Job Closed
This listing is no longer active.
Delivering decision advantage to mission partners worldwide
Information Systems Security Manager
Location
United States
Posted
118 days ago
Salary
$152.0K - $228.1K / year
Seniority
Lead
Job Description
Information Systems Security Manager
Ultra Intelligence & Communications
• Oversees multiple ISSMs, managing comprehensive security programs across various countries or businesses, and ensuring compliance with diverse government regulations • Provides strategic leadership and direction to a team of ISSMs across multiple regions or businesses • Develops, implements, and maintains a comprehensive information security strategy aligned with diverse government compliance requirements • Oversees the creation and management of security policies, standards, and procedures that meet various national and international regulations • Coordinates and standardizes security practices across different countries or businesses while conforming with unique compliance requirements • Leads enterprise-wide risk management efforts, ensuring consistent risk assessment and mitigation strategies across all operations • Manages relationships with government agencies, regulators, and external auditors across multiple jurisdictions • Oversees the budget for global information security initiatives and justifies security investments to leadership • Develops and maintains a comprehensive compliance program that addresses the requirements of multiple government requirements • Leads high-level incident response planning and execution for major security events that may have international implications • Provides regular briefings to leadership and the board of directors on the global security posture, compliance status, and risk landscape • Stays informed about evolving international cybersecurity regulations and emerging global threats • Fosters a culture of security awareness and compliance across the entire organization • Drives innovation in security practices to address evolving threats in a global context
Job Requirements
- Typically, a Bachelor Degree (or equivalent) in Computer Science, Information Security, Business Administration, or related field
- 15+ years of experience in information security, with 8+ years in senior leadership roles
- Extensive knowledge of international information security frameworks, standards, and compliance requirements (e.g., NIST, ISO 27001, GDPR, CMMC)
- Certifications Required: CISSP (Certified Information Systems Security Professional)
- Additional senior-level certifications such as CISM, CRISC, or CGEIT
- Preferred Qualifications: Master Degree (or equivalent)
- Experience working with classified systems and holding a high-level security clearance
- Background in government contracting or military information security operations
- Familiarity with cloud security architectures and compliance in multi-national environments
- Knowledge of AI and machine learning applications in global cybersecurity operations
- Experience with governance, risk, and compliance (GRC) platforms on an enterprise scale
- Proven experience managing multi-national or multi-sponsor security programs
Benefits
- Climate controlled, well-lit and clean work environment!
- Work/life balance that includes up to 3 weeks PTO for first year
- 8 Paid Holidays, with 3 floating holidays
- 401k Plan with Company Match
- Educational Assistance Program (Tuition Reimbursement)
- Wellness Program and incentives
- Company HSA contributions
- Insurance Benefits that start 1st of the month following hire
- Eligibility in Company Performance-based bonuses annually
- Additional Employee Discounts and Perks
- Company-Paid Benefits: $75 monthly student loan repayment program
- Basic Life Insurance
- Basic Accidental Death and Dismemberment (AD&D) Insurance
- Short Term Disability
- Long Term Disability
- Employee Assistance Program (EAP)
- Voluntary Employee-Paid Benefits: Medical and Prescription insurance
- Dental insurance
- Vision insurance
- Supplemental Life Insurance Plans
- Supplemental AD&D insurance for Employee and Family
- Accident Plan
- Critical Illness Plan
- Hospital Indemnity Plan
- Pet Insurance
- Identity Theft
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Design and implement security solutions for Java-based applications • Secure applications, microservices, APIs, and databases against vulnerabilities • Perform static (SAST) and dynamic (DAST) security testing • Perform quarterly Vulnerability Scans and annual Penetration Test • Manage application dependencies and vulnerabilities within established SLAs • Implement and support authentication (OAuth, SAML), authorization (RBAC), and encryption • Integrate security into the CI/CD pipeline to automate security testing and compliance checks • Monitor, analyze, and respond to security incidents and security questionnaires • Manage Drata for security monitoring, compliance automation, and audit readiness • Ensure compliance with data protection regulations (GDPR, CCPA, HIPAA) and security frameworks (ISO 27001, NIST, SOC 2) • Collaborate with development teams to enforce secure coding best practices via code reviews • Work with Spring Security to enforce access controls and secure distributed applications • Maintain and publish TopQuadrant’s Authorized Software List • Stay updated on the latest security vulnerabilities affecting Java and Spring ecosystems
