Now hiring

Cyber Security Program Manager (TULSA, OK, US, 74134) @ QTR Corporation

TULSA, OK, US, 74134OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p style="margin:0.0in;Times New Roman', serif;font-weight:bold"><span style="">Primary Purpose of Job:</span></p> <p style="text-align:justify;margin:0.0in;Times New Roman', serif"><span style="">The Cyber Security Program Manager is responsible for leading and operationalizing QuikTrip’s Enterprise Cyber Security Program, including the development, implementation, and continuous improvement of security strategy, practices, and standards across the corporation and its subsidiaries. This role serves as the day‑to‑day manager of enterprise cybersecurity initiatives—coordinating governance, driving security execution, and ensuring alignment with organizational objectives. In addition to core cybersecurity program responsibilities, this position serves as the primary cybersecurity leader for QuikTrip’s subsidiaries—ensuring their security operations, controls, and governance align with enterprise standards. The role also supports broader regulatory and compliance initiatives such as Payment Card Industry (PCI), contributes to the development and maintenance of the Enterprise Privacy Program, and operates as the HIPAA Security Officer to uphold all security requirements related to protected health information.</span></p> <h3 style="text-align:justify;margin:0.0in;Times New Roman', serif"><span style=""> </span></h3> <h3 style="text-align:justify;margin:0.0in;Times New Roman', serif"><span style="">Major functions for this position:</span></h3> <p style="margin:0.0in 0.0in 0.0in 59.0pt;text-align:justify;text-indent:-59.0pt;Times New Roman', serif"> </p> <ol style="margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><strong><span style="">Assist in developing and overseeing QuikTrip’s Enterprise Cyber Security Strategy, practices, and programs. Assist in planning and implementing security for all computing hardware and software systems. (60%)</span></strong> <ol style="list-style-type:lower-alpha;margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Assist and advise user departments in appropriate security procedures.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Protect the corporate computing infrastructure from unauthorized access.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Protect the company network from attacks.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Protect the confidentiality of company data and employee information.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Oversee the development and maintenance of Information Technology security and compliance standards.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Set policy on introduction of third-party software to the network, implement end point protection software, and monitor compliance. </span></li> </ol> </li> </ol> <p style="margin:0.0in 0.0in 0.0in 14.75pt;text-align:justify;Times New Roman', serif"> </p> <ol style="margin-bottom:0.0in;margin-top:0.0px" start="2"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><strong><span style="">Assist in the maintenance, development, and operation of QuikTrip’s Privacy program. (5%)</span></strong> <ol style="list-style-type:lower-alpha;margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Governance - Ensure policies, standards and procedures are kept up to date, monitor adherence to program, establish and maintain Privacy Committee involving business leaders from across the enterprise. </span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Ensure Privacy Impact Assessments are continually run across projects or efforts around privacy, continual development of processes related to PIA’s, and perform regular compliance assessments to validate policies are affecting and being adhered to.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Ensure Continuous Compliance Monitoring across the enterprise to make sure the Privacy program is operating effectively. This will include audits of process, third party, controls, reporting, and incident response measures.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Ensure the creation of a Personal Data Inventory, including usage, processing activities, data retention, and anonymization.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Ensure Awareness, Training, and other communications related to the Privacy program are in place and effective.