Information Security, Risk Manager

🔥 1 minute ago

🤠 Texas – Remote

infoinfo

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Empyrean

Empyrean

501 - 1000 employees

👥 HR Tech

☁️ SaaS

🤝 B2B

💰 $10M Venture Round - Empyrean Benefit Solutions on 2015-04

HR Tech • SaaS • B2B

Empyrean is a technology and services company that provides benefits administration and employee engagement solutions for employers. Its platform and services cover eligibility and enrollment, data exchange and integrations, reporting and analytics, employee communications, administrative services (billing, verifications, consumer accounts), compliance (ACA, COBRA, QMCSO), and workforce engagement through mobile apps, omnichannel communications, decision support, and AI-powered features. Empyrean emphasizes a service-first delivery model, HIPAA/SOC2/ISO27001 security compliance, and partnerships with brokers, carriers, and advisors to support HR teams across industries like healthcare, transportation, retail, and manufacturing. Founded in 2006, Empyrean positions itself as a B2B provider simplifying benefits administration and improving employee experience.

📋 Description

• Lead Empyrean’s ISO 27001 certification, surveillance, internal audit readiness, and ongoing ISMS compliance activities • Coordinate ISO 27001 control testing and communications with control owners, business partners, and audit stakeholders • Support assessments and assurance activities involving SOC 2, NIST AI RMF, NIST CSF, NIST 800-53, HIPAA, and other frameworks • Identify, assess, document, monitor, and communicate information security risks and control gaps • Develop, implement, track, and validate corrective action and risk-remediation plans • Manage audit and assessment activities for information security, cybersecurity, business applications, and technology controls • Lead or coordinate risk assessments for technology initiatives, environmental changes, third parties, emerging technologies, exceptions, and risk events • Facilitate security risk and governance meetings, including preparation, documentation, and follow-up • Maintain the enterprise information security risk register and related risk, issue, exception, and remediation documentation • Provide technical expertise and apply security and compliance practices to identify control weaknesses and address policy exceptions • Lead security and technology responses for client questionnaires, RFPs, due-diligence requests, and internal inquiries • Evaluate enterprise cybersecurity threat and vulnerability monitoring and management effectiveness • Develop and maintain information security policies, standards, and governance documentation • Provide security risk and IT controls expertise on technology initiatives and evaluate control design and implementation • Interpret audit findings, make practical recommendations, and verify remediation implementation • Support broader information security initiatives, incidents, escalations, roadmaps, and strategic projects

🎯 Requirements

• Strong communication, presentation, and organization skills • Strong time-management skills and ability to manage multiple priorities • Ability to work effectively with varied roles and teams • Prior security compliance, risk, or audit experience, particularly with ISO 27001 • Experience with SOC 2, HIPAA, NIST, FedRAMP, or similar frameworks is a plus • Experience preparing work papers, audit reports, and presentations • Working knowledge of information security, technology risk, audit, and control-assurance practices • Strong understanding of ISO 27001, SOC 2/TSC, NIST CSF, NIST 800-53, NIST AI RMF, CIS, COBIT, and related frameworks • Experience with enterprise workflow, ticketing, directory, IT infrastructure, GRC, and security technologies; ServiceNow and Jira beneficial • High level of integrity and confidentiality • 5+ years of experience in information security risk, governance, compliance, technology audit, security engineering, or related areas • Working knowledge of IT and security best practices and frameworks including NIST CSF, SOC 2/TSC, CIS, ISO 27001/ISMS, COBIT, and ITIL • Knowledge of technology risks and experience evaluating cybersecurity, privacy, and engineering controls • Understanding of vulnerability management, security governance, software development, incident response, physical security, logging and monitoring, microsegmentation, SASE, zero trust, insider threat, vendor risk management, PKI, penetration testing, application controls, and segregation of duties • Advanced understanding of internal controls and ability to evaluate control design and operating effectiveness

Apply Now

Similar Jobs

🔥 1 minute ago

Edged

51 - 200

🤝 B2B

⚡ Energy

Cybersecurity Engineer hardening Edged’s infrastructure and networks. Deploying SIEM, IAM, PAM, and Microsoft security solutions while strengthening compliance and resilience.

🔥 2 hours ago

Trail of Bits

51 - 200

🔒 Cybersecurity

☁️ SaaS

₿ Crypto

Senior Security Engineer reviewing cryptographic protocols and implementations at cybersecurity firm Trail of Bits. Leading assessments, tooling, research, and client remediation guidance.

🔥 4 hours ago

Runway

51 - 200

🤖 Artificial Intelligence

☁️ SaaS

📱 Media

Infrastructure Security Engineer securing Runway’s AI model training and serving infrastructure. Building Kubernetes, cloud IAM, supply-chain and research-platform security controls.

🔥 4 hours ago

Ziply Fiber

1001 - 5000

💼 Consulting

📦 Logistics

📡 Telecommunications

IT Security Engineer securing Ziply Fiber’s fiber internet infrastructure with AI-powered detection, automation, and incident response. Managing vulnerabilities, compliance, PKI, and emerging AI security risks.

🇺🇸 United States – Remote

💵 $97.9k - $153.8k / year

💰 Corporate Round on 2022-11

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🔥 5 hours ago

Fortive

10,000+ employees

🏥 Healthcare

🏭 Manufacturing

📦 Logistics

Information Security Engineer supporting incident response, vulnerability management, and security governance at Fluke. Advancing cybersecurity for a global software, test-tools, and technology company.