About this role
Consumers Energy is Michigan’s largest energy provider, providing natural gas and/or electricity to 6.8 million of the state’s 10 million residents in all 68 Lower Peninsula counties. Consumers Energy knows job number one is to keep the lights on for customers. We are committed to delivering reliable, clean, and affordable energy to our customers 24/7.
This position is not eligible for immigration sponsorship, e.g., H-1B, TN, etc. Please do not apply if you will need immigration sponsorship for a work visa now or in the future, including sponsorship for H-1B, TN, etc., now or in the future. We are unable to hire individuals with CPT, OPT, or STEM OPT for this position as the position is not eligible for participation in the H-1B lottery program and is not eligible for current or future immigration sponsorship for a work visa.
Location : This is a hybrid (virtual/onsite) position with required onsite days on Monday, Tuesday and Thursday assigned to One Energy Plaza located in Jackson, MI. The selected candidate must be within a commutable distance or willing to relocate (relocation package is available for those that qualify).
General Summary of Job Responsibilities
The Senior Manager, Security is responsible for overseeing and advancing the organization’s comprehensive security strategy across security operations, engineering, identity and access management (IAM), risk management, privacy, networking, and compliance. This role provides strategic leadership, technical expertise, and operational oversight to protect company assets, data, and infrastructure. The Senior Manager drives the execution of complex security initiatives, manages enterprise-level risk, and strengthens the organization’s overall security posture through proactive defense, regulatory adherence, and continuous program optimization.
As a senior leader within the Security organization, the Senior Manager shapes security policies, ensures compliance with regulatory and industry standards, and leads responses to security incidents. This role fosters collaboration with internal and external stakeholders, influences security culture across the enterprise, and mentors a team of security professionals to achieve business-aligned security objectives.
Essential Duties and Responsibilities
- Define and implement the organization’s security strategy, ensuring alignment with business objectives, industry standards, and regulatory requirements while driving continuous improvement across all security functions.
- Serve as the escalation point for significant security incidents, ensuring timely and effective response, remediation, and cross-team coordination during major events or disruptions.
- Oversee the identification, assessment, and mitigation of security risks while ensuring full adherence to privacy laws, data protection requirements, and compliance frameworks across all security domains.
- Stay current on emerging threats, technologies, and industry best practices, integrating new tools and methodologies to strengthen the organization’s security posture.
- Perform other non-essential duties as assigned or as needed.
- Manage workload demand, resource allocation, budgeting, and capital planning across all security functions while tracking key performance indicators (KPIs) and metrics to evaluate program effectiveness and operational efficiency.
- Mentor, coach, and develop team members while fostering a culture of continuous learning, professional growth, and diversity, equity, and inclusion (DE&I) to build a high-performing and empowered security team.
- Oversee and manage one or more security domains, such as:
Security Operations & Incident Response (e.g., CSIRT, threat detection, monitoring, proactive threat hunting, forensic analysis)
- Security Engineering & Identity and Access Management (e.g., technology design and implementation, automation, identity provisioning, authentication, authorization, governance)
- Network/Connectivity (e.g., routing, switching, firewalls, data transfer)
- Risk Management, Privacy, and Compliance (e.g., risk assessments, privacy programs, regulatory compliance such as NIST, NERC CIP, PCI, audit readiness)
Additionally, ensure organizational resilience through Business Continuity and Disaster Recovery planning and execution.
- Build and maintain strong relationships with internal and external stakeholders—including executive leadership, IT, legal, compliance, vendors, auditors, and regulators—and represent the organization in industry forums and regulatory discussions.
- Lead continuous improvement initiatives using frameworks such as CMMI and Lean; oversee documentation processes; and contribute to long-term security roadmaps, strategic planning, and financial initiatives to support organizational goals and enhance security posture.
Knowledge/Skills/Abilities
- Exceptional verbal and written communication skills, with the ability to effectively communicate complex security concepts to executive leadership, technical teams, and non-technical stakeholders across all organizational levels.
