Fortinet

Senior Information Security Manager

Fortinet$166K — $203K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in information security with project management skills.
  • Expertise in NIST SP800-53, ISO/IEC 27000, and SOC2 standards.
  • Preferred experience managing FedRAMP or GovRAMP compliance.
  • Strong knowledge of privacy frameworks like GDPR and CCPA.
  • Proficient in security control technologies and IT security practices.

Responsibilities

  • Lead the information security team and enhance the ISMS.
  • Conduct gap analysis and formulate action plans for compliance.
  • Coordinate compliance with FedRAMP and GovRAMP frameworks.
  • Develop performance metrics to ensure compliance and improvements.
  • Perform risk assessments and prepare treatment plans for security risks.

Benefits

  • Medical, dental, and vision insurance options.
  • Life and disability insurance coverage.
  • 401(k) retirement plan.
  • Paid time off including 11 holidays, vacation, and sick leave.
  • Participation in the Fortinet equity program.
Full Job Description
JOB DESCRIPTION

Fortinet looking for a Senior Information Security manager to join the Information Security team in the U.S. This position is responsible for leading the information security team, focusing on information security compliance projects. This role will oversee the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS), coordinate security compliance initiatives across the organization, and serve as the primary liaison with external auditors and regulatory bodies. The position requires a strong understanding of ISO/IEC 27001 and NIST security frameworks, cloud security, risk management, governance, and security operations.

The successful candidate must be a U.S. citizen, and work onsite at Fortinet's headquarter in Sunnyvale, California.

Job Responsibilities:

  • Manage information security team, lead the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS). 

  • Perform gap analysis based on NIST SP800-53 and other compliance framework, create mitigation/action plans. 

  • Determine the applicability and apply the information security and privacy requirements to ISMS policies. 

  • Prepare required documents for supporting various compliance frameworks such as FedRAMP and GovRAMP. 

  • Develop related KPI metrics for performance measurement, and for ensuring continued compliance and improvement.

  • Create compliance project plans. Manage the implementation.

  • Conduct risk and privacy impact assessments on business and operation processes. Prepare finding reports. Create and implement risk treatment plans. 

  • Collaborate with operation teams to ensure that appropriate controls are implemented and operated properly. 

  • Participate in and lead the daily security operation, oversee the handling of security alerts and incidents. 

  • Lead vulnerability management activities, monitor remediation progress, and work closely with operations teams to ensure timely patching of identified vulnerabilities.

  • Manage internal and external audits. Develop audit plans, respond to various audits and review requests.  

 

Skills and Qualifications:

  • 7+ years of experience in information security area, with people and project management experience. 

  • Subject matter expert of NIST SP800-53, ISO/IEC 27000 and SOC2 related standards, regulations and guidelines. 

  • Experience of managing FedRAMP or GovRAMP implementation and compliance is highly preferred. 

  • Knowledge and experience working with various information security frameworks (ISO/IEC 27001, NIST 800-53, NIST SP800-161, GovRAMP, FedRAMP, PCI DSS) and regulatory frameworks (SOX, PCI-DSS, HIPAA, GDPR, SOC, etc.)

  • Strong knowledge of and experience in privacy framework and regulatory compliance requirements (e.g., GDPR, CCPA).

  • Strong network security knowledge. Thorough understanding of current and emergent trends in information security

  • Working knowledge of information security control technologies including access control, cryptography, vulnerability management, SIEM/log management, ID/IPS, and penetration test.

  • Working knowledge and hardening skills on information technologies including Linux, Windows, VMWare, MySQL, MSSQL, etc.

  • Working knowledge of Cloud platforms, Cloud security (AWS, Azure, GCP) and network security. 

  • Experience and knowledge of Fortinet products and services are preferred. 

  • Strong verbal and written communication skills. Demonstrate ability to work with team members, cross functional and external parties. 

  • Ability to work independently in a fast-paced, dynamic environment. Able to establish priorities and meet deadlines.

  • Ability to provide continual attention to details. Strong analytical mindset. Able to gather and report data in meaningful format.

  • Passionate about policies, processes and documentation. Able to translate general standards to practical guidelines suitable for business operations. 

 

Educational & Certification Requirements:

  • Bachelor’s degree in computer science, Information Security or related field;

  • A certification in one or more of the following desirable:

    • CISSP

    • CISA, CISM

    • ISO 27001 Lead-Auditor

    • VCP

    • CCSP

    • CRISC

  • NIST SP800-53 related training program.

  • GovRAMP/FedRAMP related training program.

 

Must be authorized to work in the U.S. without sponsorship.

The US base salary range for this full-time position is $166,500-$203,500. Fortinet offers employees a variety of benefits, including medical, dental, vision, life and disability insurance, 401(k), 11 paid holidays, vacation time, and sick time, as well as a comprehensive leave program.

Wage ranges are based on various factors, including the labour market, job type, and job level. Exact salary offers will be determined by factors such as the candidate's subject knowledge, skill level, qualifications, experience, and geographic location.

All roles are eligible to participate in the Fortinet equity program. Bonus eligibility is reviewed at the time of hire and annually at the Company’s discretion.

About Fortinet

Fortinet is a cybersecurity company that provides network security solutions to businesses, service providers, and government organizations worldwide. The company's products and services include firewalls, VPNs, intrusion prevention systems, endpoint security, and more. Fortinet was founded in 2000 and is headquartered in Sunnyvale, California.
Learn more about Fortinet
Size
10,860 employees
Market Cap
$38.2 billion
Industry
Net Income
$486.2 million
Founded
2000
5 Year Trend
+21.2%
Revenue
$2.5 billion
NASDAQ

Similar Jobs

More Jobs at Fortinet

More Information Technology Jobs

Find similar Senior Information Security Manager jobs: