Senior Manager, Information Security & IT

Genea

• $160K — $180K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in cybersecurity and IT, including 2+ years in leadership roles.
  • Strong technical expertise in cloud security, application security, and incident response.
  • Experience with secure SDLC and DevSecOps practices, including threat modeling and penetration testing.
  • Familiarity with cybersecurity frameworks like SOC 2 Type 2 and ISO 27001.
  • Knowledge of AI cybersecurity risks and secure AI adoption practices.
  • Strong understanding of identity and corporate IT environments.

Responsibilities

  • Lead and enhance Genea's cybersecurity compliance programs including SOC 2 Type 2 and readiness for ISO 27001.
  • Establish governance for secure enterprise adoption of AI and manage associated risks.
  • Define measurable cybersecurity KPIs and report progress to the executives.
  • Drive cloud and application security practices, ensuring secure design with Engineering and Product teams.
  • Oversee the incident response process, managing detection, investigation, and recovery efforts.
  • Manage corporate IT operations, ensuring robust endpoint and SaaS management.
  • Develop and grow the IT team, fostering accountability and operational standards.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Flexible spending accounts (FSA).
  • Life and accidental death and dismemberment (AD&D) insurance.
  • Long-term disability (LTD) coverage.
  • Paid time off (PTO).
  • 401(k) retirement savings plan.
Full Job Description
Job Title: Senior Manager, Information Security & IT

Reports To: Chief Technology Officer

Department: Technology - Information Security & IT

Work Location: Irvine, CA or US-Remote

Job Overview

Genea is looking for a hands-on Senior Manager, Information Security & IT to lead and continuously improve our cybersecurity and corporate IT programs.

Reporting to the CTO, this role will lead Genea's cybersecurity and IT programs across compliance, cloud and application security, incident response, identity and access management, and corporate IT.

Genea is already SOC 2 Type 2 compliant. This role will be responsible for continuously maintaining and maturing that program while helping drive additional cybersecurity and compliance initiatives, including ISO 27001 and other relevant frameworks as the business evolves.

We are looking for a cybersecurity leader who embraces AI, understands the evolving risks introduced by AI and agentic technologies, and can help Genea adopt AI securely while leveraging AI and automation to strengthen cybersecurity operations.

This is a hands-on leadership role for someone who can set direction, build scalable programs, lead the IT team and build out the cybersecurity function as needed, work closely with Engineering and other business teams, and remain involved in execution where needed.

Duties and Responsibilities

Cybersecurity Compliance & Programs
  • Own and continuously mature Genea's cybersecurity compliance program, including SOC 2 Type 2, policies, controls, audit readiness, evidence management, risk assessments, cybersecurity awareness, and readiness for ISO 27001 and other relevant frameworks.
  • Establish practical governance and guardrails for secure enterprise adoption of AI, including approved AI technologies, data protection, third-party AI risk, responsible usage, and emerging AI cybersecurity requirements.
  • Establish measurable cybersecurity KPIs, KRIs, risk reporting, and provide regular program updates to the executive team.


Cloud & Application Security
  • Drive Genea's cloud and application security program in close partnership with Engineering, DevOps, Platform, and Product teams, including secure-by-design practices for traditional applications as well as AI and GenAI capabilities.
  • Strengthen cybersecurity across AWS and Azure, including IAM roles and permissions, least privilege, network controls, secrets management, encryption, logging, secure configurations, infrastructure hardening, and secure access to AI models, agents, APIs, and data.
  • Mature secure SDLC and DevSecOps practices, including threat modeling, architecture reviews, SAST/DAST, dependency and container scanning, software supply-chain security, and controls for emerging AI risks such as prompt injection and excessive agent permissions.
  • Own vulnerability management and coordinate internal and external penetration testing, prioritizing findings and driving remediation with Engineering.


Incident Response & Cybersecurity Operations
  • Own cybersecurity monitoring, detection, investigation, and incident response across cloud, applications, endpoints, corporate systems, and AI-enabled services.
  • Lead incident response from triage and containment through recovery, post-incident review, and corrective actions, while maintaining playbooks and tabletop exercises.
  • Leverage AI and automation to improve threat detection, investigation, alert triage, and response, while monitoring emerging AI-enabled threats and attack techniques.


