RFE/RL is looking for the IT Security Manager who will lead and coordinate RFE/RL’s IT security function under the direction of the CIO. This is a hands-on technical leadership role focused on security architecture, engineering, and operational oversight. This role leads security initiatives, guides technical security decisions, and helps ensure that cyber risks are effectively managed across the organization. The IT Security Manager provides functional leadership across Security Operations and Governance, Risk & Compliance while working closely with IT Infrastructure, Networks, business stakeholders, and external security partners.
Responsibilities:
Security Leadership
- Lead and coordinate the IT security function and technical security roadmap.
- Advise the CIO and leadership team on cyber risks, priorities, and investments.
- Act as the senior escalation point for significant security incidents.
- Promote a pragmatic, risk-based approach to cybersecurity across the organization.
Security Architecture & Engineering
- Define and maintain security architecture, standards, and technical baselines.
- Provide security guidance for infrastructure, cloud, identity, Microsoft 365, and AI-related initiatives.
- Lead implementation and optimization of security technologies and controls.
- Ensure security is incorporated into technology projects and modernization efforts.
Security Operations & Risk Management
- Oversee security monitoring, incident response, vulnerability management, and MSSP services.
- Partner with Governance & Risk specialists to support compliance, audits, and risk management activities.
- Monitor security performance, identify gaps, and drive remediation efforts.
- Coordinate security activities across IT, Networks, and business teams.
Performs other related duties as assigned.
Minimum Qualifications:
Education:
- University Degree in Computer Science, Information Technology, Cybersecurity, or a related field (Mandatory).
- Combination of education and experience (accepted).
Work Experience:
- 8+ years of progressive experience in cybersecurity, security architecture, engineering, or security operations (Mandatory).
- 3+ years in a senior or lead security role with organization-wide responsibility (Mandatory).
- Proven hands-on experience with Microsoft security technologies, including Defender, Sentinel, Entra ID, and Microsoft 365 Security (Mandatory).
- Experience with incident response, vulnerability management, and security monitoring (Mandatory).
- Proven experience successfully managing an IT Security function, including implementing security standards in an international enterprise (Mandatory).
- Experience with NIST-based security programs (Desirable).
- Experience managing security service providers and MSSPs (Desirable).
Competencies:
- Strong knowledge of Microsoft security technologies, including Defender, Sentinel, Entra ID, and Microsoft 365 Security.
- Deep understanding of security architecture principles, frameworks, and industry best practices.
- Ability to communicate effectively with both technical teams and senior leadership, translating complex security risks into business language.
- Proven ability to lead cross-functional teams and influence without direct authority.
- Strong analytical and problem-solving skills with the ability to assess complex security risks and reach sound technical conclusions.
- Strong organizational and communication skills, both verbal and written.
- Ability to work with a significant degree of autonomy and manage multiple priorities effectively.
- Receptive to feedback, willing to learn, and embracing continuous improvement.
- CISSP, CISM, SC-100, CCSP, or equivalent security certification (Desirable).
Languages:
- English language: Proficient (Mandatory).
- Czech language: Desirable/welcome.
Should you be interested in this position please apply by submitting your CV and a cover letter in English.
Appointment against this post is on a local basis only. Please note that for the locally advertised positions preference will be given to those with a work permit and/or a valid residence status in the Czech Republic. Locally recruited employees should reside within commuting distance of Prague, Czech Republic, or be willing to move to take up work. They are not eligible for allowances applicable to candidates who are internationally recruited. Rather, they receive statutory benefits as per Czech labor law. Salary scales for locally recruited employees are based on the best prevailing local conditions. RFE/RL does, however, cover the costs of interview travel and, upon appointment, some relocation costs.
Note: In response to changing operational requirements, RFE/RL retains the discretion not to make an appointment, or to modify the job specifications for a particular vacancy.
By replying to this advertisement or sending your CV and/or other personal data to RadioFreeEurope/RadioLiberty, you are agreeing to having your data saved and managed by employees of the HR department of the company for possible future reference in full accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) GDPR and Act No 110/2019 Coll., on personal data processing. This agreement may only be withdrawn by a written revocation and remains valid until that date. However no longer than 5 years.
Odpovědí na tento inzerát či zasláním Vašeho životopisu a případných dalších osobních materiálů do společnosti RadioFreeEurope/RadioLiberty dáváte souhlas ke zpracování a uchování Vašich osobních údajů dle Nařízení Evropského parlamentu a Rady (EU) 2016/679 ze dne 27. dubna 2016 o ochraně fyzických osob v souvislosti se zpracováním osobních údajů a o volném pohybu těchto údajů a o zrušení směrnice 95/46/ES (obecné nařízení o ochraně osobních údajů), dále jen GDPR a zákona č. 110/2019 Sb., o zpracování osobních údajů. Tento souhlas platí až do jeho odvolání písemnou formou, maximálně však po dobu 5 let.
Privacy Notice for RFE/RL Job Applicants
RFE/RL, Inc. is a private, nonprofit corporation funded by a grant from the U.S. Congress through the U.S. Agency for Global Media (USAGM). Due to RFE/RL’s special character, the countries in which RFE/RL operates, and the type of work RFE/RL performs, it is RFE/RL's obligation to verify the accuracy of information provided by each applicant in order to ensure the safety and security of our employees and workplace. RFE/RL must ensure that everybody who advances to the final stage of the selection process for a position at RFE/RL and who wishes to enter into an employment relationship with RFE/RL must undergo pre-employment background check.
With respect to the above, RFE/RL informs you, as an applicant, that your employment at RFE/RL is contingent on the successful completion of pre-employment check.
Therefore after your acceptance of RFE/RL‘s offer letter, you will be subject of pre-employment check (performed by external Czech entity). Detailed information about collection and processing of your personal data in this matter will be provided to you together with the offer letter.
Privacy Notice for RFE/RL Internship or Fellowship Applicants
The process described above largely applies to applicants for internships and fellowships as well – simply replace the word “employment” with “internship” or “fellowship” as applicable.