
Manager, Information Security
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Automate the creation of System Security Plans (SSP), which encompasses the Security Concept of Operations, Risk Management Matrix, Security Control Traceability Matrix, and perform Security Impact Analysis (SIA) on significant system modifications.
• Develop and manage automated Plans of Action and Milestones (POAMs).
• Contribute to the automation and implementation of Artificial Intelligence (AI) within Synack’s Information Security operations.
• Oversee inventory and risk assessments of AI/agentic systems in accordance with NIST AI RMF and ISO 42001, including aspects such as data management, model and agent change control, non-human identity, and credential scoping.
• Create and manage automated evidence collection and control-drift monitoring for security controls.
• Engage with stakeholders regarding security compliance matters aligned with CIS and NIST standards; monitor mitigation/remediation efforts and assist with reports and metrics.
• Codify security controls into Infrastructure as Code (IaC) guardrails, CNAPP policies, and CI/CD checks to mitigate risks at the commit and deployment stages.
• Collaborate with Project Managers and Software Engineers to integrate information security policies, standards, procedures, and guidelines across hosted services and infrastructure, emphasizing hardening and DevSecOps principles.
• Coordinate with field teams on vendor security assessments and conduct third-party risk evaluations of Synack vendors.
• Ensure the security and privacy posture of Synack is upheld.
• 8+ years of experience in IT Security Strategy, Risk Management, IT Audit, and Compliance within a Cloud Service Provider environment.
• Proficiency in Python, Terraform, and CI/CD pipelines.
• Ability to integrate tools with AI effectively.
• Experience with Enterprise Governance, Risk Management, and Compliance (GRC) tools.
• Familiarity with event monitoring and alerting solutions such as Datadog, Stackdriver, and Azure Sentinel.
• Experience with SOAR or auto-remediation platforms, as well as detection engineering and SIEM query languages.
• Knowledge of Cloud Native Application Protection Platforms (CNAPP).
• Experience in leveraging security tools throughout the Software Development Lifecycle (SDLC).
• Understanding of secrets management and workload identity (non-human).
• Working knowledge of ISO27000, ISO42001, OWASP, SOC2, GDPR, CMMC, FedRAMP, and NIST standards.
• Exceptional written and verbal communication skills tailored for both technical and non-technical audiences.
• Must be a United States citizen due to federal government contract stipulations.
• Equity may be part of the compensation package.
• A comprehensive benefits package is available; refer to Synack’s benefits overview for details.
• An inclusive and diverse workplace.
FRSecure
Coinbase
GoodLeap
6sense
Get handpicked remote jobs straight to your inbox weekly.