Search

Information Security Manager

PublishedPublished: 6/14/2022
Technology

Job Description

firstPRO is now accepting resumes for a Manager of Information Security Compliance & Risk. This is a direct hire role and onsite 3 days per week.


The role manages a team of three Information Security Analysts and owns SOC 2 and ISO 27001 certification programs, while partnering closely with Legal, Compliance, Privacy, IT, and Security Engineering and Operations to ensure effective control design, evidence collection, risk management, and continuous improvement.


Responsibilities:


Governance and Compliance Leadership

  • Own and maintain the firm’s information security governance framework, including policies, standards, and procedures.
  • Lead annual SOC 2 and ISO 27001 audit cycles, including audit readiness, evidence coordination, and remediation tracking.
  • Ensure ongoing compliance with client, regulatory, and contractual information security requirements.
  • Manage policy exceptions, risk acceptances, and documentation of compensating controls.

Regulatory Authorization and Assurance

  • Lead the renewal and ongoing maintenance of government and client security authorizations, attestations, and approvals required for regulated engagements.
  • Coordinate cross-functional evidence collection and control validation to support authorization renewals and periodic reassessments.
  • Track authorization requirements, renewal timelines, and control changes to ensure continuous eligibility for regulated work.

Qualifications & Skills

  • Bachelor’s degree required; degree in information security, risk management, or a related field preferred.
  • 7 to 10 years of experience in information security, GRC, audit, or risk management required.
  • Prior experience managing SOC 2 and or ISO 27001 programs required.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...