged, and escalated in accordance with established procedures.</li>\n<li>Lead and coordinate timely, effective response to cybersecurity incidents to minimize business impact.</li>\n<li>Support restoration of affected systems and services following cybersecurity incidents, including leading forensic investigations as required.</li>\n<li>Research emerging threats and attack vectors, and implement appropriate countermeasures to continuously strengthen the organization’s security posture.</li>\n<li>Coordinate internal and external penetration testing activities to identify and remediate exploitable weaknesses.</li>\n\n<p><strong>Risk Management, Controls & Assurance</strong></p>\n\n<li>Ensure protective security controls are implemented and operating effectively to reduce risk exposure.</li>\n<li>Coordinate with compliance and IT teams to design, implement, and maintain operational security controls.</li>\n<li>Support asset cataloging and ownership alignment to ensure accountability for systems, data, and security controls.</li>\n<li>Execute quarterly User Access Reviews across the application portfolio in an efficient manner.</li>\n<li>Respond to external audit and compliance questionnaires, providing accurate and timely security documentation and evidence.</li>\n\n<p><strong>Security Awareness & Enablement</strong></p>\n\n<li>Ensure employees, vendors and/or contractors with access to systems and data are appropriately trained in relevant security awareness and individual security responsibilities.</li>\n<li>Design, manage, and enforce the organization’s security awareness program, including the execution of recurring phishing simulation campaigns.</li>\n<li>Support the development, testing, and ongoing improvement of Disaster Recovery plans to ensure the organization can effectively respond to and recover from disruptive events, including cybersecurity incidents.</li>\n<li>Serve as a trusted security advisor to internal teams, raising awareness and providing guidance to help protect products, systems, and services from known and emerging threats.</li>\n\n</div>"
},
{
"text": "NON-ESSENTIAL FUNCTIONS:",
"content": "<div>\n\n<li>Ability to produce executive reporting to illustrate Cybersecurity posture and areas for improvement.</li>\n<li>Ability to communicate and present ideas and recommendations effectively to Technology management.</li>\n<li>Ability to translate Cybersecurity information into a manner that end users can understand.</li>\n\n</div>"
},
{
"text": "SUPERVISORY RESPONSIBILITIES: ",
"content": "<div>\n\n<li>None.</li>\n\n</div>"
},
{
"text": "EDUCATION/EXPERIENCE REQUIREMENTS: (including certification, licenses, etc.)",
"content": "<div>\n\n<li>Minimum 8 years of Cybersecurity analyst/management experience.</li>\n<li>Bachelor’s Degree in a technical field required.</li>\n<li>CISSP or CISM certification strongly preferred.</li>\n<li>Formal training in Cybersecurity governance, risk, and compliance (GRC).</li>\n<li>Understanding of Cybersecurity communities (OWASP).</li>\n<li>Understanding of SOC 2, SOX, NIST, and GDPR compliance.</li>\n\n</div>"
},
{
"text": "KNOWLEDGE, SKILLS AND ABILITIES:",
"content": "<div>\n\n<li>Expert knowledge of information security principles, practices, and architectures.</li>\n<li>Expert knowledge with Threat Detection, Email Security, DLP, Data Governance tools such as Proofpoint, MS Defender, or Mimecast.</li>\n<li>Hands-on experience with the development of Cybersecurity Training and Phishing Campaigns.</li>\n<li>Experience with leading Disaster Recovery programs.</li>\n<li>Experience with Vulnerability Management Platforms such as Rapid7 and Qualys.</li>\n<li>Experience with Patch Management platforms such as SCCM and Ivanti.</li>\n<li>Understanding of supporting technology audits and testing technology controls.</li>\n<li>Understanding of cloud environments such as Azure, SalesForce.com and Office365.</li>\n\n</div>"
},
{
"text": "PERFORMANCE METRICS:",
"content": "<div>\n\n<li>Regular reporting of key Cybersecurity metrics for the company to executive management.</li>\n<li>Year over year Improvement of scores within the vulnerability management platform.</li>\n<li>Meet all compliance requirements related to Cybersecurity.</li>\n<li>Timely completion of preventive Cybersecurity measures such as User Access Reviews, End User Cybersecurity Training, and Phishing Campaigns.</li>\n<li>Reduction of Cybersecurity issues uncovered by 3<sup>rd</sup> party security testing and compliance audits.</li>\n<li>Disaster Recovery readiness score.</li>\n\n</div>"
}
],
"country": "US",
"createdAt": 1780098329603,
"updatedAt": null,
"categories": {
"team": "Information Technology",
"location": "Phoenix, AZ",
"commitment": "Full Time",
"department": "Technology and Operations",
"allLocations": [
"Phoenix, AZ"
]
},
"salaryRange": null,
"workplaceType": "hybrid"
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/32f70266a623236fefb0d065b753c6af019b0d6b?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/c8b15639-da7d-4f0a-b9c7-d54ecd0edcddJSONGET https://api.bluedoor.sh/job-postings/v1/sources/46684017-47df-4b73-8e7e-95e7f8861395JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/32f70266a623236fefb0d065b753c6af019b0d6b/eventsJSON