HICX logo
HICX

The platform for supplier experience management

Information Security Manager

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2008H1B No SponsorCompany SiteLinkedIn

Location

Romania

Posted

1 day ago

Salary

0

Seniority

Senior

Bachelor DegreeEnglishAWSAzureCloud

Job Description

Information Security Manager

HICX

• Set up and drive the overall information security strategy. • Own the ISMS standards and their adoption, ensuring compliance with company and external requirements including SOC 2 and ISO 27001. • Organise and manage ISMS-related scheduled activities and drive continuous improvement of the ISMS. • Contribute to security architecture and design decisions. • Oversee security tooling such as EDR, SIEM, MFA, password managers, device management, and access review processes. • Act as the primary escalation point, during and outside business hours, for all major security-related incidents and events. • Coordinate and manage corrective actions and responses to security incidents. • Own security documentation, including policies, standards, exceptions, risk registers, and control evidence. • Oversee the internal risk-assessment and audit programme, supporting internal and external audits, remediating findings, and tracking control improvements to closure. • Support vendor and supplier risk management, including due diligence, sub-processor oversight, and security assessments. • Own the access control process, validate and audit access across divisions and functions. • Provide management reporting on risk posture, incidents, audit status, metrics, service trends, and improvement plans. • Work with engineering, DevOps, HR, and customer facing teams to embed controls into everyday processes. • Drive ongoing security governance improvements. • Address data privacy and data protection concerns, and manage responses to customer data privacy requests. • Act as Data Protection Officer (DPO) for the organisation if and as required. • Help enforce security policies, building adoption, embedding them in the company culture, and introducing regular checks on departmental compliance. • Own and deliver security awareness training and campaigns to strengthen the security culture. • Complete security-related sections of RFPs and customer questionnaires, build and maintain a security knowledge base, and provide assurance of the integrity, confidentiality, and availability of information owned, controlled, and processed by the organisation. • Attend meetings with customers and prospects to provide insights into how HICX implements security across the organization. • Manage a small team of IT support admins providing internal IT support to HICX employees and contractors. • Act as the escalation point for complex IT issues, incidents, and problems requiring cross-team coordination. • Ensure IT support activities align with security controls, access management, and acceptable use requirements. • Oversee onboarding, offboarding, account lifecycle management, and device provisioning/deprovisioning. • Own and maintain standard operating procedures and the operations platform. • Help balance usability, cost, and security when selecting or renewing SaaS and IT tools. • Carry out other reasonable duties as required by the Company.

Job Requirements

  • Excellent track record of leading security audits; ISO 27001, SOC 2, Cyber Essentials Plus
  • Proven experience in a senior information security leadership role (Head of Security, Information Security Manager, or similar), ideally within a SaaS or technology business.
  • Demonstrable experience building, operating, and maturing an ISMS, including achieving and maintaining SOC 2 and ISO 27001 certification.
  • Strong, hands-on knowledge of security tooling and controls; EDR, SIEM, MFA, identity and access management, device/endpoint management, and vulnerability management.
  • Solid understanding of cloud security (AWS, Azure, and Microsoft 365 admin suite)
  • Experience leading end-to-end security incident response, including out-of-hours management of major incidents.
  • Knowledge of UK GDPR/GDPR and global data protection laws, with experience acting as, or working closely with, a Data Protection Officer.
  • Experience of third-party, vendor, and supplier risk management, including due diligence and sub-processor oversight.
  • Experience completing customer security questionnaires and RFPs, maintaining a security knowledge base, and presenting security posture to customers and prospects.
  • Excellent communication skills, with the ability to translate technical risk into clear business language for technical and non-technical audiences, including executives and customers.
  • Strong leadership and people-management skills, with a track record of developing and motivating a small team.
  • Pragmatic, risk-based mindset that balances security with business enablement, usability, and cost.
  • Highly organised, self-motivated, and comfortable working autonomously within a fully remote, international team.
  • Collaborative and influential, able to embed a strong security culture across the whole organisation.
  • Relevant professional certification is desirable (e.g. CISSP, CISM, CISA, or ISO 27001 Lead Implementer/Auditor).
  • Experience managing internal IT operations and a small IT support team, onboarding/offboarding, account lifecycle, device provisioning, and SaaS administration is desirable

