Global IT Manager, Security & Compliance

Serverfarm

Georgia

Hybrid

USD 135,000 - 145,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Paid time off
Paid holidays
401k
Medical coverage
Dental coverage
Vision coverage

Job summary

Serverfarm is a leading data center company expanding across North America and beyond. This role focuses on compliance, risk, and security operations handling certifications, audits, vulnerability management, and incident response for a broad site portfolio.

As a senior security professional, you will drive governance across ISO 27001, SOC, PCI DSS, and HIPAA, manage vendor risk, and lead investigations with executive visibility while supporting business continuity initiatives.

Qualifications

  • Eight or more years in information security, IT compliance, or IT risk, with meaningful time spent in both compliance and technical security work.
  • Demonstrated ownership of an ISO 27001 program, including direct experience preparing for and defending findings with an external certification body.
  • Hands-on experience with at least two of: SOC 2, PCI DSS, HIPAA, NIS2, or DORA.
  • Genuine technical depth - reading logs, vulnerability scans, OAuth reviews, and remediation discussions.
  • Experience with vulnerability management platforms, EDR tooling, and enterprise identity platforms.
  • Experience leading security incident response through to a customer-facing or executive-facing conclusion.
  • Ability to communicate risk credibly to engineers and executives, and to hold vendors accountable.

Responsibilities

  • Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for ~13 sites.
  • Prepare for audits, present and defend control evidence, and close IT findings.
  • Manage third-party and vendor risk with assessments and a vendor register.
  • Lead customer-facing security due diligence and remediation activities.
  • Maintain IT risk register and drive items to closure.
  • Coordinate IT participation in business continuity and disaster recovery testing.

Skills

Information security
IT compliance
IT risk
ISO 27001 program
Vulnerability management
Incident response
Identity governance
Auditing & reporting

Tools

Vulnerability management platforms
Endpoint detection & response
Enterprise identity platforms

Job description

Serverfarm is a leading developer and operator of data centers with over 750+ locations and key customer relationships in 45 countries. We're revolutionizing how data centers operate across North America, Western Europe, and Israel, serving the world's leading technology and hyperscale companies. With Manulife Investment Management's acquisition in 2023 and our award-winning InCommand platform we're positioned for explosive growth as AI adoption and cloud migration drive unprecedented demand for data center capacity. A career at Serverfarm means being at the forefront of digital infrastructure innovation, where your work directly impacts how the world's data is managed and secured. As we target 4x growth over the next four years, you'll have unprecedented opportunities to take on new challenges, develop cutting-edge skills, and grow your career across our expanding global operations. Join our team of innovators and help shape the future of sustainable data centers while building a career without boundaries.

Key Accountabilities
Compliance and Risk
  • Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for a portfolio of approximately thirteen operating sites.

  • Act as IT's counterpart to external certification bodies and auditors - prepare for audits, present and defend control evidence, and own remediation of IT findings through to closure.

  • Manage third-party and vendor risk management for IT: vendor security assessments, a maintained vendor register with periodic reassessment.

  • Own customer-facing security due diligence - questionnaires, audits and assessments.

  • Maintain the IT risk register and opportunities-for-improvement log, and drive items to closure rather than allowing them to age.

  • Coordinate IT participation in business continuity and disaster recovery testing, and ensure results are documented.

Security Operations
  • Manage vulnerability management end to end - scanning coverage, triage, remediation ownership, escalation of anything aging, and periodic reporting to leadership.

  • Work along side counterparts to oversee endpoint detection and response and the security alerting pipeline; ensure alerts reach an owner and that investigations are recorded and closed.

  • Lead security incident response - containment, investigation, root cause, customer-facing incident reporting, and post-incident hardening.

  • Manage email security, including domain authentication posture and secure email gateway configuration.

  • Run the security awareness program - monthly phishing simulation, results analysis, and targeted follow-up.