Identity, Access Management & Corporate IT
  • Own corporate IT operations, including employee endpoints, MDM, SaaS applications, device lifecycle management, onboarding/offboarding, hardware and software provisioning, and employee IT support.
  • Manage identity and access across corporate and approved AI systems, including SSO, MFA, privileged access, least privilege, IAM policies, access reviews, API credentials, and joiner/mover/leaver processes.
  • Drive automation, standardization, patching, secure configuration, endpoint cybersecurity, access governance, and appropriate controls for enterprise AI tools and data usage.


Team Leadership & Development
  • Lead and develop the IT team, establishing clear ownership, operational standards, and accountability across corporate technology and cybersecurity responsibilities.
  • Build the cybersecurity team as the organization grows, identifying capability gaps and hiring or developing the right talent across areas such as cybersecurity engineering, operations, compliance, and risk.


Customer, Vendor & Cybersecurity Risk
  • Own customer cybersecurity questionnaires, RFP responses, customer security reviews, third-party assessments, and vendor cybersecurity risk, including material AI-related vendor and platform risks.
  • Represent Genea's cybersecurity program in customer and partner discussions and clearly communicate Genea's cybersecurity posture and controls.
  • Identify and track material cybersecurity risks, drive remediation, and ensure appropriate executive visibility.


Qualifications
  • 7+ years of experience across cybersecurity, information security, cloud security, application security, security engineering, or IT, including 2+ years in a leadership or management role.
  • Strong technical experience with cloud-native SaaS environments, including AWS and/or Azure, IAM, application security, cloud security, vulnerability management, endpoint cybersecurity, and incident response.
  • Experience with secure SDLC and DevSecOps practices, including threat modeling, penetration testing, SAST/DAST, dependency scanning, container scanning, and secrets management.
  • Practical experience with SOC 2 Type 2, ISO 27001, NIST, or similar cybersecurity frameworks, including working with auditors, assessors, penetration-testing firms, and cybersecurity vendors.
  • Working knowledge of AI/GenAI cybersecurity risks and secure AI adoption practices, including data protection, AI governance, LLM and agent security, and emerging threats such as prompt injection and excessive agent permissions.
  • Strong understanding of modern identity and corporate IT environments, including SSO, MFA, endpoint management, MDM, SaaS administration, and privileged access, with the ability to communicate cybersecurity risk clearly to Engineering teams, customers, business leaders, and executives.
  • Experience building or significantly maturing cybersecurity and IT programs within a growing SaaS technology company preferred.
  • Experience implementing cybersecurity automation across CI/CD, cloud infrastructure, compliance, cybersecurity operations, and AI-enabled workflows preferred.
  • Experience with technologies such as AWS, Azure, Okta, CrowdStrike or equivalent, SIEM, MDM, vulnerability-management platforms, and automated GRC tools preferred.
  • Familiarity with AI cybersecurity frameworks and practices such as NIST AI RMF, OWASP GenAI/LLM guidance, AI red teaming, or securing agentic AI systems; CISSP, CISM, CCSP, or comparable cybersecurity certifications are preferred but not required.


What Success Looks Like

Success in this role means Genea maintains a strong, measurable, and continuously improving cybersecurity posture while supporting the speed and growth of the business.

Cybersecurity risks are clearly identified and prioritized, compliance programs remain audit-ready, cloud and application security practices are integrated into Engineering workflows, AI is adopted with appropriate cybersecurity guardrails, incidents are handled effectively, enterprise customers have confidence in Genea's cybersecurity program, and corporate IT provides employees with a reliable and secure technology environment.

The ideal candidate combines strong technical judgment, practical cybersecurity risk management, operational discipline, a builder's mindset, and a willingness to embrace AI thoughtfully. Cybersecurity should enable the business and Engineering teams to move quickly and securely rather than become a bottleneck.

Compensation

$160-180K annual base salary.This role is also bonus eligible.

This range reflects what Genea reasonably expects to pay for this role at the time of posting. Where an offer falls within the range depends on the candidate's experience, qualifications, and skills, and on internal equity.

Benefits

Full-time employees are eligible to participate in a comprehensive benefits program that includes medical, dental, and vision insurance; flexible spending accounts (FSA); life insurance; accidental death and dismemberment (AD&D) insurance; long-term disability (LTD) coverage; paid time off (PTO); and a 401(k) retirement savings plan. Eligibility is subject to plan terms and conditions.

Similar Jobs

More Jobs at Genea

More Information Technology Jobs

Find similar Senior Manager, Information Security & IT jobs: