
Senior Information Security Manager
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California.
• Take ownership and enhance preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments.
• Convert overarching security objectives into specific technical requirements, controls, tools, and implementation strategies.
• Assess, select, configure, and implement security platforms and tools for DLP, insider threats, endpoint security, IAM, vulnerability management, access controls, and security monitoring.
• Continuously evaluate security posture, pinpoint gaps and vulnerabilities, prioritize risks, and drive remediation to completion.
• Collaborate with IT, Engineering, DevOps, and Product teams to integrate security controls into technologies, infrastructures, and business initiatives.
• Develop metrics and reporting on the effectiveness of security controls and the overall security posture.
• Work alongside Security Operations to enhance visibility and protection for threat investigation and response.
• Create, maintain, and test incident response playbooks, business continuity processes, and disaster recovery plans.
• Collaborate with the CISO, CIO, and CTO on security compliance initiatives and engage directly with auditors.
• Convert requirements from SOC 2, ISO 27001, ISO 42001, GDPR, CCPA/CPRA, and the EU AI Act into practical technical controls.
• Provide technical guidance and mentoring to security engineers, analysts, IT partners, and external contractors.
• Act as a trusted security advisor for both technical and non-technical stakeholders.
• Manage ambiguous security challenges from strategy and evaluation through implementation, measurement, and ongoing improvement.
• 7+ years of progressive experience in information security, with substantial hands-on experience in implementing enterprise security controls.
• 2+ years of experience in technical leadership, team leadership, or people management.
• Profound understanding of cloud, SaaS, endpoint, identity, network, and data security, including traditional and Agentic AI environments and workloads.
• Strong hands-on experience in implementing security tools and controls rather than just defining policy or overseeing implementation.
• Experience with DLP, IAM, endpoint security, vulnerability management, insider threats, access management, and security monitoring.
• Solid understanding of modern cloud infrastructure, security architecture, and risk management.
• Experience working in environments that use Mac, Linux, cloud, SaaS, and open-source technologies.
• Experience in automating security controls and workflows through scripting (e.g., Python) and infrastructure as code security (e.g., Terraform, policy as code, CI/CD pipeline guardrails).
• Familiarity with NIST, CIS, ISO 27001, SOC 2, and Zero Trust frameworks.
• Experience participating in security audits, working closely with auditors, collecting technical evidence, and addressing findings.
• Extensive knowledge of securing third-party API and OAuth integrations, including scoping, token lifecycle management, and revocation across SaaS and data platforms.
• Ability to translate complex technical threats and vulnerabilities into actionable solutions collaboratively with Engineering, Product, IT, and non-technical stakeholders.
• Strong analytical and problem-solving skills, with the ability to independently assess security challenges and determine the appropriate technical approach.
• Experience in U.S.-based technology environments and familiarity with enterprise security expectations.
• Comfortable working autonomously in a fast-paced environment where priorities and requirements are subject to change.
• Regular employees may qualify for commissions or bonus programs (target included in OTE).
• Equity opportunities.
• Comprehensive benefits.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.