Identity and Access
  • Contribute to identity governance across a hybrid estate spanning cloud and on-premises IdP

  • Oversee access review cadence, privileged access controls, and the joiner-mover-leaver process from an IT control standpoint, including third-party and contractor access.

Required Qualifications
  • Eight or more years in information security, IT compliance, or IT risk, with meaningful time spent in both compliance and technical security work.

  • Demonstrated ownership of an ISO 27001 program, including direct experience preparing for and defending findings with an external certification body.

  • Hands-on experience with at least two of: SOC 2, PCI DSS, HIPAA, NIS2, or DORA.

  • Genuine technical depth - you should be comfortable reading firewall and authentication logs, assessing a vulnerability scan, evaluating an OAuth consent request, and challenging an engineer's proposed remediation on its merits.

  • Experience with vulnerability management platforms, endpoint detection and response tooling, and enterprise identity platforms.

  • Experience leading security incident response through to a customer-facing or executive-facing conclusion.

  • Ability to communicate risk credibly to both engineers and executives, and to hold vendors and internal stakeholders accountable without formal authority over them.

  • Willingness to travel to sites periodically for audit, assessment, and control validation.

$135,000 - $145,000 a year

Serverfarm is committed to providing an equal opportunity workplace and offers paid time off, paid holidays, 401k and FULL coverage medical, dental and vision. Our compensation philosophy rewards employees for achieving the values and objectives aligned with the company's goals and strategic initiatives.

The listed salary range for this position is an estimate based on the competitive job market. Final compensation will be based on your own individual skills, experience, and location.

The above statements are intended to describe the general nature and level of work being performed in this role. They are not intended to serve as an exhaustive list of all possible responsibilities and duties.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Center Operations Security Program Manager
Data Center Operations Security Program Manager

Serverfarm • Atlanta (GA)

On-site
USD 110,000 - 160,000
Paid time off
401k
Full coverage medical
+1
Global IT Manager, Data Center IT
Global IT Manager, Data Center IT

Serverfarm • Georgia

Hybrid
USD 130,000 - 140,000
Paid time off
401k
Full coverage medical
Data Center Operations Security Program Manager
Data Center Operations Security Program Manager

Serverfarm • Houston (TX)

On-site
USD 60,000 - 100,000
Paid time off
Paid holidays
401k
+1
IT Support Technician, Corporate IT
IT Support Technician, Corporate IT

Serverfarm LLC • Suwanee (GA), Northern (KY)

Hybrid
USD 71,635,000 - 85,962,000
Paid time off
Paid holidays
401k
+3
Data Center Technician (Critical Facilities) (Sign-on Bonus Offered)
Data Center Technician (Critical Facilities) (Sign-on Bonus Offered)

Serverfarm • Atlanta (GA)

On-site
USD 90,000 - 140,000
Paid time off
401k and health benefits
Data Center Technician Supervisor (Sign-on Bonus Offered)
Data Center Technician Supervisor (Sign-on Bonus Offered)

Serverfarm • Atlanta (GA)

On-site
USD 75,000 - 110,000
Paid time off
401k
Medical, dental, and vision coverage
+1
Data Center Technician
Data Center Technician

Serverfarm • United States

On-site
USD 70,000 - 110,000
401k
Full medical, dental and vision
Paid time off and holidays
Project Manager - Data Centers
Project Manager - Data Centers

Serverfarm • Houston (TX)

On-site
USD 170,000 - 190,000
Paid time off
401k plan
Full coverage medical, dental, and vision
Data Center MEP/HVAC Technician
Data Center MEP/HVAC Technician

Serverfarm • Covington (GA)

On-site
USD 60,000 - 90,000
Paid time off
Paid holidays
401k
+1
Data Center Technician - (Sign-on Bonus Offered)
Data Center Technician - (Sign-on Bonus Offered)

Serverfarm • Atlanta (GA)

On-site
USD 50,000 - 70,000
Paid time off
Paid holidays
401k
+1