A company with a pioneering past and a purposeful future.
At ACCO Brands, we are united by a common purpose, to empower our consumers to feel good when they work, learn, and play. For more than a century we have developed and nurtured brands that enable people to work with more productivity, learn with more confidence, and play with more enjoyment. We are passionate about a winning culture where we grow together, driving business, professional growth, and success. We invite you to be part of a team that is grounded in a history of category-leading brands and products and focused on positioning our company for the future.
**Job Summary**
ACCO Brands is seeking a dynamic, forward-thinking **Sr. Cybersecurity Manager** to lead a global team of cybersecurity analysts, secure ACCO Brands' global digital ecosystem, and drive cross-functional risk-reduction initiatives across business units and infrastructure teams. Reporting to the VP of Global Cybersecurity and Infrastructure, this role oversees day-to-day cybersecurity operations, drives strategic security initiatives, and serves as a key liaison across IT, business units, and external partners.
**Responsibilities**
**Strategy, Governance & Risk**
+ Partner with the VP of Global Cybersecurity and Infrastructure to align security initiatives with enterprise risk posture, compliance obligations, and business objectives, translating them into cybersecurity priorities and roadmaps.
+ Leverage external security benchmarking and maturity assessments (e.g., BitSight, NIST) to develop cybersecurity performance metrics for executive leadership as part of broader risk and performance reporting.
+ Represent Cybersecurity in enterprise-level initiatives and governance councils, influencing business decisions through security insights and risk intelligence.
+ Lead enterprise-wide governance initiatives aligned with the NIST Cybersecurity Framework (CSF), translating technical risk into actionable business insights for executive stakeholders and identifying areas for improvement and control gaps.
+ Define and track key performance indicators (KPIs) and control metrics aligned with NIST CSF functions.
+ Contribute to and enforce cybersecurity policies, standards, and procedures that support compliance with PCI DSS, GDPR, SOX, and internal governance requirements.
+ Drive control validation initiatives to ensure the ongoing effectiveness of technical and administrative safeguards.
**Team Leadership & Development**
+ Lead, mentor, and manage a team of cybersecurity analysts and security engineers.
+ Coordinate workload planning, performance evaluations, and skill development across the cybersecurity team.
+ Foster a collaborative team culture through one-on-one coaching, career development, and goal setting.
**Security Operations & Incident Response**
+ Oversee daily security operations, including monitoring, triage, and incident response, using tools such as Rapid7 InsightIDR and CrowdStrike Falcon.
+ Serve as a key member of the cybersecurity incident response process, supporting the VP of Global Cybersecurity and Infrastructure from detection through resolution and post-incident review.
+ Manage continuous threat detection, intelligence gathering, and escalation procedures.
+ Oversee and guide analysts and engineers responsible for managing tools such as Proofpoint, Cisco Umbrella, SSO/MFA platforms, and next-generation firewalls, ensuring alignment with security strategy and best practices.
**Additional Responsibilities**
**Vulnerability & Threat Management**
+ Manage the enterprise vulnerability management lifecycle, including identification, validation, and risk-based remediation.
+ Partner with IT and infrastructure teams to validate remediation plans and enforce patching SLAs.
+ Coordinate and advance internal remediation activities and processes to improve and maintain the organization's external risk posture.
**Cloud & Application Security**
+ Oversee the development, implementation, and management of cloud security controls within Microsoft Azure and other cloud providers as applicable.
+ Collaborate with application development teams to integrate security practices into the software development lifecycle (SDLC).
+ Evaluate and enhance application security policies, secure coding practices, and code review procedures.
+ Ensure secure configurations and identity management across cloud-native platforms.
+ Partner with business and IT teams on security architecture reviews and secure project enablement.
**Vendor, Third-Party & Awareness Programs**
+ Design and roll out a Third-Party Risk Management program to inventory and assess cybersecurity risk across third parties, and integrate findings into the enterprise risk posture.
+ Manage vendor relationships, including MSSPs and security solution providers, to ensure alignment with program goals, service levels, and cost-effectiveness.
+ Evaluate and review security tools and technol