Your Opportunity
The Senior Manager, Information Security leads the organization’s cybersecurity governance, risk management, and compliance programs, ensuring security policies, regulatory requirements, and industry best practices are effectively implemented.
The Senior Manager, Information Security is responsible for developing, managing, and executing IT security governance, risk, and compliance strategy. This includes overseeing risk assessments, audits, vendor security evaluations, policy enforcement, and leading a team of security analysts or specialists
This role is cross-functional, collaborating with IT, Risk, Legal, Compliance, and business teams to maintain compliance with frameworks like ISO 27001, NIST, SOC 2, and applicable privacy regulations such as GDPR and HIPAA
This role is ideal for a seasoned cybersecurity professional with deep GRC experience, capable of driving cybersecurity programs that ensure operational resilience, regulatory compliance, and enterprise risk mitigation while leading and mentoring a high-performing team.
Key Responsibilities
- Leadership & Team Management: Build, mentor, and manage a high-performing GRC team, tracking objectives and key results (OKRs) and fostering a culture of continuous development.
- Risk Management: Identify, assess, and monitor IT-related risks, evaluate risk exceptions, and oversee tactical and strategic resolution plans.
- Compliance & Auditing: Plan and coordinate internal audits, third-party audits, and regulatory assessments; ensure corrective actions are implemented effectively.
- Policy Development: Develop, update, and enforce IT security policies, standards, procedures, and guidelines aligned with changing regulations and business requirements.
- Vendor and Third-Party Risk: Conduct security assessments of vendors, partners, and cloud providers to ensure regulatory and contractual compliance.
- Governance & Frameworks Implementation: Oversee GRC platform deployment and configuration to automate control monitoring, reporting, and continuous improvement.
- Awareness & Training: Implement cybersecurity awareness programs and deliver end-user or management training on security and compliance expectations.
- Strategic Advisory: Serve as a trusted advisor for IT risk and compliance strategy, engaging with executive leadership and stakeholders to ensure alignment with enterprise goals.
Required Qualifications
- Education: Bachelor’s degree in Information Technology, Cybersecurity, Information Security, Computer Science, or a related field.
- Experience: 10+ years in IT security or risk management with 2+ years leading teams managing regulatory or compliance programs. Experience in technology risk consulting, IT audits, and multi-country compliance programs is highly valued.
- Certifications: CISSP, CISM, CRISC, CISA, or CGEIT preferred.
- Technical Skills: Proficiency in GRC tools, familiarity with identity/access management (LDAP/AD, SAML, OIDC), cloud security, and integration with SIEM, vulnerability management, and ITSM platforms
- Soft Skills: Strong leadership, communication, stakeholder engagement, problem-solving, and decision-making abilities. Ability to translate complex compliance requirements into actionable strategies.
The expected range of compensation for this role is $132,000 to $182,000 annually.