Information Security Manager

Ecotal

Durham (NC)

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ecotal is seeking an Information Security Manager to lead security operations and compliance programs across the organization. This hands-on senior role requires deep technical expertise and the ability to drive a NIST-aligned program while partnering with IT, Legal, HR, and business stakeholders.

You will own endpoint protection with Microsoft Defender, manage Zscaler, govern SIEM, oversee vulnerability and patch programs, and advance AI governance policies as the security function scales.

Qualifications

  • 5+ years of progressive experience in information security with expertise in security operations.
  • Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, and Cloud).
  • Production experience managing Zscaler (ZIA and/or ZPA), including policy administration and troubleshooting.
  • Strong SIEM experience, including detection development, alert tuning, incident investigation, and log source integration.
  • Experience managing vulnerability programs across AWS and Azure cloud environments.
  • Working knowledge of digital forensics and incident response methodologies.

Responsibilities

  • Administer and optimize Microsoft Defender across the endpoint environment, including policy configuration, alert triage, incident response, and reporting.
  • Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems
  • Own SIEM administration, detection engineering, log source onboarding, alerting, incident workflows, dashboards, and operational metrics
  • Lead vulnerability scanning efforts across AWS, Azure, and on-premises environments. Prioritize, track, and validate remediation activities in partnership with IT and engineering teams
  • Maintain endpoint patching programs, reporting, exception tracking, and service-level compliance
  • Investigate security events, perform forensic analysis, document findings, and coordinate response activities with internal and external stakeholders

Skills

Security operations
Endpoint security
Network security
SIEM
Vulnerability management
Patch management
Digital forensics
Incident response
Policy development
AI governance
Security awareness
Vendor risk management

Education

Bachelor's degree in Computer Science / Information Systems / Cybersecurity

Tools

Microsoft Defender
Zscaler (ZIA/ZPA)
SIEM tooling
AWS
Azure
On-premises systems

Job description

We are seeking an Information Security Manager to lead security operations and compliance programs across the organization. This is a hands-on individual contributor role designed for a senior technical security professional ready to take ownership of a comprehensive security program, with the opportunity to grow into a leadership position as the function scales. The successful candidate will bring a balance of deep technical expertise and program-level compliance experience. This role will own day-to-day security tooling, lead a NIST-aligned compliance program, develop policies in emerging technology areas including artificial intelligence, and maintain visibility into systems and assets across the environment. The position reports directly to executive leadership and partners closely with IT, Legal, HR, and business stakeholders

Responsibilities
  • Security Operations & Engineering Endpoint Security: Administer and optimize Microsoft Defender across the endpoint environment, including policy configuration, alert triage, incident response, and reporting.
  • Network and Access Security: Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems
  • SIEM Operations: Own SIEM administration, detection engineering, log source onboarding, alerting, incident workflows, dashboards, and operational metrics
  • Vulnerability Management: Lead vulnerability scanning efforts across AWS, Azure, and on-premises environments. Prioritize, track, and validate remediation activities in partnership with IT and engineering teams
  • Patch Management: Maintain endpoint patching programs, reporting, exception tracking, and service-level compliance
  • Digital Forensics & Incident Response: Investigate security events, perform forensic analysis, document findings, and coordinate response activities with internal and external stakeholders
Compliance & Governance:
  • NIST-Based Security Program: Maintain and continuously improve a security program aligned with the NIST Cybersecurity Framework, including controls mapping, evidence collection, gap analysis, and remediation tracking.
  • Policy Management: Own the security policy library, ensuring policies and standards are current, reviewed regularly, approved appropriately, and effectively communicated.
  • AI Governance: Develop and maintain policies governing AI usage, acceptable use standards, and evaluation processes for new AI technologies in coordination with Legal and IT teams
  • System Inventory Management: Build and maintain an authoritative inventory of systems, applications, data flows, and ownership records
  • Audit & Assessment Support: Lead responses to internal and external audits, customer security reviews, and regulatory assessments. Manage remediation efforts through closure
  • Risk Management: Identify, document, assess, and track information security risks while providing mitigation recommendations and reporting residual risk to leadership
Leadership & Cross-Functional Partnership:
  • Stakeholder Engagement: Partner with IT, Legal, HR, and business leaders to provide practical security guidance that balances risk management with business objectives
  • Security Awareness: Lead security awareness initiatives, including phishing simulations, training programs, and ongoing employee communications
  • Vendor & Third-Party Risk Management: Assess and manage security risks associated with vendors, contractors, and third-party service providers.
  • Future Team Leadership: Establish the foundation for a scalable security organization and, as the function grows, recruit, mentor, and lead security professionals.
Required Education & Experience:
  • Demonstrated use of AI technologies to enhance and scale security operations, with an AI-first mindset for Security Operations.
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
  • 5+ years of progressive experience in information security with expertise in security operations, engineering.
  • Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, and Cloud).
  • Production experience managing Zscaler (ZIA and/or ZPA), including policy administration and troubleshooting.
  • Strong SIEM experience, including detection development, alert tuning, incident investigation, and log source integration.
  • Experience managing vulnerability programs across AWS and Azure cloud environments.
  • Working knowledge of digital forensics and incident response methodologies.
  • Experience operating security programs aligned with the NIST Cybersecurity Framework and/or NIST 800-53.
  • Proven ability to write, maintain, and operationalize security policies and standards.
  • Excellent written and verbal communication skills, including the ability to explain technical risks to non-technical audiences.
  • Ability to work in a hybrid environment with regular in-office presence.
Preferred Qualifications:
  • Industry certifications such as CISSP, CISM, GCIH, GCFA, GCIA, or equivalent.
  • Experience in highly regulated environments or critical infrastructure sectors.
  • Familiarity with industry regulatory frameworks and compliance requirements.
  • Experience scripting or automating security workflows using Python, PowerShell, KQL, or similar technologies.
  • Prior experience serving as a senior technical lead preparing to transition into a management role.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Program Lead
Senior Security Program Lead

GlobalSource IT • Columbia (SC)

On-site
USD 90,000 - 120,000
Competitive compensation
Professional growth opportunities
Collaborative team environment
+1
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior IT Security Manager
Senior IT Security Manager

GoFormz • San Diego (CA)

On-site
USD 140,000 - 190,000
Information Security Engineer (Data Security)
Information Security Engineer (Data Security)

Zscaler • Town of Texas (WI)

Hybrid
USD 137,000 - 196,000
Health plans
Parental leave options
Retirement options
+2
Security Engineer
Security Engineer

CRICO • Boston (MA)

On-site
USD 90,000 - 130,000
Manager of Security
Manager of Security

Centerfield • United States

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Sentrilock • West Chester Township (OH)

On-site
USD 110,000 - 150,000
Security Engineer
Security Engineer

SentriLock • Olde West Chester (OH)

On-site
USD 110,000 - 160,000
Senior Security & Infrastructure Engineer
Senior Security & Infrastructure Engineer

Zentalis Pharmaceuticals • San Diego (CA)

On-site
USD 150,000 - 210,000