VeriSign

Manager - Information Security Compliance

VeriSign$135K — $183K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Expertise in cybersecurity best practices and frameworks (CIS, SOC, NIST) with hands-on control testing experience.
  • Experience working in a public company setting, managing compliance across diverse regulatory frameworks.
  • Deep technical knowledge of security controls and their implementation in a large IT landscape.
  • Creative ability to tailor control tests specific to unique implementations.
  • 8+ years in information security governance, risk, or compliance roles with progressively increasing responsibilities.
  • At least 4 years specifically in security control assessments.
  • 2+ years of experience in a leadership or management role in security.

Responsibilities

  • Manage the security control assurance program, overseeing test procedures and driving remediation efforts for identified gaps.
  • Ensure compliance with regulatory requirements by translating them into actionable control objectives.
  • Develop a continuous control monitoring program by collaborating with stakeholders on automated test processes.
  • Work closely with technical teams to enhance security controls and establish implementation standards.
  • Communicate findings through reports and dashboards to various audiences, including senior leadership.
  • Contribute to the creation of enterprise information security policies and standards.
  • Lead and mentor a team, setting priorities and ensuring quality deliverables.

Benefits

  • Hybrid work schedule with flexibility.
  • Opportunity for a discretionary bonus based on performance.
  • Potential for discretionary stock awards based on role performance.
Full Job Description
Verisign is seeking a hands-on technical manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. In this role, you will support an enterprise-wide governance, risk, and compliance program focusing on security control assurance, security risk management, policies and standards, continuous control monitoring, and ensuring compliance with internal and external security requirements.

Some immediate focus areas include:
  • Reviewing information security control design and conducting tests
  • Standing up automated evidence collection practices
  • Responding to external regulatory information requests

An ideal candidate cares deeply about automation and reducing friction. We expect the candidate to possess competencies that allow them to bring noticeable and measurable improvements in some of the above-mentioned areas. This position requires the technical depth and communication range to brief audiences from system engineers to senior leadership.

Primary Responsibilities:
  • Manage a security control assurance program, including planning and executing test procedures, assessing design and operating effectiveness, and driving identified gaps to remediation.
  • Manage compliance with external regulatory obligations, translating requirement into control objectives, coordinating regulator information requests, and tracking remediation commitments.
  • Build a continuous control monitoring program by collaborating with control and system owners and translating security control requirements into automated tests.
  • Interface directly with technical engineering teams to design and improve security controls, define implementation requirements, and determine what effective security control operations should look like.
  • Report on compliance and control assessment results, risk trends, and remediation priorities to audiences ranging from controls owners to senior leadership through clear reporting, executive briefings, and dashboards.
  • Assist with the development of enterprise information security policies and standards.
  • Lead a team of practitioners, setting priorities and quality standards, and ensuring commitments are met.

Qualifications:
  • Domain expertise in cyber security standard methodologies and security control frameworks such as CIS Controls, SOC 2/3 Trust Services Criteria, NIST Cybersecurity Framework, and NIST SP800-53; with hands-on experience testing and mapping controls across frameworks
  • Experience in a public company environment managing compliance across multiple regulatory and security frameworks
  • Technical understanding of security controls, identifying control objectives, and how to implement them in a complex enterprise IT environment
  • Ability to creatively develop and refine control tests tailored to specific control implementations
  • 8+ years progressively responsible experience in information security governance, risk, compliance, or security assessment/audit
  • 4+ years of security control assessment experience required
  • 2+ years of related experience leading or managing others
  • Professional security management certification, such as a Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC) are preferred
  • Bachelor's degree in Information Systems, Computer Science, or related field, or equivalent experience, required

This position is based in our Reston, VA office and offers a hybrid work schedule.

The pay range is $135,800 - $183,800.

The anticipated annual base salary range for this position is noted above, however, base pay offered may vary depending on job-related knowledge, skills, experience. Verisign offers a discretionary bonus which is based on individual and company performance, and certain roles may be eligible for discretionary stock awards.

About VeriSign

VeriSign, Inc. is an American company based in Reston, Virginia, United States that provides domain name registry services and internet security. Verisign operates two of the Internet's thirteen root nameservers. Verisign also offers a range of security services, including managed DNS, distributed denial-of-service (DDoS) attack mitigation and cyber threat reporting. The company was founded in 1995 and is headquartered in Reston, Virginia.
Learn more about VeriSign
Size
904 employees
Market Cap
$21.6 billion
Industry
Net Income
$814.8 million
Founded
1995
5 Year Trend
+3.1%
Revenue
$1.2 billion
NASDAQ

Similar Jobs

More Jobs at VeriSign

More Information Technology Jobs

Find similar Manager - Information Security Compliance jobs: