
Senior Manager, Information Security, IT
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in California.
• Lead and enhance Genea's cybersecurity and corporate IT initiatives.
• Oversee and advance the cybersecurity compliance program, which includes SOC 2 Type 2, policies, controls, audit preparedness, evidence management, risk assessments, awareness, and ISO 27001 readiness.
• Set up governance and guidelines for secure enterprise AI implementation.
• Develop cybersecurity KPIs, KRIs, and risk reporting, providing updates to executives.
• Collaborate with Engineering, DevOps, Platform, and Product teams to enhance cloud and application security.
• Fortify security measures across AWS and Azure, focusing on IAM, least privilege, network controls, secrets management, encryption, logging, secure configurations, and infrastructure hardening.
• Advance secure SDLC and DevSecOps methodologies, including threat modeling, architecture assessments, SAST/DAST, dependency and container scanning, supply-chain security, and AI-risk controls.
• Manage vulnerability assessments and coordinate penetration testing and remediation efforts.
• Supervise cybersecurity monitoring, detection, investigation, and incident response for cloud, applications, endpoints, corporate systems, and AI-enabled services.
• Lead incident response activities including containment, recovery, post-incident analysis, corrective measures, playbooks, and tabletop exercises.
• Utilize AI and automation for threat detection, investigation, alert triage, and response management.
• Oversee corporate IT operations, encompassing endpoints, MDM, SaaS applications, device lifecycle management, onboarding/offboarding, provisioning, and employee IT support.
• Manage identity and access protocols, including SSO, MFA, privileged access, IAM policies, access audits, API credentials, and joiner/mover/leaver workflows.
• Develop and lead the IT team and build the cybersecurity team as the organization expands.
• Handle customer security questionnaires, RFP submissions, customer security evaluations, third-party assessments, and vendor cybersecurity risk management.
• Represent Genea's cybersecurity initiatives in discussions with customers and partners.
• Identify and monitor critical cybersecurity risks, drive remediation efforts, and ensure visibility for executives.
• 7+ years of experience in cybersecurity, information security, cloud security, application security, security engineering, or IT, with at least 2 years in a leadership or management position.
• Extensive technical expertise with cloud-native SaaS environments, particularly AWS and/or Azure, IAM, application security, cloud security, vulnerability management, endpoint cybersecurity, and incident response.
• Familiarity with secure SDLC and DevSecOps practices, including threat modeling, penetration testing, SAST/DAST, dependency scanning, container scanning, and secrets management.
• Hands-on experience with cybersecurity frameworks such as SOC 2 Type 2, ISO 27001, NIST, or similar, including collaboration with auditors, assessors, penetration-testing firms, and cybersecurity vendors.
• Understanding of AI/GenAI cybersecurity risks and secure AI adoption practices, covering data protection, AI governance, LLM and agent security, prompt injection, and preventing excessive agent permissions.
• Strong knowledge of contemporary identity and corporate IT environments, including SSO, MFA, endpoint management, MDM, SaaS administration, and privileged access controls.
• Capability to articulate cybersecurity risks clearly to Engineering teams, customers, business leaders, and executives.
• Preferred experience in building or substantially maturing cybersecurity and IT programs within a growing SaaS technology company.
• Experience in implementing cybersecurity automation across CI/CD, cloud infrastructure, compliance, cybersecurity operations, and AI-enabled workflows is a plus.
• Familiarity with AWS, Azure, Okta, CrowdStrike or equivalent, SIEM, MDM, vulnerability-management platforms, and automated GRC tools is advantageous.
• Knowledge of AI cybersecurity frameworks and practices, such as NIST AI RMF, OWASP GenAI/LLM guidance, AI red teaming, or securing agentic AI systems.
• CISSP, CISM, CCSP, or comparable cybersecurity certifications are preferred but not mandatory.
• Must meet U.S. employment eligibility verification requirements.
• 401(k) matching
• PTO
• 100% paid parental leave
• Remote work options
• Development/training opportunities
• Medical insurance
• Dental insurance
• Vision insurance
• Flexible spending accounts (FSA)
• Life insurance
• Accidental death and dismemberment (AD&D) insurance
• Long-term disability (LTD) coverage
• 401(k) retirement savings plan
• Bonus eligibility
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.