
IT Security Manager
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in United States.
• Oversee daily security operations and engineering activities.
• Take ownership of security tools and operations, including EDR/XDR, SIEM, data-loss prevention, device compliance, and Conditional Access/Zero Trust controls.
• Facilitate the Daily Security Huddle and conduct weekly Vulnerability Management meetings.
• Drive the resolution of vulnerabilities to meet defined SLAs.
• Manage the identity and access management program, incorporating MFA, Conditional Access, privileged access management, RBAC, and automation for joiner/mover/leaver processes.
• Act as the main internal liaison for the MSSP/vCISO regarding SOC alert triage, escalation, and follow-up remediation efforts.
• Maintain and enhance incident response playbooks and runbooks.
• Organize tabletop exercises and conduct post-incident reviews.
• Serve as a security escalation point for ongoing incidents.
• Assist with the annual SOC 2 Type II audit cycle, which includes evidence collection, control walkthroughs, and serving as a liaison to auditors.
• Keep NIST CSF control documentation up to date and contribute to risk remediation initiatives.
• Support HIPAA/PHI security measures and carry out periodic risk assessments.
• Coordinate annual third-party penetration testing and follow-up remediation.
• Lead a cross-border security engineering and operations team comprising staff from the U.S. and India.
• Manage performance evaluations, coaching, talent development, and succession planning.
• Collaborate with Infrastructure, Workplace Services, and Development leadership on security initiatives that span multiple functions.
• Minimum of 10 years of experience in information security operations or engineering.
• At least 2 years in a people management or team leadership role.
• Practical experience with Defender for Endpoint, Sentinel, Purview, Intune, and Entra ID, including Conditional Access, MFA, and PIM.
• Familiarity with SOC 2 Type II and/or HIPAA compliance programs, including evidence gathering, control testing, and auditor interactions.
• Experience managing or closely collaborating with an MSSP or outsourced SOC.
• Proven track record in building or enhancing an incident response program, including playbooks and tabletop exercises.
• Comfortable managing distributed teams across the U.S. and India.
• Excellent written and verbal communication skills.
• Ability to articulate technical risks in business language for non-technical stakeholders.
• Opportunity to be part of a well-established and leading brand in a rapidly growing market.
• Gain valuable experience through close collaboration with Executive leadership.
• Work in a positive culture-focused environment.
• Flexible hybrid or remote work options available.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.