Senior Manager of Cyber Security in Clark, New Jersey at Turtle and Hughes
Explore Related Opportunities
Job Description
Why Turtle?
At Turtle, we’re redefining what it means to be an industry leader in electrical distribution, and we want you to be part of our exciting journey! For over 100 years, we’ve built a reputation for innovation, excellence, and exceptional customer service—and we’re just getting started. We are a diverse, passionate team spread across the US, Canada, Mexico, and Puerto Rico, committed to growth, learning, and creating opportunities for each other. At Turtle, every day is a chance to make a real difference, solve complex challenges, and push the boundaries of what’s possible. We believe in fostering an environment that inspires collaboration and sparks creativity, where employees are empowered to contribute to our mission and shape the future of the industry. If you're looking for a fast-paced, dynamic career where your ideas are valued and your growth is prioritized, Turtle is the place for you. Join us and be a part of a company that’s making waves and empowering its people to do extraordinary things every single day!
About the Role
The Sr. Manager of Cyber Security is a hands-on technical manager responsible for executing and managing Turtle’s day-to-day cybersecurity operations, program compliance, and team performance. Reporting to the Chief Technology and Information Security Officer (CTISO), this role bridges tactical security operations with programmatic oversight—actively working within security toolsets, leading incident response, managing the organization’s Managed Security Service Provider (MSSP) relationship, and owning the compliance posture across ISO 27001, NIST CMMC Level 2, and the organization’s aspirational ISO 9001 program. The Director leads a team with dedicated coverage across Governance, Risk, and Compliance (GRC) and technical security operations, and drives continuous improvement across people, process, and technology.
This is a USA based position. The Director of Cyber Security is expected to travel to the Corporate headquarters in Clark, NJ as needed, approximately 1–2 times per quarter. Additional travel to USA branch locations will be required on occasion. The role requires availability for after-hours response in the event of a security incident.
What You'll Do:
Security Operations & Tactical Management:
- Manage the organization’s security operations function, serving as a hands-on practitioner across the security toolset; accountable for threat monitoring, vulnerability management, and incident response from detection through post-incident review.
- Maintain and continuously improve security controls and tooling configurations across endpoint, network, email, and identity environments, in coordination with the MSSP and technical staff.
- Own the phishing simulation program and enforce associated security policies, coordinating outcomes with HR and department management as required.
MSSP & Vendor Management:
- Support and manage the MSSP relationship end-to-end; direct day-to-day service activities, hold the provider accountable to SLAs, and ensure threat detection and incident escalation protocols meet organizational requirements.
- Manage security vendor relationships across the technology portfolio and oversee the vendor risk register.
Compliance & Governance:
- Enforce the organization’s compliance posture for ISO 27001 and NIST CMMC Level 2; direct the GRC function across evidence maintenance, risk register management, policy governance, and audit readiness.
- Provide framework ownership for the organization’s ISO 9001 program; owns the GDP framework alignment and cross-functional coordination, while operational teams retain ownership of document content and process definitions.
- Ensure all internal and external audit activity is effective through the GRC Program Manager, for nonconformance tracking, root-cause analysis, and findings closure.
AI Governance & Risk:
- Represent Cyber Security’s independent role in Turtle’s three-party AI governance model, serving as the security and risk voice alongside the CTO (AI strategy, budget, and vendor governance) and Data Services & Enterprise Architecture (AI roadmap execution) to evaluate, approve, and monitor AI tool adoption across the organization.
- Own the AI security risk function, including model and data leak security across AI platforms, shadow AI detection and unsanctioned LLM governance, third party AI vendor risk assessments, and enforcement of AI acceptable use policy for all deployed systems.
Team Management:
- Lead, develop, and retain the cybersecurity team; establish operating cadences, manage performance, and define training and certification roadmaps aligned to role requirements.
- Define and report team KPIs covering security posture, compliance status, and program health to the CTISO; serve as the primary escalation point and cross-functional liaison for cybersecurity matters across the organization.
Security Awareness & Training:
- Own the Security Awareness Training program—including onboarding, annual refreshers, role-based content, and phishing simulations—track outcomes and enforce policy requirements in coordination with HR and department managers.
What You'll Bring
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field; equivalent work experience strongly considered in lieu of degree.
- 5–7 years of progressive, hands-on cybersecurity experience, with at least 2 years in a leadership or team management capacity.
- Demonstrated hands-on experience administering and operating security technologies including SIEM, EDR/XDR, vulnerability management platforms, and MFA/identity protection.
- Working knowledge of and operational experience with ISO 27001 and NIST frameworks (CMMC Level 2 / SP 800-171); direct experience owning or managing compliance to these standards is required.
- Experience managing MSSPs and security technology vendors, including SLA oversight, performance management, and contract review.
- Proven ability to lead incident response end-to-end
- Experience directing or working within a GRC function; familiarity with audit coordination, risk register management, and nonconformance processes.
- Familiarity with Good Documentation Practices (GDP) and quality management framework alignment (ISO 9001 exposure a plus).
- Familiarity with AI governance frameworks and emerging AI risk principles; ability to assess AI tools for security, data privacy, and compliance implications in an enterprise context.
- Relevant certifications are not required, but are beneficial to the candidate, including CISSP, CISM, or relevant GIAC certifications.
What We Offer
We offer a competitive benefits package that includes:
- 401(k) plan
- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- Paid holidays
- Vacation
- Employee negotiated discounts
Who We Are
Founded in 1923, Turtle is a fourth-generation, family-owned, and three-generation women-owned business, and one of the nation’s largest independent electrical and industrial distributors. Headquartered in Clark, NJ, our Electrical Distribution division operates 14 branches spanning from coast to coast. It is a significant force in the engineering and procurement of power distribution, automation, lighting, and energy projects, offering integrated services for the industrial and construction markets. Turtle Integrated provides on-site MRO procurement, cost-saving, and spend analytics across the US and in Canada, Puerto Rico, and Mexico.
What To Do Next
You can begin by filling out our application online. If you want to learn more about Turtle, please visit our website www.turtle.com or our LinkedIn: @Turtle.
Turtle is proud to be is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, gender identity or expression, national origin, disability, genetic information, pregnancy, marital status, military or veteran status, or any other protected characteristic as outlined by federal, state, or local laws.