The Information Security Manager is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. The Manager will lead the Information Security function, working closely with other senior executives, IT team members, and external stakeholders to manage and mitigate security risks.
Key Responsibilities:
Strategy & Planning:
• Establish security policies, procedures, and standards to protect company assets.
• Lead risk assessment and management processes, including threat modeling and vulnerability assessments.
• Develop and implement a comprehensive information security strategy and program.
Leadership & Management:
• Manage a high- performing information security function
• Provide guidance and mentorship to IT members
• Coordinate with other departments to ensure alignment with security policies and objectives.
Compliance & Governance:
• Conduct regular audits and assessments to ensure ongoing compliance.
• Ensure compliance with relevant laws, regulations, and industry standards (e.g., GDPR, HIPAA, PCI- DSS).
• Oversee the development and implementation of information security policies and procedures.
Incident Response & Management:
• Develop and oversee incident response planning and execution.
• Lead the response to security breaches and incidents, including forensic analysis and remediation.
• Communicate with relevant stakeholders during incidents, including executive management and, when necessary, external parties.
Education & Awareness:
• Develop and deliver training programs to educate employees on security best practices and policies.
• Promote security awareness across the organization.
Technical Oversight:
• Oversee the implementation and management of security technologies and solutions (e.g., firewalls, intrusion detection/prevention systems, endpoint protection).
• Stay abreast of the latest security technologies, threats, and trends.
Vendor Management:
• Assess and select security vendors to ensure they meet the company‘s security requirements.
• Oversee vendor performance and ensure compliance with contractual obligations.
• Negotiate contracts and service level agreements to maximize value and security benefits.
• Manage relationships with external vendors and service providers.
Qualifications:
Education & Certifications:
• Relevant certifications such as CISSP, CISM, CISA, or equivalent.
• Bachelor’s degree in Computer Science, Information Security, or a related field.
Experience:
• Demonstrated success in developing and implementing security strategies and programs.
• Proven experience in a senior leadership role
• 7+ years of experience in information security roles.
Skills & Competencies:
• Strong understanding of current threat landscape and security technologies.
• Excellent leadership, communication, and interpersonal skills.
• Strong problem- solving and decision- making skills.
• In- depth knowledge of information security management frameworks (e.g., ISO/IEC 27001, NIST).
• Ability to work under pressure and manage multiple priorities.