Benefits

  • You must be Based in Bucharest, Romania for this role however can work remotely from this location.
  • Flexible PTO - We offer 25 days of paid holiday per year + 3 Public Holidays.
  • We celebrate special occasions with you - like your birthday! Additional PTO for all employees during their birthdays.
  • Receive Competitive Pay - Our team makes sure to provide a highly competitive rate based on your skills and location.
  • Work with a diverse, international team.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 11-50H1B No Sponsor

• Lead Cloud & AI Security Strategy: Own and execute the strategic vision, roadmap, and operating model for Ascension's Cloud Security and AI Security programs under the Senior Director, driving secure adoption of cloud and AI technologies through risk-based priorities, measurable outcomes, and alignment with enterprise objectives. • Build and Develop High-Performing Teams: Lead, coach, and inspire Cloud Security and AI Security teams while establishing scalable operating models, conducting capacity and workforce planning, optimizing team processes, and fostering a culture of accountability, collaboration, adaptability, and continuous learning. • Drive Security Technology Strategy & Program Transformation: Develop and manage the Cloud Security & AI Security technology roadmap, including capability planning, technology evaluation, vendor selection, and oversight of implementations such as CNAPP, AI security controls, and automation capabilities. • Advance Secure Cloud & AI Enablement: Partner across technology, architecture, engineering, governance, legal, and business teams to establish security standards, risk management practices, and control requirements that enable innovation while protecting Ascension's cloud environments and AI solutions. • Measure, Communicate, and Advance Security Outcomes: Establish program metrics, key performance indicators, executive reporting, and strategic points of view to communicate risk, security posture, priorities, and program value. Develop and deliver presentations to senior management to support decision-making and drive alignment across the enterprise.

United States
$138.3K - $195.2K / year
Ellit Groups logo

C2C Security Architect

Ellit Groups

Putting patients at the heart of healthcare digital transformation enabled by information technology.

ContractRemoteTeam 51-200Since 2019H1B No Sponsor

• Act as a subject matter expert in enterprise security architecture, risk management, and compliance frameworks. • Perform security risk reviews across applications, infrastructure, and enterprise systems, identifying vulnerabilities and recommending mitigation strategies. • Support AI adoption initiatives within security risk assessment processes. • Translate business, regulatory, and clinical security requirements into technical security control specifications. • Design, implement, and evaluate security architecture frameworks and controls across enterprise platforms. • Lead and support security architecture solutioning during pre-implementation and system design phases. • Conduct application and infrastructure vulnerability assessments, including identification of gaps and remediation recommendations. • Develop and maintain security metrics, reporting dashboards, and performance indicators for ongoing risk monitoring. • Ensure alignment of security architecture with enterprise standards and regulatory requirements. • Collaborate with enterprise architecture teams to ensure alignment between business objectives, technical architecture, and security controls. • Partner with security engineering teams to implement secure configurations and enforce security policies. • Design and validate identity and access management (IAM) controls. • Evaluate and strengthen network security architecture.

United States
Coalition, Inc. logo

Security Support Specialist

Coalition, Inc.

Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines comprehensive insurance coverage and innovative cybersecurity tools to help businesses manage and mitigate potential cyberattacks. Work at Coalition is centered on the joint mission to Protect the Unprotected. We have built a remote-first, highly inclusive culture that welcomes people from diverse backgrounds. We trust each other to take responsibility, share ownership of outcomes, and put in the work together to protect businesses from digital risk. Coalition’s exceptional growth stems from its ability to address real-world problems for organizations of all sizes while remaining true to our founding values of character, humility, responsibility, purpose, authenticity, and inclusion.

