IT/InfoSec Manager in Folsom, California at TaxResources Inc
Explore Related Opportunities
Job Description
IT & Information Security Manager
Company TaxAudit
Reports To Director of Technology
Role Type Hands-on IT, Cloud Infrastructure, and Cybersecurity Leadership
Core Requirement AWS Architecture, Operations, Migration, Governance, and Security Ownership
Pay Rage $170,000 - $220,000
TaxAudit is a strong, forward-thinking national company that is #1 in our space, with over 30 years of continued success and growth. Our lean IT teams rely on exceptional employees who use their technical expertise, sound judgement, and collaboration to help move the company forward.
We are looking for a talented, committed, and hands-on IT & Information Security Manager to join a growing and motivated team working in a fast-paced, agile environment. The successful candidate will want to make a difference, work hard, collaborate well, lead with accountability, and help maintain the systems critical to the success of our employee-owned company.
Position Summary
TaxAudit is seeking an experienced, hands-on IT & Information Security Manager to lead IT operations, cloud infrastructure, and information security — including our continued migration to AWS. AWS experience is a core requirement: the successful candidate must be able to architect, operate, troubleshoot, govern, and secure production in AWS environments from both a technical and cybersecurity perspective.
This is a player/coach role reporting to the Director of Technology, managing a technical team that may include Network Engineers, Systems Engineers, and Information Security Engineers, while remaining hands-on across infrastructure, networking, Microsoft 365/Entra ID, cybersecurity, incident response, risk management, and application security. The role partners closely with Operations, Software Engineering, the Help Desk, Facilities, vendors, and executive leadership, and takes an AI-forward approach to execution using tools such as Claude, Kiro, AWS Bedrock, and Copilot.
Key Responsibilities
Leadership & Operations
• Lead IT operations and information security functions — infrastructure, cloud, cybersecurity, staffing, vendors, budgets, projects, and policy — and report regularly to executive leadership on risk, operations, and AWS migration progress.
• Manage IT staffing (recruiting, supervision, scheduling, development, evaluation, and performance/disciplinary actions) and build a focused, high-performing technical team.
• Own IT financial management, including budgeting, purchasing, vendor and contract negotiation, licensing/renewals, and AWS/cloud spend.
• Partner with the Help Desk on end-user issues and coordinate communication of infrastructure and security changes.
AWS Cloud & Enterprise Infrastructure
• Own technical delivery of the company’s continued migration of infrastructure, applications, and services to AWS, including evaluating workloads for migration, modernization, re-platforming, or retirement.
• Design, operate, and govern secure, scalable AWS environments — account structure, networking, compute/storage/database services, logging, monitoring, backup, and cost optimization (full stack detailed under Technical Environment).
• Maintain enterprise infrastructure spanning AWS, Microsoft 365/Entra ID, networking, firewalls, telecom, datacenter/colocation, and remaining on premises/VMware environments during the cloud transition.
• Oversee production availability, backup, disaster recovery, patching, capacity planning, and change management, with appropriate documentation.
Cybersecurity, Risk & Application Security
• Own the company’s cybersecurity architecture and posture across AWS, infrastructure, endpoints, applications, and users, including IAM/least-privilege design and AWS-native security tooling (see Technical Environment).
• Lead security operations — SIEM/SOC monitoring (Splunk Enterprise Security), detection, alerting, endpoint security (EDR/XDR), vulnerability management, and email/web security and awareness training — and serve as primary escalation point for incident response.
• Maintain the company’s NIST CSF-aligned cybersecurity governance program, including audits, assessments, cybersecurity insurance requirements, and customer/vendor security questionnaires.
• Partner with Software Engineering to build security into the SDLC — penetration testing, SAST/DAST, dependency and IaC scanning, and CI/CD security controls — including for cloud-native AWS applications.
• Maintain security policies, standards, and procedures, and track risks and remediation for leadership visibility.
Technical Environment
Candidates should have substantial hands-on experience with technologies and concepts including:
AWS / Cloud: AWS Organizations, IAM, VPC, EC2, S3, RDS, ELB/ALB, Route 53, CloudWatch, CloudTrail, GuardDuty, Security Hub, Inspector, Config, IAM Access Analyzer, KMS, WAF/Shield, Secrets Manager, AWS Backup, disaster recovery, and Infrastructure as Code.
