Manager, Information Security

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $150k - $180k / year

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 2%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Synack, Inc.

Synack, Inc.

201 - 500 employees

🔒 Cybersecurity

📋 Compliance

☁️ SaaS

Cybersecurity • Compliance • SaaS

Synack, Inc. is the premier security testing platform harnessing a vetted community of the world’s most talented security researchers to deliver continuous penetration testing and vulnerability management. The company helps customers build and augment their security testing capabilities and capacity to deliver transformational results that surpass traditional pentesting methods. Synack is committed to reducing cybersecurity risk for its customers by bridging the cybersecurity talent gap and providing on-demand access to a trusted network of researchers in a secure environment, all on one platform.

📋 Description

• Automate generation of System Security Plans (SSP), including Security Concept of Operations, Risk Management Matrix, Security Control Traceability Matrix, and conduct Security Impact Analysis (SIA) on major system changes • Develop and maintain automated Plans of Action and Milestones (POAMs) • Contribute to automation and use of Artificial Intelligence (AI) within Synack’s Information Security operations • Own inventory and risk assessments of AI/agentic systems aligned to NIST AI RMF and ISO 42001, including data handling, model and agent change control, non-human identity, and credential scoping • Build and own automated evidence collection and control-drift monitoring for security controls • Communicate with stakeholders on security compliance issues aligned to CIS and NIST standards; track mitigation/remediation tasks and assist with reports and metrics • Codify security controls into IaC guardrails, CNAPP policies, and CI/CD checks to prevent risks at commit and deploy time • Work with Project Managers and Software Engineers to incorporate information security policies, standards, procedures, and guidelines across hosted services and infrastructure, focusing on hardening and DevSecOps principles • Coordinate with field teams on vendor security assessments and conduct third-party risk assessments of Synack vendors • Ensure Synack’s security and privacy posture is maintained

🎯 Requirements

• 8+ years of experience in IT Security Strategy, Risk Management, IT Audit and Compliance with a Cloud Service Provider • Experience with Python, Terraform, and CI/CD pipelines • Comfort integrating tools with AI • Experience with Enterprise Governance, Risk Management, and Compliance (GRC) tools • Experience with event monitoring and alerting tools such as Datadog, Stackdriver, and Azure Sentinel • Experience with SOAR or auto-remediation platforms and detection engineering / SIEM query languages • Experience with Cloud Native Application Protection Platforms (CNAPP) • Experience leveraging security tools within the Software Development Lifecycle (SDLC) • Familiarity with secrets management and workload identity (non-human) • Working knowledge of ISO27000, ISO42001, OWASP, SOC2, GDPR, CMMC, FedRAMP, and NIST • Excellent written and verbal communication skills for technical and non-technical audiences • Must be a citizen of the United States due to federal government contract requirements

🏖️ Benefits

• Equity may be included in the compensation package • Benefits package available; see Synack’s benefits overview • Inclusive and diverse workplace

Apply Now

Similar Jobs

🔥 17 minutes ago

Ferguson

10,000+ employees

🏗️ Construction

🏭 Manufacturing

📦 Logistics

Senior manager leading enterprise security engineering for Ferguson, a major industrial and building-supplies distributor. Driving vulnerability management, DevSecOps, cloud security, and risk remediation.

🔥 1 hour ago

Danaher

10,000+ employees

🧬 Biotechnology

🏥 Healthcare

🔬 Science

Global security director protecting Beckman Coulter Diagnostics’ people, facilities, and operations. Leading enterprise risk, crisis management, executive protection, and travel security programs.

🔥 1 hour ago

Dragonfli Group

11 - 50

🔒 Cybersecurity

💼 Consulting

Endpoint Security Engineer engineering EDR/XDR protection for Dragonfli Group’s federal-agency clients. Securing massive endpoint, server, virtualization, and multi-cloud environments.

🔥 1 hour ago

DoorDash

10,000+ employees

🍽️ Food & Beverage

📦 Logistics

🛍️ eCommerce

Corporate Counsel advising DoorDash’s delivery marketplace on cybersecurity incidents, investigations, and enforcement. Developing legal strategies to disrupt cybercrime and protect customers, merchants, and partners.

🔥 2 hours ago

PartsBase Inc.

51 - 200

📦 Logistics

🏭 Manufacturing

🎖️ Defense

Senior AI Security Engineer securing PartsBase's global aviation marketplace, cloud infrastructure, and applications. Building AI-driven threat detection and remediation automations.

🗣️🇪🇸 Spanish Required