Cyber Security Program Manager

QuikTrip CorporationTulsa, OK
1d$146,000 - $182,520

About The Position

The Cyber Security Program Manager is responsible for leading and operationalizing QuikTrip’s Enterprise Cyber Security Program, including the development, implementation, and continuous improvement of security strategy, practices, and standards across the corporation and its subsidiaries. This role serves as the day‑to‑day manager of enterprise cybersecurity initiatives—coordinating governance, driving security execution, and ensuring alignment with organizational objectives. In addition to core cybersecurity program responsibilities, this position serves as the primary cybersecurity leader for QuikTrip’s subsidiaries—ensuring their security operations, controls, and governance align with enterprise standards. The role also supports broader regulatory and compliance initiatives such as Payment Card Industry (PCI), contributes to the development and maintenance of the Enterprise Privacy Program, and operates as the HIPAA Compliance Officer to uphold all security requirements related to protected health information.

Requirements

  • Bachelor’s Degree, preferably in MIS or Computer Science or equivalent work experience.
  • Extensive experience in cybersecurity program management and operations. 8+ years of cybersecurity practices and technologies spanning risk management, governance, architecture, cloud security, threat detection, incident response, and vulnerability management. Intimately familiar with cyber security frameworks like NIST and CIS.
  • Solid grasp of the issues associated with standards, compliance, security, and disaster recovery including the costs, benefits, and risks to the company.
  • Strong oral and written communications skills.
  • Project leadership skills.
  • Must be able to work under pressure and provide guidance to Information Technology users during crisis modes.
  • On call 24 by 7. This position requires the employee to be available by phone and/or email and/or have accessibility to calendar, contacts and data while out of the office.

Nice To Haves

  • Certification as an Information Systems Security Professional. (CISM, CISA, CISSP, SANS, or equivalent)
  • Disaster Recovery planning, CSIRT, regulatory compliance (PCI, HIPAA, Privacy), ITIL
  • AD and MS servers, AS400, security and audit tools, Network and Telecommunications experience.

Responsibilities

  • Assist in developing and overseeing QuikTrip’s Enterprise Cyber Security Strategy, practices, and programs. Assist in planning and implementing security for all computing hardware and software systems.
  • Assist and advise user departments in appropriate security procedures.
  • Protect the corporate computing infrastructure from unauthorized access.
  • Protect the company network from attacks.
  • Protect the confidentiality of company data and employee information.
  • Oversee the development and maintenance of Information Technology security and compliance standards.
  • Set policy on introduction of third-party software to the network, implement end point protection software, and monitor compliance.
  • Assist in the maintenance, development, and operation of QuikTrip’s Privacy program.
  • Governance - Ensure policies, standards and procedures are kept up to date, monitor adherence to program, establish and maintain Privacy Committee involving business leaders from across the enterprise.
  • Ensure Privacy Impact Assessments are continually run across projects or efforts around privacy, continual development of processes related to PIA’s, and perform regular compliance assessments to validate policies are affecting and being adhered to.
  • Ensure Continuous Compliance Monitoring across the enterprise to make sure the Privacy program is operating effectively. This will include audits of process, third party, controls, reporting and incident response measures.
  • Ensure the creation of a Personal Data Inventory, including usage, processing activities, data retention and anonymization.
  • Ensure Awareness, Training, and other communications related to the Privacy program are in place and effective.
  • Liaise and communicate effectively with external entities, such as supervisory and regulatory authorities. Ensure Cyber Security program follows relevant industry and governmental standards, including but not limited to the Payment Card Industry Data Security Standard and HIPAA Standard.
  • Fill the role of HIPAA Security Officer (HSO) by managing information security policies, procedures, and technical systems to maintain the confidentiality, integrity, and availability of healthcare information systems, conducting investigations, and maintaining records.
  • Keep apprised of changes to the standard.
  • Evaluate new systems for impact.
  • Conduct annual PCI audit and submit result to QuikTrip’s acquirer.
  • Directing the work effort and providing information to internal and external resources as required.
  • Conduct an annual risk assessment of QuikTrip’s systems, evaluating risk of loss versus operating cost. Present results to Senior Management for review and acceptance.
  • Develop and produce metrics on IT Security for Board of Directors, IT Leadership, and general QT employees.
  • On request of management, present reports concerning security-related activity of specific employees or vendors.
  • Interface with QT internal auditors, financial auditors, PCI auditors, and any other external auditors as required. Provide any requested information and arrange meetings with QT personnel. Provide responses and compensating controls to audit comments.
  • Provide security support to IT department and the Company at large.
  • Lead troubleshooting efforts to resolve security issues and problems for QT systems.
  • Work with technology groups to provide general security direction, guidelines, and controls.
  • Ensure the technical design of all major systems have the appropriate levels of technology security as well as making sure all new systems adhere to QuikTrip security standards. Conduct risk assessments of new technology and custom applications.
  • Contribute to IT Strategic Planning and budgeting process, as well as day-to-day security planning, by analyzing future security needs, make recommendations on computer hardware, software, and processes.

Benefits

  • Employee Benefits – QuikTrip
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service