AWS Security: Cloud security architecture, IAM/least privilege, workload security, encryption, key management, centralized logging, network segmentation, vulnerability management, incident response, cloud governance, and secure Infrastructure as Code.
Security Operations: Splunk Enterprise Security, SIEM, EDR/XDR, Cisco Secure Endpoint, Cisco Umbrella, vulnerability-management platforms, WAF, IDS/IPS, incident response, threat detection, and security monitoring.
Microsoft / Identity: Microsoft 365, Entra ID, Exchange Online, SSO, MFA, Conditional Access, identity lifecycle management, Active Directory, DNS, group policies, and DLP.
Infrastructure: VMware vSphere, VDI, Windows Server, enterprise networking, Cisco firewalls/switches/routers, storage, datacenter/colocation infrastructure, telecommunications, monitoring, backup, and disaster recovery.
Application Security / DevSecOps: Penetration testing, SAST/DAST, vulnerability remediation, Veracode or equivalent tooling, CI/CD security, Infrastructure as Code, and secure SDLC practices.
Required Qualifications
• 10+ years of progressive experience across IT infrastructure, cloud operations, and cybersecurity, including 5+ years leading technical teams or technology functions.
• Strong hands-on experience architecting, operating, troubleshooting, governing, and securing production AWS environments — including IAM, networking, logging/monitoring, and native AWS security services — plus experience leading or substantially contributing to migrations to AWS.
• Experience managing both enterprise IT operations and cybersecurity/security operations responsibilities, including building or operating SIEM/SOC and incident-response capabilities.
• Strong hands-on knowledge of Microsoft technologies (Microsoft 365, Entra ID, Windows Server, Active Directory, DNS, Exchange, group policies) and enterprise networking (Cisco IOS, router/switch configuration, SNMP, TCP/IP, WAN/LAN, firewalls, remote access).
• Strong understanding of vulnerability management, endpoint/network/identity/application/cloud security, and cybersecurity frameworks such as NIST CSF, including supporting security audits and assessments.
• Experience managing highly available production infrastructure, backup, and disaster-recovery environments.
• Strong analytical, oral communication, interpersonal, and technical/business writing skills, with the ability to translate complex technical and cybersecurity risk for executive and business leadership.
• Strong project-management, vendor-management, budget-management, and people-management skills; able to work independently, prioritize, and manage multiple initiatives amid changing business demands.
• Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent work experience.
Preferred Qualifications
• AWS certifications such as AWS Certified Solutions Architect and/or AWS Certified Security – Specialty.
• CISSP, CISM, CCSP, Microsoft, VMware, Cisco, or comparable professional certifications.
• MBA or advanced degree with a technology, cybersecurity, or business leadership focus.
• Experience with Infrastructure as Code and cloud automation.
• Experience securing cloud-native applications, containers, APIs, and CI/CD environments.
• Experience operating in organizations with mature cybersecurity, compliance, audit, and cybersecurity insurance requirements.
Physical Demands and Work Environment
• This is a hybrid position based in Folsom, CA, with several days on-site required initially for onboarding, on-site visits with the team at least once per month, plus occasional additional travel for company-wide events or meetings with executive leadership as needed.
• On-call availability is required.
• Requirements include close vision and the ability to give and receive information through speaking and listening.
• This role requires the ability to use a computer keyboard, mouse, and other devices for significant portions of the workday. It may also require occasional handling of computer components, tools, cables, and moderately heavy objects such as computers and peripherals, as well as occasional inspection of cables in floors and ceilings.
• A remote work environment requires reliable high-speed internet access, and a dedicated workspace that is quiet, private, and free from distractions.
These physical requirements are intended to describe the general nature of the work and are not exhaustive. Additional job-related physical requirements may apply as needed.
Tax Audit is an equal opportunity employer. We consider qualified applicants without regard to legally protected characteristics and are committed to maintaining a respectful, inclusive, and accessible workplace.