Company Overview
Credit First National Association is a private label credit card bank and the consumer credit division of Bridgestone Americas. The Bridgestone Americas family of enterprises, including CFNA, is comprised of more than 50 production facilities and 55K employees throughout the Americas. We provide the consumer credit solution for the Firestone Complete Auto Care, Tires Plus, and Wheel Works brands, in addition to customized retail credit services for more than 8,000 other tire and automotive retailers nationwide. At our office in Cleveland, OH, more than 300 professionals gather each day to run a successful private label credit card program. We invest in our community and strongly believe that meaningful commitment to a wide variety of philanthropic organizations builds a better world and a brand that makes us proud.
Information Technology
The Manager of Cyber Security operations leads a team who support, design and implement security strategies to protect CFNA systems and networks. This is a hands-on role and requires technical expertise in the IT and Cyber Security space.
**This role is a hybrid role and will require at least 2 days per week on site in our Brook Park office location**
Responsibilities:
• Assists with performing IT risk assessments
• Maintains working relationships with functional and operational areas to ensure that the Information and Cyber security standards, procedures, and policies are followed.
• Monitors security controls to ensure their functionality and performing as designed
• Monitors alerts and events and perform remediation as needed.
• Works as part of a team to ensure regulatory compliance.
• Provides feedback on partner performance to Application Managers to ensure vendor adherence to established guidelines related to quality, price, delivery, etc.
• Implement controls to secure CFNA systems and data.
• Works with the Manager of Platform Services and Support to secure the environment and implement security measures for the organization.
• Act as a consultant to different business areas relating to security best practices and requirements.
Requirements:
• Bachelor's degree in IT or related curriculum, plus 5+ years of experience in defining and implementing enterprise security programs.
• 2-5 years of experience managing a PCI-DSS program
• Deep understanding of cloud and network security and compliance in cloud-native technologies.
• Proficiency in programming or scripting languages.
• Experience with security tools for threat mitigation and risk reduction: vulnerability scanners, firewalls, IDS/IPS, etc.
• Knowledge of networking and web protocols, with skills in traffic analysis for anomaly detection.
• Familiarity with modern cloud components and security vulnerabilities: VMs, containers, Kubernetes, infrastructure as code, etc.
• Proven collaboration skills in achieving complex objectives.
• Experience in banking/financial services
• Experience with at least 3 security control frameworks (ISO/IEC 27001, SOC-2, NIST CSF, COSO, COBIT, etc.).
• At least one industry standard certification in information or cloud security (CISM, CCSK, CCSP, CISSP, etc.)
• Relevant Experience in the following Technologies:
o SIEM
o Firewalls
o Intrusion Detection/Prevention Systems
o Data Loss Prevention
o Web Filtering
o Encryption Technologies and techniques
o Mobile Data Management (MDM)
o Network Access Controls
o Web Proxy
o Disaster Recovery/Business Continuity
o Third Party Management
Typically requires a minimum of 12 years of related experience with a bachelor’s degree; or 8 years and a master’s degree; or a PhD with 5 years of experience; or equivalent work experience
Bridgestone is proud to be an Equal Employment Opportunity / Affirmative Action employer. It is our policy to consider for employment all individuals regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, gender, sex, sexual orientation, gender identity and/or expression, genetic information, veteran status, or any other characteristic protected by federal, state or local law.
Employment Eligibility
If hired, a Form I-9 Employment Eligibility Verification must be completed at the start of employment. Temporary work authorization or the need for sponsorship may disqualify you from employment.