Senior Manager - Product Cybersecurity (Hybrid)

at United Airlines in Chicago, Illinois, United States

Job Description


There’s never been a more exciting time to join United Airlines. We’re on a path towards becoming the best airline in the history of aviation. Our shared purpose – Connecting People, Uniting the World – is about more than getting people from one place to another. It also means that as a global company that operates in hundreds of locations around the world with millions of customers and tens of thousands of employees, we have a unique responsibility to uplift and provide opportunities in the places where we work, live and fly, and we can only do that with a truly diverse and inclusive workforce. And we’re growing – in the years ahead, we’ll hire tens of thousands of people across every area of the airline. Our careers include a competitive benefits package aimed at keeping you happy, healthy and well-traveled. From employee-run “Business Resource Group” communities to world-class benefits like parental leave, 401k and privileges like space available travel, United is truly a one-of-a-kind place to work. Are you ready to travel the world?

We believe that inclusion propels innovation and is the foundation of all that we do. United’s Digital Technology team spans the globe and is made up of diverse individuals all working together with cutting-edge technology to build the best airline in the history of aviation. Our team designs, develops and maintains massively scaling technology solutions brought to life with innovative architectures, data analytics, and digital solutions.

Key Responsibilities:

The Senior Manager – Product Cybersecurity is a technical leader responsible for managing a team of highly innovative cybersecurity engineers responsible for developing and maintaining end-to-end security architecture of United’s product(s)/application(s)/service(s). This person will create and implement a vision for security across all products within the United portfolio.

Cybersecurity Process Management and Administration: Provide periodic updates, education and presentations to staff and management on various aspects of cybersecurity

+ Accountable for administrative management of cybersecurity professionals, either as direct reports or sourced – HR administration, salary administration, time reporting, etc.

+ Define, prioritize, allocate resources, track, and provide status reporting of work assignments, projects, and programs

+ Reviews and is responsible for departmental budgets and resource allocations

Interface: Monitors changes in legislation and compliance standards that affect assigned areas of responsibility and proactively acts to update standards, best practices and architectures based on this information

+ Manages, coordinates, and evaluates the work of assigned cybersecurity department to ensure the security, confidentiality, integrity & availability of United’s systems, products, and services

+ Builds relationships and partners with functional areas across the business to raise awareness and support for cybersecurity

+ Coordinates department activities with internal/external technology & business owners/service providers

+ Provides overall resource/project management for department, including matching people to projects, obtaining needed resources, etc.

+ Maintains relationships with internal and external audit agencies to facilitate execution of audits


+ Manages the development and implementation of cybersecurity strategies

+ Works with multi-functional teams to develop, document and implement cybersecurity standards, best practices, and architectures

+ Manages the planning, documentation and execution of cybersecurity evaluations and testing

+ Coordinates remediation of non-compliant items to meet applicable compliance standards and best practices

+ Is available to respond to unplanned cybersecurity & risk management events including crisis situations

United Airlines is an equal opportunity employer. United Airlines recruits, employs, trains, compensates, and promotes regardless of race, religion, color, national origin, gender identity, sexual orientation, physical ability, age, veteran status, and other protected status as required by applicable law.


What’s needed to succeed (Minimum Qualifications):

+ Bachelor’s degree (STEM)

+ At least 9 years of related experience

+ One or more of the following:

+ Certified Ethical Hacker (CEH)

+ GIAC Security Essentials (GSEC)

+ Certified Information Security Manager (CISM)

+ Comp TIA Security + Certified Information Systems Security Professional (CISSP)

+ Certified Information Systems Auditor (CISA)

+ Systems Security Certified Practitioner (SSCP)

+ CompTIA Advanced Security Practitioner (CASP+)

+ Offensive Security Certified Professional (OSCP)

+ AWS Solution Architect Pro., Networking, and Security Specializations

+ Strong and demonstrable ability to communicate technical concepts to a non-technical audience and partners

+ Experience with threat modeling or other risk identification techniques, and risk management

+ Experience managing teams to identify strategic and tactical risk

+ Experience partnering and influencing multi-functional teams to drive security improvements

+ Experience driving prioritization of security risks/vulnerabilities and ensuring that they are properly understood by the business and fixed and/or mitigated

+ Strong analytical and quantitative skills with the ability to use data and metrics to back up assumptions and recommendations and drive actions

+ Excellent oral and written communication skills

+ Demonstrated ability to convey complex technical subjects in a concise and direct manner

+ Demonstrated problem solving, critical thinking, logical structuring skills and a willingness to learn and stretch outside of your comfort zone

+ Demonstrated knowledge on threat landscape, security threat and vulnerability management, and security monitoring and analytics

+ Must be legally authorized to work in the United States for any employer without sponsorship

+ Successful completion of interview required to meet job qualification

+ Reliable, punctual attendance is an essential function of the position


What will help you propel from the pack (Preferred Qualifications):

+ Master’s degree

+ 12+ years of relative experience

+ Working knowledge and/or hands on experience with as many as possible of the following areas:

+ Operating system & platform security

+ Networking Security and an understanding of network and web related protocols

+ Voice over IP and unified communication security

+ Strong domain expertise in the fields of IT security and risk management

+ Strong knowledge of IT infrastructure security best practices, procedures, and standards

+ Experience with cloud native products and in-depth understanding microservice topologies and implementations

+ Expertise in application development and dev-ops security technologies and integration

+ Demonstrated ability to think strategically about business, product, and technical challenges

+ Experience within the transformation of traditional data center security measures into industry adopted cloud technologies

+ Demonstrable ability to work with compliance frameworks and requirements

+ Ability to work in a fast-paced and Agile development environment

+ Experience providing training and mentorship

+ Ability to perform manual security code reviews

+ Ability to interpret dynamic/static analysis tools, and penetration test results

United Airlines is an equal opportunity employer. United Airlines recruits, employs, trains, compensates and promotes regardless of race, religion, color, national origin, gender identity, sexual orientation, physical ability, age, veteran status and other protected status as required by applicable law. We will ensure that individua

Copy Link

Job Posting: JC238797751

Posted On: Apr 24, 2023

Updated On: Jul 06, 2023

Please Wait ...