Job Description: Information Security ManagerPosition Title Information Security Manager
Job Summary We are seeking an experienced Information Security Manager to lead and manage the organization's information security strategy, governance, risk management, and security operations. The ideal candidate will be responsible for developing security policies, managing cybersecurity programs, ensuring regulatory compliance, and leading initiatives to protect organizational assets, data, and infrastructure from cyber threats.
Key Responsibilities Security Strategy & Governance - Develop and implement enterprise information security strategies aligned with business objectives.
- Establish and maintain security policies, standards, procedures, and guidelines.
- Define security frameworks, controls, and governance processes.
- Lead security awareness and training programs across the organization.
- Provide security guidance to business units and technology teams.
Risk Management & Compliance - Conduct security risk assessments and manage risk treatment plans.
- Identify security gaps and recommend risk mitigation strategies.
- Manage compliance activities against industry standards and regulations.
- Support audits, assessments, and regulatory reviews.
- Maintain security documentation, policies, and control evidence.
Security Operations & Incident Management - Oversee security operations including SOC, vulnerability management, and incident response activities.
- Establish incident response processes and ensure timely handling of security incidents.
- Coordinate investigations of cybersecurity events and data breaches.
- Review security monitoring reports and threat intelligence updates.
- Drive continuous improvement of security capabilities.
Vulnerability & Threat Management - Manage vulnerability assessment and penetration testing programs.
- Prioritize vulnerabilities based on business risk and impact.
- Ensure remediation activities are tracked and completed.
- Monitor emerging cyber threats and recommend appropriate defenses.
Identity, Access & Data Security - Ensure implementation of IAM policies, least privilege access, and privileged access controls.
- Oversee data protection, encryption, and information classification programs.
- Support cloud security and application security initiatives.
Team Leadership & Stakeholder Management - Lead and mentor information security teams.
- Define security roles, responsibilities, and performance objectives.
- Collaborate with IT, engineering, compliance, legal, and business stakeholders.
- Communicate security risks and recommendations to senior leadership.
Required Technical Skills - Strong understanding of cybersecurity principles and security architecture.
- Experience with security frameworks:
- ISO 27001
- NIST Cybersecurity Framework
- CIS Controls
- COBIT
- Knowledge of:
- Risk management
- Incident response
- Vulnerability management
- Security operations
- Identity and access management
- Cloud security
- Data protection
- Experience managing security tools and technologies:
- SIEM platforms
- EDR/XDR solutions
- Vulnerability scanners
- Firewalls
- DLP solutions
- IAM platforms
Preferred Tools & Technologies - SIEM: Splunk, Microsoft Sentinel, IBM QRadar
- Endpoint Security: CrowdStrike, Microsoft Defender, SentinelOne
- Vulnerability Management: Tenable, Qualys, Rapid7
- Cloud Security: AWS Security, Microsoft Azure Security, Google Cloud Security
- GRC Platforms: ServiceNow GRC, Archer, OneTrust
Preferred Certifications - Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- ISO 27001 Lead Implementer / Lead Auditor
- Certified Cloud Security Professional (CCSP)
- GIAC Security Certifications
Education & Experience - Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field preferred.
- 8+ years of experience in cybersecurity, information security, or IT risk management.
- Experience leading security teams and managing enterprise security programs.
- Experience with security audits, compliance programs, and risk assessments.
- Proven experience managing cybersecurity incidents and security improvement initiatives.
Soft Skills - Strong leadership and decision-making abilities.
- Excellent communication and stakeholder management skills.
- Ability to explain complex security risks to executive audiences.
- Strong analytical and problem-solving capabilities.
- Ability to manage multiple security initiatives and priorities.
Key Deliverables - Information security strategy and roadmap.
- Security policies and governance documentation.
- Risk assessment and compliance reports.
- Incident response improvements.
- Security awareness programs.
- Vulnerability remediation tracking.
- Executive security dashboards and reports.
Role Type Full-time / Contract
Department Cybersecurity / Information Security / Risk & Compliance