Let's grow together.
Information Security Manager
Location
Illinois
Posted
8 days ago
Salary
$119.2K - $146.6K / year
Seniority
Senior
Job Description
Information Security Manager
Mariani Landscape
• Manage and execute the company’s information security program, including policies, procedures, controls, security standards, risk assessments, remediation tracking, and ongoing security improvements. • Perform day-to-day security activities, including monitoring security tools, reviewing alerts, investigating suspicious activity, coordinating remediation, managing vulnerabilities, and improving detective and preventive controls. • Assess, implement, and maintain security controls across enterprise systems, including infrastructure, endpoints, identity platforms, cloud environments, field service applications, mobile devices, and the Microsoft Azure and Microsoft 365 ecosystems. • Maintain and execute the company’s incident response process. Investigate security events, coordinate containment and remediation efforts, document incidents, and work with internal teams and external partners as needed. • Identify and address cybersecurity risks related to field service scheduling systems, mobile device usage, remote workforce access, geographically dispersed operations, and field technician workflows. • Perform or coordinate vulnerability assessments, risk reviews, security control evaluations, and remediation efforts. Prioritize findings based on business impact, likelihood, and operational risk. • Support and improve identity and access management practices, including user access reviews, privileged access controls, multi-factor authentication, conditional access, endpoint security, and device compliance. • Configure, monitor, and improve security across Microsoft Azure and Microsoft 365 environments, including Entra ID, Defender, Purview, Exchange Online, SharePoint, Teams, Intune, and related security capabilities. • Support disaster recovery and business continuity planning from a cybersecurity perspective. Assist with backup protection, recovery testing, ransomware readiness, and resilience planning. • Maintain security documentation, policies, procedures, standards, risk registers, audit evidence, and compliance-related materials. Help ensure alignment with applicable cybersecurity best practices and business requirements. • Promote a practical security awareness culture across the organization, including field technicians, office staff, operations teams, and business users. Support phishing simulations, user education, and security communications. • Assist with security reviews of vendors, service providers, software platforms, and third-party integrations. Track risks and coordinate follow-up remediation where needed. • Work closely with infrastructure, applications, service desk, operations, and business stakeholders to identify security needs, resolve issues, and implement practical security improvements.
Job Requirements
- Minimum of 5+ years of hands-on experience in cybersecurity, information security, infrastructure security, systems administration, or a related technical discipline.
- Demonstrated ability to manage and execute core security functions without relying on a large internal security team.
- Strong technical experience with incident response, vulnerability management, endpoint security, identity and access management, security monitoring, and threat mitigation.
- Solid understanding of cybersecurity principles, common attack techniques, security controls, risk management, and infrastructure hardening.
- Hands-on experience securing Microsoft Azure and Microsoft 365 environments, including creation and maintenance of automation scripts.
- Familiarity with Microsoft security tools such as Microsoft Defender, Entra ID, Intune, Purview, Sentinel, or related technologies preferred.
- Experience supporting security in environments with remote workers, mobile devices, distributed locations, or field service operations strongly preferred.
- Ability to evaluate security risks and recommend practical, business-aligned remediation steps.
- Strong documentation skills, including the ability to maintain policies, procedures, standards, incident records, and risk registers.
- Comfortable communicating security topics to both technical and non-technical audiences.
- Ability to work independently, prioritize effectively, and drive security work to completion.
- Experience with disaster recovery, business continuity, backup protection, and ransomware preparedness preferred.
- Security certifications such as CISSP, CISM, CISA, Security+, CySA+, GSEC, or similar are preferred but not required.
- Infrastructure, cloud, or Microsoft certifications are a plus.
