
Global IT Manager, Security & Compliance
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in United States.
• Take charge of the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for around thirteen operational sites.
• Serve as IT's representative to external certification organizations and auditors; prepare for audits, present and defend control evidence, and manage the resolution of IT findings until closure.
• Oversee third-party and vendor risk management for IT, which includes conducting vendor security assessments and periodic reassessments.
• Manage customer-facing security due diligence, encompassing questionnaires, audits, and assessments.
• Sustain the IT risk register and opportunities-for-improvement log, ensuring items are driven to closure.
• Coordinate IT's involvement in business continuity and disaster recovery testing and document the outcomes.
• Handle the end-to-end vulnerability management process, including scanning coverage, triage, remediation ownership, escalation, and leadership reporting.
• Supervise endpoint detection and response as well as the security alerting pipeline; ensure alerts are assigned, investigated, recorded, and resolved.
• Lead security incident response efforts, including containment, investigation, root cause analysis, customer-facing incident reporting, and post-incident enhancements.
• Manage email security aspects, including domain authentication posture and secure email gateway configuration.
• Implement the security awareness program, featuring monthly phishing simulations, results analysis, and targeted follow-ups.
• Contribute to identity governance across a hybrid cloud and on-premises identity-provider landscape.
• Oversee access reviews, privileged access controls, and the joiner-mover-leaver process, including access for third parties and contractors.
• A minimum of eight years in information security, IT compliance, or IT risk, with substantial experience in both compliance and technical security roles.
• Proven ownership of an ISO 27001 program, including firsthand experience in preparing for and defending findings with an external certification body.
• Practical experience with at least two of the following: SOC 2, PCI DSS, HIPAA, NIS2, or DORA.
• Solid technical expertise, including the ability to read firewall and authentication logs, assess vulnerability scans, evaluate OAuth consent requests, and contest proposed remediations.
• Familiarity with vulnerability management platforms, endpoint detection and response tools, and enterprise identity solutions.
• Experience in leading security incident responses through to a conclusion that is suitable for both customers and executives.
• Capability to communicate risks effectively to both engineers and executives, as well as to hold vendors and internal stakeholders accountable without formal authority.
• Willingness to travel to sites occasionally for audits, assessments, and control validation.
• Paid time off
• Paid holidays
• 401(k)
• Full coverage medical insurance
• Full coverage dental insurance
• Full coverage vision insurance
WOW
Serverfarm
Hinge Health
VSP Vision Care
Get handpicked remote jobs straight to your inbox weekly.