Position Summary
Support, develop, and continuously improve Minitab’s global Information Security Management System (ISMS). Contribute to the full lifecycle of the ISO 27001‑certified program, including policy development, risk management, compliance oversight, audit coordination, third‑party risk management, incident response, and business continuity. Partner cross‑functionally to ensure security governance is embedded throughout business operations and aligned with organizational objectives.
Responsibilities
- Lead and maintain the Information Security Management System: Direct and support programs, policies, and daily practices to ensure continued compliance with ISO 27001; maintain alignment with privacy, legal, HR, operational, and reporting obligations; support governance oversight, corrective action planning, and continuous improvement initiatives; contribute to change management efforts, including integration of newly acquired entities.
- Manage risk, compliance, and regulatory alignment: Monitor and interpret relevant cybersecurity laws, regulations, and industry frameworks; perform information security risk assessments and evaluate control environments; develop remediation plans and collaborate with IT, Operations, HR, Legal, Risk Management, and senior leadership to implement corrective actions; maintain documentation to support regulatory and audit requirements.
- Oversee third‑party risk and customer security engagement: Respond to customer security questionnaires and due diligence requests; conduct and manage vendor risk assessments; maintain documentation required for contractual and regulatory compliance.
- Support incident response and business continuity: Participate in business continuity planning activities; support incident response efforts and post‑incident reviews; assess operational impact of cybersecurity incidents and contribute to mitigation and recovery planning.
- Develop security awareness and organizational training: Develop and maintain the company’s security awareness and training program; promote a culture of cybersecurity and privacy awareness across the enterprise.
Qualifications
- 5+ years of experience working with Information Security Management Systems (ISMS), including ISO 27001 or similar frameworks. Big 4 consulting experience highly desired.
- Bachelor’s degree in a related field preferred; equivalent experience will be considered.
- Familiarity with cybersecurity frameworks and Risk Management Framework (RMF).
- Knowledge of cybersecurity and privacy laws, regulations, and compliance standards.
- Experience conducting security risk assessments and developing remediation plans.
- Strong technical writing, analytical, and governance skills.
- Project management experience preferred.
- Relevant certifications such as CISSP, CISM, or equivalent are a plus.
- Fluent in English (read, write, speak).
- Ability to work onsite daily or remotely with regular travel to company offices as required.
- Willingness to travel to State College, PA monthly for onboarding during the first 6 months of employment and as needed thereafter.
Benefits
- Health insurance: Medical, Dental, and Vision insurance provided at no cost for full‑time employees upon date of hire. Low co‑pay pharmacy benefit and affordable family coverage plan available. Short and Long Term Disability fully paid by Minitab. Employee Assistance Program (EAP) provides guidance for personal issues.
- Life insurance: Group Term Life Insurance provided at no cost for full‑time employees at three times employee base salary. Voluntary Life Insurance purchase option at affordable rates.
- Retirement planning: 401(k) plan with T. Rowe Price, with company match up to 6% of employee contribution. Employees fully vested upon date of hire.
- Paid time off: Paid holidays and 4 weeks of annual paid time off. PTO increases one week every five years.
- Professional development: Tuition and related expenses assistance for higher education and other professional development.
- Flexible spending account: Medical and Dependent Care Reimbursement Accounts, Parking and Transit pre‑tax deductions.
- Hybrid work schedule: Hybrid model for eligible positions.
- Premium benefits: Onsite gym, indoor swimming pool, yoga studio, movie theater, outdoor sand volleyball court, game room, arcade room, golf simulator; personal training and nutrition counseling available upon request.
- Salary range: $130K – $140K plus discretionary year‑end performance bonus.
Legal compliance: This position is ineligible for visa sponsorship. To be considered for this role, applicants must be legally authorized to work in the United States and not require sponsorship for employment now or in the future. Qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Job application remains open until filled.