Benefits
- 401(k) plan with company match
- Medical insurance
- Dental insurance
- Vision insurance
- FSA/HSA
- PerkSpot
- Long-Term Disability and Life Insurance
- Paid time Off
- Tuition Reimbursement (after one year of service)
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Serve as the enterprise cybersecurity lead responsible for cybersecurity operations and risk management across infrastructure, endpoints, identity, cloud, applications, data, and third-party environments. • Partner closely with Infrastructure & Operations to strengthen endpoint security, vulnerability management, patching, identity and access management, logging, monitoring, and incident detection and response capabilities. • Provide technical cybersecurity leadership across Microsoft, cloud, SaaS, and enterprise platforms to improve overall security posture. • Partner with enterprise application teams to ensure secure architecture, integrations, and data practices across core business platforms, including Microsoft technologies and enterprise applications. • Lead cybersecurity incident response coordination, tabletop exercises, root cause analysis, and remediation planning. • Evaluate emerging threats and recommend pragmatic, risk-based mitigation strategies aligned to business priorities. • Monitor and assess cybersecurity posture across internal and third-party environments. • Help define and mature enterprise cybersecurity capabilities, operating processes, and governance appropriate for a growing organization. • Develop and maintain cybersecurity policies, standards, procedures, and best practices. • Build and maintain a practical cybersecurity roadmap focused on risk reduction, resiliency, and operational effectiveness. • Establish cybersecurity metrics, scorecards, and reporting for IT leadership and executive stakeholders. • Conduct risk assessments and partner with teams to prioritize remediation activities. • Support security awareness and training initiatives. • Support enterprise cybersecurity governance practices, including access controls, vendor risk management, data protection, and security awareness. • Partner with stakeholders on cybersecurity-related audits, customer questionnaires, cyber insurance requirements, and compliance activities. • Help mature incident response, disaster recovery, and business continuity capabilities. • Establish practical, scalable controls appropriate for a fast-paced, growth-oriented organization. • Drive accountability, service quality, and measurable outcomes across third-party providers. • Evaluate cybersecurity tools and recommend solutions aligned to business needs and organizational maturity. • Establish a strong cybersecurity operating foundation and improve organizational resiliency through pragmatic controls and risk reduction.
• Administer and optimize the DSPM platform (Cyera); drive data discovery, classification, and risk prioritization across cloud and on-premises environments. • Administer and operate the DLP platform (Proofpoint); create, tune, and maintain policies to prevent unauthorized data movement. • Investigate and respond to DLP incidents; work with information owners and business stakeholders to resolve and remediate. • Collaborate with Security Analysts to correlate data security findings with broader security investigations and incidents. • Design and implement a data classification schema and labeling program. • Define and maintain data security policies and procedures. • Build metrics and reporting to communicate program health and risk reduction to leadership. • Partner with legal, compliance, and IT teams to align data security controls with business requirements. • Support audits and regulatory requirements related to data protection. • Contribute to disaster recovery planning and exercises with technology teams.
Information Security Incident Specialist, Fluent Ukrainian
SupportYourAppSupport-as-a-Service that helps companies scale faster by taking care of their customers’ needs.
• Manage security and operational incidents end-to-end, including investigation, coordination, and response; • Communicate directly with Clients and stakeholders during Data Breach incidents; • Conduct Root Cause Analysis, develop preventive measures, and prepare management reports; • Analyze Clients’ workflows and incident trends to identify risks and improve security processes; • Assess the security of software, platforms, and third-party vendors; • Review new hiring locations for compliance with data protection and security standards; • Develop incident response procedures and maintain internal security documentation and knowledge base.
• Assess security configurations across Windows Server, Linux, networking, Azure and Microsoft 365 against recognised best practice standards • Develop and implement remediation plans to address identified security weaknesses across the infrastructure estate • Resolve permission and ACL issues, including file and folder access concerns, without impacting service availability • Improve Azure and Microsoft 365 security posture, including remediation of findings raised by Microsoft security tooling and maintaining Microsoft Secure Score • Strengthen identity, ransomware resilience and end-user security controls across the wider technology estate • Review and uplift data protection measures, including DLP configurations and broader data loss prevention controls • Create and maintain process documentation as controls, processes and operating practices mature




