Information Security Manager
OverviewJoin our dynamic team as an
Information Security Manager and lead the charge in safeguarding our organization's digital assets and infrastructure. This pivotal role involves developing, implementing, and maintaining comprehensive security strategies aligned with industry standards and regulatory requirements. You will oversee the security posture across diverse IT environments, including cloud infrastructure, on-premises networks, and enterprise systems. Your expertise will ensure our information security policies are robust, compliant, and adaptive to emerging threats, empowering us to operate confidently in a rapidly evolving digital landscape.
Duties- Design, implement, and manage enterprise-wide information security programs based on frameworks such as NIST cybersecurity framework, ISO 27000 series, and FISMA.
- Develop and maintain system security plans, security policies, and procedures to ensure compliance with regulatory frameworks like PCI, FedRAMP, and government information & network security standards.
- Lead security risk assessments and vulnerability management initiatives across IT infrastructure including LAN, WAN, SAN, cloud platforms (AWS, Azure), and network protocols such as IPsec, TCP/IP, BGP, OSPF.
- Oversee the deployment and management of security tools such as SIEM systems (Splunk), IDS/IPS solutions, firewalls (Cisco ASA), Cisco ISE for identity & access management (IAM), and network monitoring software like SolarWinds or PRTG.
- Conduct incident response planning, incident recovery exercises, and threat detection & response activities to minimize impact from cyber threats.
- Manage security governance processes including IT security monitoring, audit programs, compliance management using GRC software, and security assessment procedures.
- Collaborate with cross-functional teams on system hardening efforts using tools like Ansible or Terraform; ensure secure configurations for operating systems (Windows, Linux) and cloud environments.
Experience- Proven experience in leading information security programs within complex IT environments involving computer networking, cybersecurity protocols, and cloud computing architectures.
- Extensive knowledge of network security concepts including routing protocols (EIGRP, OSPF), load balancing, VPNs (OpenVPN), encryption standards (FIPS), and high availability/disaster recovery strategies.
- Hands-on expertise with security frameworks such as ISO 27002/27001/27017/27018 standards; familiarity with RMF (Risk Management Framework) and DIACAP is highly desirable.
- Strong background in conducting vulnerability assessments using tools like Nessus or Qualys; experience with threat intelligence platforms such as ThreatConnect or Recorded Future is advantageous.
- Demonstrated ability to lead team efforts in IT risk management, security policy implementation, compliance audits, and incident management processes.
- Educational background in computer science or related fields; certifications such as CISSP, CISM or CISA are preferred to validate your expertise in cybersecurity governance and risk management.
Join us to be at the forefront of cybersecurity excellence! Your leadership will be instrumental in shaping a secure future for our organization while fostering a culture of continuous improvement in information security practices.
Benefits:
- Flexible schedule
- Health insurance