<br><br></span></li> </ol> </li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><a name="_heading=h.2et92p0"></a><a name="_heading=h.tyjcwt"></a><a name="_heading=h.3dy6vkm"></a><a name="_heading=h.1t3h5sf"></a><a name="_heading=h.4d34og8"></a><strong><span style="">Liaise and communicate effectively with external entities, such as supervisory and regulatory authorities. </span></strong><strong><span style="">Ensure Cyber Security program follows relevant industry and governmental standards, including but not limited to the Payment Card Industry Data Security Standard and HIPAA Standard. (10%)</span></strong> <ol style="list-style-type:lower-alpha;margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Fill the role of HIPAA Security Officer (HSO) by managing information security policies, procedures, and technical systems to maintain the confidentiality, integrity, and availability of healthcare information systems, conducting investigations, and maintaining records.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Keep apprised of changes to the standard.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Evaluate new systems for impact.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Conduct annual PCI audit and submit result to QuikTrip’s acquirer.</span></li> </ol> </li> </ol> <p style="text-align:justify;margin:0.0in;Times New Roman', serif"> </p> <ol style="margin-bottom:0.0in;margin-top:0.0px" start="4"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><strong><span style="">Directing the work effort and providing information to internal and external resources as required. (10%)</span></strong> <ol style="list-style-type:lower-alpha;margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Conduct an annual risk assessment of QuikTrip’s systems, evaluating risk of loss versus operating cost. Present results to Senior Management for review and acceptance.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Develop and produce metrics on IT Security for Board of Directors, IT Leadership, and general QT employees. </span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">On request of management, present reports concerning security-related activity of specific employees or vendors.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Interface with QT internal auditors, financial auditors, PCI auditors, and any other external auditors as required. Provide any requested information and arrange meetings with QT personnel. Provide responses and compensating controls to audit comments.</span></li> </ol> </li> </ol> <p style="text-align:justify;margin:0.0in;Courier New'"> </p> <ol style="margin-bottom:0.0in;margin-top:0.0px" start="5"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><strong><span style="">Provide security support to IT department and the Company at large. (5%)</span></strong> <ol style="list-style-type:lower-alpha;margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Lead troubleshooting efforts to resolve security issues and problems for QT systems. </span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Work with technology groups to provide general security direction, guidelines, and controls.</span></li> </ol> </li> </ol> <p style="margin:0.0in 0.0in 0.0in 32.75pt;text-align:justify;Times New Roman', serif"> </p> <ol style="margin-bottom:0.0in;margin-top:0.0px" start="6"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><strong><span style="">Ensure the technical design of all major systems have the appropriate levels of technology security as well as making sure all new systems adhere to QuikTrip security standards. Conduct risk assessments of new technology and custom applications. (5%)</span></strong></li> </ol> <p style="margin:0.0in 0.0in 0.0in 32.75pt;text-align:justify;Times New Roman', serif"><strong><span style=""> </span></strong></p> <ol style="margin-bottom:0.0in;margin-top:0.0px" start="7"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><strong><span style="">Contribute to IT Strategic Planning and budgeting process, as well as day-to-day security planning, by analyzing future security needs, make recommendations on computer hardware, software, and processes. (5%)</span></strong></li> </ol> <h1 style="margin:0.0in;text-align:justify;text-indent:0.0in;Times New Roman', serif;font-weight:normal;font-style:italic"><strong><span style="font-style:normal"> </span></strong></h1> <h1 style="margin:0.0in;text-align:justify;text-indent:0.0in;Times New Roman', serif;font-weight:normal;font-style:italic"><strong><span style="font-style:normal">Position in Organization:</span></strong></h1> <h1 style="margin:0.0in 0.0in 0.0in 0.5in;text-align:justify;text-indent:-0.25in;Times New Roman', serif;font-weight:normal;font-style:italic"><span style="font-style:normal">·<span style="font:7.0pt 'Times New Roman'"> </span></span><span style="font-style:normal">Reports to: Director of Cyber Security (CISO)</span></h1> <h1 style="margin:0.0in 0.0in 0.0in 0.5in;text-align:justify;text-indent:-0.25in;Times New Roman', serif;font-weight:normal;font-style:italic"><span style="font-style:normal">·<span style="font:7.0pt 'Times New Roman'"> </span></span><span style="font-style:normal">Directly supervises: N/A</span></h1> <h1 style="margin:0.0in 0.0in 0.0in 0.5in;text-align:justify;text-indent:-0.25in;Times New Roman', serif;font-weight:normal;font-style:italic"><span