Full TimeRemoteTeam 501-1,000

Role Description In the Senior Security Support Analyst role, your mandate is to assist our policyholders in understanding how to use Coalition’s provided security tools in order to improve their risk posture and reduce the likelihood of a cyber attack and subsequent claim. Our Security Support Center provides world-class support to Coalition's 100,000+ policyholder base. - Help policyholders navigate our security products, tailoring messaging to their technical proficiency. - Explain how to address critical security findings and why addressing those findings reduces risk. - Work closely with product and engineering teams to codify security best practices into underwriting algorithms, rating models, and risk management apps. - Lead team initiatives, handle complex cases and projects, and act as a subject-matter expert (SME). - Demonstrate high throughput in handling case workload alongside your team. Responsibilities - Risk Assessment & Customer Advisory - Independently review and analyze the security posture of insureds and prospective insureds. - Evaluate customer security programs, technologies, controls, and business environments. - Advise technical and non-technical stakeholders on security architecture and cloud security. - Assess and quantify security risk to enable underwriting and project leadership decisions. - Technical Support - Provide technical support for Coalition’s security products via ticketing system and scheduled calls. - Become a Subject Matter Expert on security products and guide users on leveraging product capabilities. - Security Leadership - Participate in the Claims Feedback Loop (CFL) process to identify missing domains and recommend improvements. - Participate in Zero Day Alert Outreach activities to notify policyholders about emerging threats. - Assess and interpret scanning and security finding data for organizations of all sizes. - Identify deficiencies in external scanning data and recommend improvements. - Process, Product, Communication, Leadership, and Culture - Create, maintain, and enhance team documentation, runbooks, and knowledge bases. - Lead team initiatives and projects related to toolset enhancement and process changes. - Represent Coalition as an expert to policyholder security leaders. - Mentor peers and contribute to team and department goals. Qualifications - 4+ years of hands-on security analysis, security engineering, incident response, or related experience. - Demonstrated understanding of the lifecycle of network threats and attack vectors. - Proven ability to assess and quantify security risk for complex organizations. - Experience advising technical stakeholders and tailoring recommendations. - Experience with security support tooling (e.g., vulnerability scanners, SIEM). - Strong interpersonal communication skills, both verbal and written. - Self-motivated and comfortable working in a fast-paced environment. - Bachelor’s degree in Computer Science, Information Security, Engineering, or related field. Bonus Points - Experience with offensive and assessment tools such as Nmap, Nessus, and Metasploit. - Experience securing cloud-based platforms (AWS, Azure, GCP). - Programming or scripting experience (e.g., Python, Go, Bash). - Experience with SCADA / industrial control systems (ICS) networks. - Prior experience in cyber insurance or security consulting for insurers. Compensation As a remote-first organization, our compensation reflects the cost of labor across several Canadian geographic markets. - In Alberta, British Columbia & Ontario: $118,600/year up to $150,000/year. - For all other locations: $106,700/year up to $133,425/year. Perks - 100% medical, dental, and vision coverage. - Flexible PTO. - Annual home office stipend and WeWork access. - Mental & physical health wellness programs. - Competitive compensation and opportunity for advancement.

Canada
C$106.7K - C$150K / year
OpenAI logo

Senior Technical Program Manager – Security

OpenAI

Creating safe AGI that benefits all of humanity.

Full TimeRemoteTeam 201-500Since 2015H1B Sponsor

• Drive execution of critical security and compliance programs such as vulnerability management, merger and acquisition security and integration, infrastructure hardening, and datacenter security management • Partner with IT, Infrastructure, Application, Legal, Privacy, and Security teams to build scalable programs, and deliver critical security outcomes across multiple disciplines • Establish scalable frameworks and build programs around critical security initiatives including vulnerability management, evidence collection, incident response coordination, supply chain risk management, and device security • Track and enforce OpenAI’s privacy and security requirements by translating commitments into engineering milestones and driving their full implementation across systems • Create and maintain program-level visibility across risk areas, security milestones, and cross-org dependencies

California + 3 moreAll locations: California | District Of Columbia | New York | Washington
$165.4K - $285K / year