Senior Security Advisor – Lead Control Assessor
Soteria - Security Solutions & AdvisoryTailored Security Solutions Managed Detection and Response
• Lead and execute cybersecurity control assessments against a defined subset of key controls aligned to established frameworks (NIST SP 800-53 Rev. 5). • Assess control implementation status using standardized criteria and validation methodologies. (NIST SP 800-53A Rev. 5). • Test information systems using documentation review, system walk-throughs, and stakeholder interviews to assess the design and operating effectiveness of NIST SP 800-53 Rev. 5 security controls. • Apply consistent judgment to determine evidence sufficiency and appropriateness. • Lead planning, kickoff, execution coordination, and closeout activities for assigned assessment engagements. • Coordinate assessment activities and task assignments across Control Assessors to meet delivery timelines. • Serve as the primary point of contact for client stakeholders during assessment engagements. • Review and approve assessment narratives, findings, and control determinations prior to quality assurance submission. • Ensure assessments are executed consistently across multiple clients to support trend analysis and benchmarking. • Enforce adherence to defined assessment methodologies, scope boundaries, and validation standards. • Support quality assurance reviews by addressing feedback and ensuring accuracy, clarity, and consistency of deliverables. • Lead and participate in client interviews, system walkthroughs, and working sessions in a professional, structured manner. • Clearly communicate assessment scope, expectations, and evidence requirements to stakeholders. • Present assessment results, key findings, and risk implications to executive leadership and board-level stakeholders in a clear, concise, and professional manner. • Mentor and guide Control Assessors on assessment techniques, documentation standards, and professional judgment. • Escalate risks, issues, or control interpretation questions to program leadership as appropriate.
• Manage certification frameworks, including CMMC, NIST, and SOC 2 • Assist the Company to successfully achieve compliance with applicable security certifications • Develop, track, and maintain security and compliance policy documents • Build and maintain controls documentation aligned with multiple compliance frameworks and standards • Ensure ongoing compliance with the Company’s information security policies and procedures and ensure controls are implemented • Develop IT security standards, best-practice implementations, and systems to ensure enterprise information system security • Identify acceptable levels of risk and establish roles and responsibilities for information classification and protection • Maintain security policies and procedures • Evaluate risk and develop security standards, procedures, and controls with a mindset of continuous process improvement • Analyze and review system configurations for security vulnerabilities • Monitor Company security vulnerabilities • Assist with remediation of escalated incident tickets and review completed tickets for accuracy and sufficiency • Conduct vendor security assessments and support the Company’s vendor management program • Coordinate security and compliance technology development requests • Coordinate with external IT service providers on security and compliance matters, including device configuration, application management, and security updates • Attend Security Committee meetings and draft meeting minutes • Coordinate Security Committee meetings and maintain records of activities • Communicate cybersecurity risks to senior management through reports, presentations, metrics, and documentation • Conduct security awareness training and assist with publishing security bulletins and advisories • Design and conduct testing of data security controls, including simulated events and phishing exercises • Provide security guidance and training to Company employees • Provide security guidance for IT projects, including evaluation and recommendation of technical controls
Senior Security Engineer
you.comYou.com, founded in 2020 by AI experts Richard Socher and Bryan McCann, is a rapidly growing AI-powered productivity platform headquartered in Palo Alto, Califo
• Act as a security subject matter expert to support engineers through design reviews, threat modeling, code reviews, patch creation, and security testing. • Collaborate with product and engineering teams to architect resilient, security-first services. • Engineer and implement secure, scalable, and resilient systems. • Develop and customize high-signal security tooling through automation and plugins. • Manage day-to-day security tasks, including abuse remediation, threat research, and incident handling. • Participate in on-call rotations and incident response efforts to ensure platform and customer security.