- Strong interpersonal and relationship-building skills, with the ability to lead cross-functional teams, foster collaboration across departments, and build consensus around security initiatives.
- High emotional intelligence, with the ability to understand and manage team dynamics, promote psychological safety, and cultivate an inclusive environment that values diverse perspectives and contributions.
- Demonstrated commitment to employee development, with a proven track record of mentoring, coaching, and supporting team members' professional growth, career advancement, and succession planning.
- Proven ability to work collaboratively in team environments, with a strong commitment to humility, accountability, initiative, and effective interpersonal engagement.
- Ability to develop and execute comprehensive security strategies that align with organizational objectives while balancing risk management, operational requirements, and business priorities.
- Demonstrated ability to make sound, data-driven decisions under pressure, particularly during security incidents, while effectively balancing immediate response needs with long-term strategic goals.
- Expertise in leading organizational change within security programs, including managing stakeholder resistance, driving adoption of new technologies and processes, and fostering a culture of continuous improvement.
- Ability to assess, prioritize, and manage security risks within the broader business context, ensuring effective resource allocation and alignment with organizational risk tolerance.
Additional Knowledge/Skills/Abilities
- Expert-level understanding of enterprise identity architecture, identity governance, privileged access management (PAM), authentication technologies, federation services, and directory services.
- Proven experience leading identity modernization initiatives involving Microsoft Entra ID, Active Directory, CyberArk, Identity Governance and Administration (IGA) platforms, and cloud-based identity services.
- Strong understanding of Zero Trust architecture, least-privilege access models, phishing-resistant authentication methods, privileged account governance, and identity security best practices.
- Demonstrated success leading platform engineering teams responsible for highly available enterprise services, including strategic planning, operational support, platform lifecycle management, and technology transformation initiatives.
Education/Experience
- Bachelor’s degree in a related field and seven (7) or more years of experience in one or more Security or IT disciplines, such as Asset Management, Automation, Compliance, Identity & Access Management, Network Engineering and Operations, Incident Response, IT Infrastructure and Architecture, Network and Security Operations, Privacy, Risk Management, or Security Engineering.
- [OR] Associate’s degree in a related field and nine (9) or more years of experience in one or more of the above Security or IT disciplines.
- [OR] High School Diploma/GED and eleven (11) or more years of experience in one or more of the above Security or IT disciplines.
Why should you join our team?
At Consumers Energy, we offer more than just a place to work. We foster a culture that supports career development, growth, and stability, and we take pride in offering our co-workers excellent benefits and compensation packages. We are deliberately creating an inclusive culture that makes our diverse team of co-workers feel valued, supported, and empowered every day. We're a company made up of thousands of people, all with different stories to share and work to do, but we stand united in our company purpose: world class performance delivering hometown service.
What we offer:
- Competitive compensation packages
- Medical, Dental and Vision
- 401k with company match
- Paid parental leave
- Up to 13 paid Holidays
- Paid time off
- Educational Assistance Program
Diversity, Equity & Inclusion:
We, at CMS Energy, value Diversity, Equity, & Inclusion. It is part of our DNA. We treat our employees with respect, we treat each other fairly and we value the opinions of others. We are passionate about building and nurturing an environment where everyone feels included. We don’t discriminate. We seek to learn about each other and better understand our unique differences. Our uniqueness makes us authentic. We create safe spaces where everyone can be who they truly are. We invite difficult conversations and uncomfortable topics. We value diverse perspectives; this is what makes us great together. We harbor an inclusive environment where employees feel empowered to share their backgrounds, experiences, and ideas. Our Employee Resource Groups, Women in Energy (WE), Minority Advisory Panel (MAP), Pride Alliance of Consumers Energy (PACE), GENERGY (Different Generations), capable (Different Abilities), Interfaith, People Planet Partners, and Veterans Advisory Panel (VAP) are key enablers to living the values of our company culture: Caring, Empowered, Deliberate, Agility, and Ownership.
All qualified applicants will not be discriminated against and will receive consideration for employment without regard to protected veteran status, disability, race, color, religion, sex, age, sexual orientation, gender identity or national origin.