IT Security Manager

Posted Sep 18

This is a fully remote position, open to applicants in United States.

📋 Description

• Oversee daily security operations and engineering activities.

• Take ownership of security tools and operations, including EDR/XDR, SIEM, data-loss prevention, device compliance, and Conditional Access/Zero Trust controls.

• Facilitate the Daily Security Huddle and conduct weekly Vulnerability Management meetings.

• Drive the resolution of vulnerabilities to meet defined SLAs.

• Manage the identity and access management program, incorporating MFA, Conditional Access, privileged access management, RBAC, and automation for joiner/mover/leaver processes.

• Act as the main internal liaison for the MSSP/vCISO regarding SOC alert triage, escalation, and follow-up remediation efforts.

• Maintain and enhance incident response playbooks and runbooks.

• Organize tabletop exercises and conduct post-incident reviews.

• Serve as a security escalation point for ongoing incidents.

• Assist with the annual SOC 2 Type II audit cycle, which includes evidence collection, control walkthroughs, and serving as a liaison to auditors.

• Keep NIST CSF control documentation up to date and contribute to risk remediation initiatives.

• Support HIPAA/PHI security measures and carry out periodic risk assessments.

• Coordinate annual third-party penetration testing and follow-up remediation.

• Lead a cross-border security engineering and operations team comprising staff from the U.S. and India.

• Manage performance evaluations, coaching, talent development, and succession planning.

• Collaborate with Infrastructure, Workplace Services, and Development leadership on security initiatives that span multiple functions.


⛳️ Requirements

• Minimum of 10 years of experience in information security operations or engineering.

• At least 2 years in a people management or team leadership role.

• Practical experience with Defender for Endpoint, Sentinel, Purview, Intune, and Entra ID, including Conditional Access, MFA, and PIM.

• Familiarity with SOC 2 Type II and/or HIPAA compliance programs, including evidence gathering, control testing, and auditor interactions.

• Experience managing or closely collaborating with an MSSP or outsourced SOC.

• Proven track record in building or enhancing an incident response program, including playbooks and tabletop exercises.

• Comfortable managing distributed teams across the U.S. and India.

• Excellent written and verbal communication skills.

• Ability to articulate technical risks in business language for non-technical stakeholders.


🏝️ Benefits

• Opportunity to be part of a well-established and leading brand in a rapidly growing market.

• Gain valuable experience through close collaboration with Executive leadership.

• Work in a positive culture-focused environment.

• Flexible hybrid or remote work options available.

People also viewed

Sony Interactive Entertainment17 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads18 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j18 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)19 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting19 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International20 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers