Fisher Investments

Information Security Program Manager

Fisher Investments$115K — $170K *
Camas, WA 98607In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of experience with attack methodologies in the cyber security domain.
  • Experience within highly regulated sectors like Financial Services or Banking.
  • Skills in building or maturing Security Assurance and Cyber Resilience capabilities.
  • Familiarity with cyber resilience exercises and control validation.
  • Knowledge of evaluating new technologies such as cloud and AI security controls.

Responsibilities

  • Help build and mature the Cyber Resilience & Assurance program.
  • Develop governance frameworks and assessment methodologies.
  • Establish validation approaches for cybersecurity controls and resilience activities.
  • Evaluate effectiveness of security controls across multiple IT environments.
  • Support threat-informed security assessments and simulations.
  • Analyze attack paths and control effectiveness against evolving threats.
  • Develop metrics and executive reporting to measure cyber resilience.

Benefits

  • 100% paid medical, dental, and vision premiums for you and eligible dependents.
  • 50% 401(k) match, up to the IRS maximum.
  • 20 days paid time off plus 10 paid holidays.
  • Family Support programs including paid caregiver leave and fertility assistance.
  • Opportunity for a hybrid work from home program based on eligibility.
Full Job Description
Overview

You will have the unique opportunity to build a program from the ground up while partnering across the firm to develop assessment methodologies, governance frameworks, resilience exercises, executive reporting, and long-term strategies.

The Opportunity:

We're searching for an Information Security Program Manager to help support our growing Information Security programs. Alongside Information Security leaders and program managers, you will help develop documentation, support process improvement efforts, contribute to governance and reporting activities, and assist with training and awareness programs. You'll gain exposure to multiple Information Security disciplines while expanding your technical writing, process analysis, and project coordination. You don't need to be a cybersecurity expert, but if you're passionate about documentation, organization, and continuous improvement, this is the job for you.

The Day-to-Day:
  • Help build and mature our Cyber Resilience & Assurance program.
  • Develop governance frameworks, standards, operating procedures, and assessment methodologies.
  • Establish validation approaches for cybersecurity controls, operational readiness, technology platforms, and cyber resilience activities.
  • Evaluate the effectiveness of security controls across identity, infrastructure, network, cloud, application, and AI environments.
  • Support threat-informed security assessments, attack simulations, exercises, and security validation activities.
  • Analyze attack paths, control effectiveness, and organizational readiness against evolving threats.
  • Develop metrics, scorecards, and executive reporting to measure cyber resilience and security effectiveness.
  • Work with business and technology partners to identify improvement opportunities and strengthen overall cyber resilience.
  • Contribute to the long-term roadmap, strategy, and maturity of the Cyber Resilience & Assurance program.
  • Understanding of threat actor tactics, techniques, and procedures (TTPs).
  • Working knowledge of the MITRE ATT&CK Framework.
  • 3+ years of experience with modern attack methodologies.

Your Qualifications:
  • Experience helping build or mature Security Assurance, Cyber Resilience, Threat Emulation, Security Validation, Adversarial Validation, Red Team, or Purple Team capabilities.
  • Experience conducting security assessments, attack simulations, adversarial exercises, or threat-led testing activities.
  • Experience working within Financial Services, Wealth Management, Banking, Insurance, or other highly regulated industries.
  • Familiarity with cyber resilience exercises, security control validation, and operational readiness assessments.
  • Experience evaluating new technologies, including cloud and frontier AI security controls.

Compensation:
  • $115,000 - $170,000 base salary per year in the state of WA. New hires should expect to start at the lower end of the range depending on experience
  • Eligible for a discretionary bonus based on firm and individual performance

  • 100% paid medical, dental and vision premiums for you and your qualifying dependents
  • A 50% 401(k) match, up to the IRS maximum
  • 20 days of PTO, plus 10 paid holidays
  • Family Support programs including 8 week Paid Primary Caregiver Leave, $10,000 fertility, family forming, and hormonal health assistance, and back-up child, adult, and elder care
  • This is an in-office role. Based on your role, tenure, and performance eligibility you may have the opportunity to participate in our hybrid work from home program. This program is subject to change.

About Fisher Investments

Fisher Investments is a privately owned investment management firm founded in 1979 by Ken Fisher. The company is headquartered in Camas, Washington, and has offices in the United States, Europe, and Asia. Fisher Investments manages assets for individuals and institutions, including pension plans, endowments, and foundations. The company is known for its investment philosophy, which emphasizes a global perspective and a focus on long-term growth. Fisher Investments has been recognized for its performance and has won numerous awards for its investment strategies.
Learn more about Fisher Investments
Size
3,500 employees
Industry
Founded
1979

Similar Jobs

More Jobs at Fisher Investments

More Information Technology Jobs

Find similar Information Security Program Manager jobs: