Information Security, Risk Manager

Posted 2 days ago

This is a fully remote position, open to applicants in Texas.

📋 Description

• Lead the ISO 27001 certification process for Empyrean, including surveillance, internal audit preparation, and ongoing compliance with ISMS.

• Coordinate the testing of ISO 27001 controls and manage communication with control owners, business partners, and audit stakeholders.

• Assist in assessments and assurance activities related to SOC 2, NIST AI RMF, NIST CSF, NIST 800-53, HIPAA, and additional frameworks.

• Identify, evaluate, document, monitor, and communicate information security risks and control deficiencies.

• Develop, implement, track, and validate plans for corrective action and risk remediation.

• Oversee audit and assessment activities concerning information security, cybersecurity, business applications, and technology controls.

• Direct or facilitate risk assessments for technology projects, environmental changes, third parties, emerging technologies, exceptions, and risk events.

• Organize security risk and governance meetings, ensuring thorough preparation, documentation, and follow-up.

• Maintain the enterprise information security risk register along with related risk, issue, exception, and remediation documentation.

• Provide technical knowledge and apply security and compliance practices to identify control weaknesses and manage policy exceptions.

• Lead security and technology responses for client questionnaires, RFPs, due diligence requests, and internal inquiries.

• Assess the effectiveness of enterprise cybersecurity threat and vulnerability monitoring and management.

• Develop and uphold information security policies, standards, and governance documentation.

• Offer expertise in security risk and IT controls for technology initiatives, evaluating control design and implementation.

• Interpret audit results, provide actionable recommendations, and verify the implementation of remediation measures.

• Support wider information security initiatives, incident management, escalations, strategic roadmaps, and projects.


⛳️ Requirements

• Excellent communication, presentation, and organizational skills.

• Strong time-management abilities and capacity to juggle multiple priorities.

• Capability to collaborate effectively with diverse roles and teams.

• Previous experience in security compliance, risk management, or auditing, especially with ISO 27001.

• Familiarity with SOC 2, HIPAA, NIST, FedRAMP, or similar frameworks is advantageous.

• Experience in preparing work papers, audit reports, and presentations.

• Practical knowledge of information security, technology risk management, auditing, and control assurance practices.

• Solid understanding of ISO 27001, SOC 2/TSC, NIST CSF, NIST 800-53, NIST AI RMF, CIS, COBIT, and related frameworks.

• Experience with enterprise workflow, ticketing systems, directory services, IT infrastructure, GRC, and security technologies; familiarity with ServiceNow and Jira is beneficial.

• High standards of integrity and confidentiality.

• Over 5 years of experience in information security risk, governance, compliance, technology auditing, security engineering, or related fields.

• Knowledge of IT and security best practices and frameworks such as NIST CSF, SOC 2/TSC, CIS, ISO 27001/ISMS, COBIT, and ITIL.

• Understanding of technology risks and experience in evaluating cybersecurity, privacy, and engineering controls.

• Familiarity with vulnerability management, security governance, software development, incident response, physical security, logging and monitoring, micro-segmentation, SASE, zero trust, insider threat, vendor risk management, PKI, penetration testing, application controls, and segregation of duties.

• Advanced knowledge of internal controls and the ability to assess control design and operational effectiveness.


🏝️ Benefits

• Comprehensive health and wellness benefits.

• Opportunities for professional development and growth.

• Flexible work arrangements to promote work-life balance.

• Competitive salary and performance-based incentives.

• Engaging work environment with a focus on collaboration and innovation.

People also viewed

Sony Interactive Entertainment14 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads15 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j15 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)16 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting16 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International17 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers