Remotery

Manager, Information Security

Posted 16 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Automate the creation of System Security Plans (SSP), which encompasses the Security Concept of Operations, Risk Management Matrix, Security Control Traceability Matrix, and perform Security Impact Analysis (SIA) on significant system modifications.

• Develop and manage automated Plans of Action and Milestones (POAMs).

• Contribute to the automation and implementation of Artificial Intelligence (AI) within Synack’s Information Security operations.

• Oversee inventory and risk assessments of AI/agentic systems in accordance with NIST AI RMF and ISO 42001, including aspects such as data management, model and agent change control, non-human identity, and credential scoping.

• Create and manage automated evidence collection and control-drift monitoring for security controls.

• Engage with stakeholders regarding security compliance matters aligned with CIS and NIST standards; monitor mitigation/remediation efforts and assist with reports and metrics.

• Codify security controls into Infrastructure as Code (IaC) guardrails, CNAPP policies, and CI/CD checks to mitigate risks at the commit and deployment stages.

• Collaborate with Project Managers and Software Engineers to integrate information security policies, standards, procedures, and guidelines across hosted services and infrastructure, emphasizing hardening and DevSecOps principles.

• Coordinate with field teams on vendor security assessments and conduct third-party risk evaluations of Synack vendors.

• Ensure the security and privacy posture of Synack is upheld.


⛳️ Requirements

• 8+ years of experience in IT Security Strategy, Risk Management, IT Audit, and Compliance within a Cloud Service Provider environment.

• Proficiency in Python, Terraform, and CI/CD pipelines.

• Ability to integrate tools with AI effectively.

• Experience with Enterprise Governance, Risk Management, and Compliance (GRC) tools.

• Familiarity with event monitoring and alerting solutions such as Datadog, Stackdriver, and Azure Sentinel.

• Experience with SOAR or auto-remediation platforms, as well as detection engineering and SIEM query languages.

• Knowledge of Cloud Native Application Protection Platforms (CNAPP).

• Experience in leveraging security tools throughout the Software Development Lifecycle (SDLC).

• Understanding of secrets management and workload identity (non-human).

• Working knowledge of ISO27000, ISO42001, OWASP, SOC2, GDPR, CMMC, FedRAMP, and NIST standards.

• Exceptional written and verbal communication skills tailored for both technical and non-technical audiences.

• Must be a United States citizen due to federal government contract stipulations.


🏝️ Benefits

• Equity may be part of the compensation package.

• A comprehensive benefits package is available; refer to Synack’s benefits overview for details.

• An inclusive and diverse workplace.

People also viewed

FRSecure15 hours ago

Information Security Assessor

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$85k – $95k/year
ApplyView job
Coinbase16 hours ago

Product Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security EngineerC$154k/year
ApplyView job
GoodLeap18 hours ago

Senior Security Engineer, Product Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$146k – $185k/year
ApplyView job
6sense18 hours ago

Senior Security Assurance Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$141.2k – $180.1k/year
ApplyView job
Vultr18 hours ago

Physical Security System Designer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$90k – $10k/year
ApplyView job
Vultr18 hours ago

Physical Security Evaluator

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$80k – $100k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers