Information Security Manager – SecOps

Bright Defense, LLC.

United States

Remote

USD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive base salary
Remote-first with flexible working hours
Certification reimbursement
Broad client exposure across industries

Job summary

A cybersecurity firm is hiring an Information Security Manager for a remote position. You will oversee client security programs, ensuring compliance with frameworks like ISO 27001 and SOC 2. The ideal candidate has 3-6 years in the field and strong skills in risk management and written communication. The role includes portfolio management, reporting, and collaboration across teams. This position offers a competitive salary, flexible hours, and opportunities for professional growth.

Qualifications

  • 3-6 years in information security or compliance roles is required.
  • Hands-on experience with SOC 2, ISO 27001, and NIST CSF.
  • Exceptional written communication skills for client-facing interactions.

Responsibilities

  • Manage a portfolio of customer security programs.
  • Lead ongoing assessments of security controls, ensuring compliance.
  • Prepare reports and updates for clients with actionable insights.

Skills

Information Security
Compliance Management
Risk Assessment
Written Communication

Education

Relevant certification (CISA, CISM, CISSP, or CRISC)

Tools

GRC platforms (Drata, Vanta, Thoropass)
Asana or similar project management tools
Google Workspace or Microsoft 365

Job description

Bright Defense · SecOps Team · Now Hiring

Information Security Manager

SecOps — Continuous Monitoring & Client Risk Management

Full-Time • Remote • SecOps • Compliance & Risk Focus

You’ll be the person clients trust to keep their security program on track between audits. This role lives at the intersection of technical rigor and clear communication — translating control monitoring, risk findings, and compliance gaps into actionable guidance that customers can act on.

About the role

As an Information Security Manager on the Bright Defense SecOps Team, you’ll manage a portfolio of customer security programs through asynchronous collaboration, lead continuous control monitoring, assess maturity, and develop risk management strategies that strengthen client security postures. You’ll work closely with Security Consultants, Offensive Security, and other SecOps functions — and serve as the primary written voice keeping customers informed on findings, progress, and next steps.

Key responsibilities
Portfolio management
  • Manage a portfolio of customer security programs with continuous oversight via async channels
  • Serve as the primary point of accountability for program health, milestone tracking, and escalation
  • Coordinate with assigned Security Consultants to align monitoring with each client’s overall strategy
  • Participate in internal syncs and contribute to broader SecOps objectives
Control monitoring & risk
  • Lead ongoing assessments of security controls against ISO 27001, SOC 2, NIST CSF, and other applicable frameworks
  • Monitor and evaluate control effectiveness, maturity levels, and residual risk exposure
  • Identify, track, and support remediation of control weaknesses and compliance gaps
  • Maintain current records of risk assessments, audit findings, and corrective action plans
Audit & compliance readiness
  • Review evidence and documentation to validate compliance posture across multiple frameworks
  • Support audit readiness for SOC 2, HIPAA, ISO 27001, PCI DSS, CMMC, and related engagements
  • Perform Third Party Risk Management assessments for new and existing vendors
  • Respond to security questionnaires on behalf of clients within a 5-business‑day SLA
Reporting & communication
  • Prepare accurate, professional, and actionable written reports and customer updates
  • Deliver data‑driven insights and recommendations with clarity and specificity
  • Ensure transparency across all customer‑facing communications regarding monitoring, findings, and remediation status
  • Continuously improve reporting standards, evidence management, and monitoring methodologies
Cross‑functional collaboration
  • Security Consulting
  • Offensive Security
  • SecOps Functions
  • Client Stakeholders
What we’re looking for
Security & compliance (required)
  • 3–6 years in information security, GRC, or compliance‑adjacent roles
  • Hands‑on experience with SOC 2, ISO 27001, NIST CSF, HIPAA, PCI DSS, or CMMC
  • Demonstrated ability to assess control effectiveness and document residual risk
  • Experience conducting or supporting security audits and evidence reviews
Risk management
  • Practical experience building or maintaining risk registers and treatment plans
    Communication & async work
    • Exceptional written communication — client‑facing reports, findings summaries, executive updates
    • Comfortable managing multiple engagements through async channels (Slack, email, project tools)
    • Able to communicate technical findings clearly to non‑technical stakeholders
    Tools & platforms
    • GRC platforms — Drata, Vanta, Thoropass, or equivalent
    • Asana or similar PM tools for task and program tracking
    • SafeBase or equivalent for security questionnaire management
    • Google Workspace or Microsoft 365 proficiency
    Nice to have
    • CISA, CISM, CISSP, or CRISC certification
    • MSSP or consulting firm background
    • Experience supporting CMMC Level 2 or ITAR‑adjacent programs
    • Familiarity with NYDFS 23 NYCRR Part 500 or other state‑level frameworks
    • Exposure to cloud security environments (AWS, Azure, GCP)
    • Background in healthcare, defense, or fintech regulated industries
    Performance benchmarks
    • 5 days SLA for security questionnaire responses
    • Monthly written updates delivered to every active client
    • 0 gaps untracked audit findings at any point in time
    • Current risk registers and corrective action logs maintained
    • Aligned control monitoring mapped to each client’s framework scope
    • 100% TPRM assessments completed before vendor onboarding
    Compensation & perks
    • Competitive base salary — range shared during screening
    • Remote‑first with flexible working hours
    • Certification reimbursement (CISA, CISM, CISSP, CRISC, and others)
    • Direct collaboration with Bright Defense co‑founders
    • Broad client exposure across defense, healthcare, and fintech verticals
    • Clear growth path toward Senior ISM or vCISO functions

    Bright Defense is an equal opportunity employer. We build diverse, high‑trust teams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Confidential • Pittsburgh

Hybrid
USD 140,000 - 190,000
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Information Security Engineer (CISO track)
Information Security Engineer (CISO track)

Tangible • United States

Remote
GBP 90,000 - 150,000
Ownership of security program
Fully remote
Learning budget
+1
Information Security Manager
Information Security Manager

eNGINE • Pittsburgh

Hybrid
USD 120,000 - 160,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000