Your OpportunityThe Senior Manager, Information Security leads the organization's cybersecurity governance, risk management, and compliance programs, ensuring security policies, regulatory requirements, and industry best practices are effectively implemented.
The Senior Manager, Information Security is responsible for developing, managing, and executing IT security governance, risk, and compliance strategy. This includes overseeing risk assessments, audits, vendor security evaluations, policy enforcement, and leading a team of security analysts or specialists
This role is cross-functional, collaborating with IT, Risk, Legal, Compliance, and business teams to maintain compliance with frameworks like ISO 27001, NIST, SOC 2, and applicable privacy regulations such as GDPR and HIPAA
This role is ideal for a seasoned cybersecurity professional with deep GRC experience, capable of driving cybersecurity programs that ensure operational resilience, regulatory compliance, and enterprise risk mitigation while leading and mentoring a high-performing team.
Key Responsibilities- Leadership & Team Management: Build, mentor, and manage a high-performing GRC team, tracking objectives and key results (OKRs) and fostering a culture of continuous development.
- Risk Management: Identify, assess, and monitor IT-related risks, evaluate risk exceptions, and oversee tactical and strategic resolution plans.
- Compliance & Auditing: Plan and coordinate internal audits, third-party audits, and regulatory assessments; ensure corrective actions are implemented effectively.
- Policy Development: Develop, update, and enforce IT security policies, standards, procedures, and guidelines aligned with changing regulations and business requirements.
- Vendor and Third-Party Risk: Conduct security assessments of vendors, partners, and cloud providers to ensure regulatory and contractual compliance.
- Governance & Frameworks Implementation: Oversee GRC platform deployment and configuration to automate control monitoring, reporting, and continuous improvement.
- Awareness & Training: Implement cybersecurity awareness programs and deliver end-user or management training on security and compliance expectations.
- Strategic Advisory: Serve as a trusted advisor for IT risk and compliance strategy, engaging with executive leadership and stakeholders to ensure alignment with enterprise goals.
Required Qualifications- Education: Bachelor's degree in Information Technology, Cybersecurity, Information Security, Computer Science, or a related field.
- Experience: 10+ years in IT security or risk management with 2+ years leading teams managing regulatory or compliance programs. Experience in technology risk consulting, IT audits, and multi-country compliance programs is highly valued.
- Certifications: CISSP, CISM, CRISC, CISA, or CGEIT preferred.
- Technical Skills: Proficiency in GRC tools, familiarity with identity/access management (LDAP/AD, SAML, OIDC), cloud security, and integration with SIEM, vulnerability management, and ITSM platforms
- Soft Skills: Strong leadership, communication, stakeholder engagement, problem-solving, and decision-making abilities. Ability to translate complex compliance requirements into actionable strategies.
The expected range of compensation for this role is $132,000 to $182,000 annually.
Flexibility: All BDO personnel are expected to spend some of their time working in the office, at the client site, and virtually unless accommodations or alternative work arrangements are in place.
Our model is a blended approach designed to support the flexible needs of our people, the firm and our clients. It's about creating work experiences that meet everyone's needs and providing flexibility to adjust when, where and how we work to meet the expectations of our role.
Ready to make your mark at BDO? Click "Apply now" to send your up-to-date resume to one of our Talent Acquisition Specialists.
To explore other opportunities at BDO, check out our careers page#LI-SA1