style="font-style:normal">·<span style="font:7.0pt 'Times New Roman'"> </span></span><span style="font-style:normal">Indirectly supervises: CSOC, GRC, Cyber Security Architect, Cyber Security Engineers, and all Cyber Security related roles. </span></h1> <h1 style="margin:0.0in;text-align:justify;text-indent:0.0in;Times New Roman', serif;font-weight:normal;font-style:italic"><strong><span style="font-style:normal"> </span></strong></h1> <h1 style="margin:0.0in;text-align:justify;text-indent:0.0in;Times New Roman', serif;font-weight:normal;font-style:italic"><strong><span style="font-style:normal">Relationships: </span></strong></h1> <h1 style="margin:0.0in 0.0in 0.0in 0.5in;text-align:justify;text-indent:-0.25in;Times New Roman', serif;font-weight:normal;font-style:italic"><span style="font-style:normal">·<span style="font:7.0pt 'Times New Roman'"> </span></span><span style="font-style:normal">Inside the Company: All Information Technology personnel and high percentage of other department personnel. High level of contact and interaction with the General Counsel.</span></h1> <h1 style="margin:0.0in 0.0in 0.0in 0.5in;text-align:justify;text-indent:-0.25in;Times New Roman', serif;font-weight:normal;font-style:italic"><span style="font-style:normal">·<span style="font:7.0pt 'Times New Roman'"> </span></span><span style="font-style:normal">Outside the Company: Hardware/software vendors, professional service providers personnel in other company data processing installations. External auditors and assessment firms. Professional security and disaster recovery organizations and user groups.</span></h1> <p style="margin:0.0in 0.0in 0.0in 0.25in;text-align:justify;Courier New'"><span style=""> </span></p> <h1 style="margin:0.0in;text-align:justify;text-indent:0.0in;Times New Roman', serif;font-weight:normal;font-style:italic"><strong><span style="font-style:normal">Position Specifications: </span></strong><span style="">The required specifications (education, experience, and skills) are those that the employee must have to hold the position. Applicants applying for this position must possess the required specifications to be considered for the job. The desired specifications are those that are not required for the employee to hold the position, but the employee should try to obtain the desired education, experience, and/or skills to be effective and successful in the position.</span></h1> <p style="text-align:justify;margin:0.0in;Times New Roman', serif"><em><span style=""> </span></em></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Required education: Bachelor’s Degree, preferably in MIS or Computer Science or equivalent work experience.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Desired education: Certification as an Information Systems Security Professional. (CISM, CISA, CISSP, SANS, or equivalent)</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Required experience: Extensive experience in cybersecurity program management and operations. 8+ years of cybersecurity practices and technologies spanning risk management, governance, architecture, cloud security, threat detection, incident response, and vulnerability management. Intimately familiar with cyber security frameworks like NIST and CIS.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Desired experience: Disaster Recovery planning, CSIRT, regulatory compliance (PCI, HIPAA, Privacy), ITIL </span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Required skills: Solid grasp of the issues associated with standards, compliance, security, and disaster recovery including the costs, benefits, and risks to the company. Strong oral and written communications skills. Project leadership skills. </span></li> <li style="text-align:justify;margin:0.0in 0.0in 0.0in 0.0px;Times New Roman', serif"><span style="">Desired skills: AD and MS servers, AS400, security and audit tools, Network and Telecommunications experience.</span></li> </ul> <p style="text-align:justify;margin:0.0in;Times New Roman', serif"> </p> <p style="text-align:justify;margin:0.0in;Times New Roman', serif"><strong><span style="">Additional criteria:</span></strong></p> <p style="text-align:justify;margin:0.0in;Times New Roman', serif"><span style="">Must be able to work under pressure and provide guidance to Information Technology users during crisis modes. On call 24 by 7. This position requires the employee to be available by phone and/or email and/or have accessibility to calendar, contacts, and data while out of the office.</span></p> <p style="margin:0.0in 0.0in 0.0in 44.25pt;text-align:justify;text-indent:-44.25pt;Times New Roman', serif"> </p> <p><strong>Starting Salary: $146,000-$182,520</strong></p> <p><strong>Benefits: <a href="https://www.quiktrip.com/employee-benefits/">Employee Benefits – QuikTrip</a></strong></p> <p><strong>#LI-MI1</strong></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores