Manager - Information Security
The Cybersecurity Operations Center (SOC) Manager in the Office of Information Security is responsible for leading, managing, and continuously improving the SOC. This role oversees coverage for day-to-day 24x7 incident monitoring, including detection, triage, investigation, containment, eradication, and recovery of cybersecurity incidents. The SOC Manager provides leadership to SOC analysts by setting expectations, developing talent, identifying skill gaps, and promoting a culture of accountability, collaboration, and operational excellence. The position collaborates with Information Security teams such as IAM, Data Protection, Application Protection, Infrastructure Protection, Threat Intelligence, Detection Engineering, Security Testing Services, Information Security Awareness & Education, Information Technology as well as business proponents to ensure information security incidents are remediated in a timely manner. The SOC Manager supports healthcare regulatory compliance, audit readiness, and evidence retention while ensuring SOC processes align with frameworks such as NIST CSF 2.0, NIST SP 800-61, and HIPAA regulations. This leader develops and reports executive-level metrics, including MTTD, MTTR, incident trends, escalation rates, analyst productivity, and SLA performance, to demonstrate SOC effectiveness and operational maturity. The SOC Manager also evaluates detection and response capabilities, advances AI and automation opportunities, and enhances operational efficiencies to reduce organizational cyber risk, strengthen team performance, and deliver measurable cybersecurity value.
The Information Security Manager provides operational and tactical leadership for a defined security service, function, or team. This role translates Information Security strategy, risk requirements, and policies into effective day to day execution; ensures reliable, compliant service delivery; and fosters a strong security culture. Operating within the Risk organization, the Manager partners with business and technology stakeholders to identify, assess, and manage information security risk in a regulated environment.
This position is hybrid and needs to live within 100 miles from one of the following sites: Rochester, MN, Jacksonville, FL, Phoenix, AZ, La Crosse, WI, Eau Claire, WI and Mankato, MN.
This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.
Bachelors degree in applicable field plus eight (8) years of relevant experience.
Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, risk management, or a related field.
Three years leadership/management experience (i.e. guiding technical staff, leading technical projects, or leading teams).
Master’s degree in applicable field plus six (6) years of relevant experience preferred.
Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, risk management, or a related field.
Three years leadership/management experience (i.e. guiding technical staff, leading technical projects, or leading teams).
One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP..