Information Security Officer

Infovisa, Inc.

United States

Sur place

USD 120 000 - 180 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Résumé du poste

Infovisa, Inc. is seeking an Information Security Officer to own the security program, set policies, and lead security operations across Check Point, CrowdStrike, Sophos, and Entra ID. The role requires 10 years of information security and 3 years of management, with GLBA and SOC 2 oversight.

Hybrid office options in NC or NE; on-site responsibilities and after-hours coverage. Based in Cornelius, NC or Lincoln, NE, the IS Officer will report to the COO and collaborate with IT and management to

Qualifications

  • 10 years of information security experience required.
  • Three years of management experience.
  • Hands-on expertise across firewalls and network security, SIEM, EDR, vulnerability management, and AWS security.
  • Working knowledge of GLBA and SOC 2; support audits/reg examinations.

Responsabilités

  • Own and execute the information security program, including strategy and policies.
  • Report security risk and remediation to executive management.
  • Operate enterprise security monitoring and log management.
  • Manage endpoint detection and response and malware protection.
  • Own vulnerability management lifecycle and patching standards.
  • Define firewall change policy and security configurations.
  • Set identity and access-management standards and conduct access reviews.
  • Lead security incident response and post-incident reviews.
  • Develop and enforce security policies; coordinate SOC 2 readiness.
  • Participate in audits, third-party scans, and regulatory examinations.
  • Conduct vendor security reviews and manage vendor relationships.
  • Oversee awareness training and security team leadership.
  • Engage with industry groups and assist with budget and on-call duties.

Connaissances

Firewalls
Network security
SIEM
EDR
Vulnerability management
AWS security
Policy writing
Documentation
Check Point
Driver's license
Entra ID
CrowdStrike
Sophos

Formation

Four-year degree in information technology / systems, or computer and information science or equivalent experience

Outils

Check Point
CrowdStrike
Sophos
Entra ID

Description du poste

Position Title: Information Security Officer

Department: Information Security

Reports To: Chief Operating Officer

Hours: 8:00 – 5:00, ET (core)

Location: Cornelius, North Carolina or Lincoln, Nebraska

Compensation: Salary + Bonus

Position Summary

The Information Security (IS) Officer owns Infovisa’s information security program including designing, implementing, and monitoring the controls that protect the enterprise while enabling the business to operate and thrive. As the company’s designated security leader, this person is accountable not only for identifying risk but for closing it. Working closely with company management and the IT team, the IS Officer sets security standards and policy, personally operates the company’s core security tooling, and provides independent oversight of the security-related work carried out by IT.

The role operates under GLBA and SOC 2 obligations and has primary responsibility for the company’s information security program.

The person in this position works across the following areas and technologies: Network Security; Enterprise Firewalls (Check Point, Check Point Harmony VPN); AWS cloud security; Endpoint Detection and Response (CrowdStrike); Security Information and Event Management (Sophos); Vulnerability Management; Identity and Access Management (Entra ID); Windows Server, Hyper-V, and IIS; TLS certificate management and PKI; DNS; and the application infrastructure of the enterprise network.

Essential Functions
  • Program ownership: own the information security program including strategy, policies, standards, and their day-to-day execution; accountable for closing findings.
  • Executive reporting: serve as the company’s designated security owner under GLBA; report the state of security risk and remediation directly to executive management in terms of threat level and associated risk.
  • Security monitoring & detection: operate and maintain the enterprise security monitoring and log-management capability; define data inputs and alerting, monitor for threats, and respond to events.
  • Endpoint & threat protection: manage endpoint detection and response and related malware protection across the environment.
  • Vulnerability, patch & hardening: own the vulnerability management lifecycle from identification through verified remediation, and set patch-management and system-hardening standards for servers and databases, monitoring compliance.
  • Firewall policy & oversight: define and maintain the firewall change policy and security configuration standards; oversee execution through formal change control; review higher-risk and datacenter firewall changes prior to implementation.
  • Identity & access: set identity and access-management standards and own periodic access reviews, including timely removal of access for separated associates.
  • Incident response: lead security incident response through detection, containment, remediation, and post-incident review.
  • Policy, documentation & compliance: develop, maintain, and enforce security policies and procedures; own the written information security program required under GLBA and the control evidence required for SOC 2; coordinate SOC 2 readiness and act as the primary internal owner for security control evidence.
  • Audits, examinations & testing: participate in external audits, third-party vulnerability scans and penetration tests, and regulatory examinations including gathering artifacts and attending interviews.
  • Vendor risk: conduct third-party/vendor security reviews and manage security vendor relationships.
  • Awareness training: manage cybersecurity awareness training for all associates.
  • Team leadership: hire, train, mentor, and manage associate(s) on the security team; provide security direction to IT staff who execute security-related changes.
  • Industry engagement: act as liaison to FS-ISAC / IT-ISAC, InfraGard, and other industry groups; share information as appropriate.
  • Budget: assist in developing the annual security budget and tracking expenses.
  • Availability: participate in an after-hours on-call rotation and work evenings and weekends as needed to support security operations, incident response, and change windows.
  • Maintain up-to-date knowledge of applicable technologies and equipment; assist with escalated support when necessary.
  • Understand and adhere to all company policies, laws, and regulations applicable to the role; report compliance issues in accordance with company policy.
  • Perform other job-related duties or special projects as assigned.
Qualifications
  • 10 years of information security experience required.
  • Three years of management experience.
  • Hands-on expertise across firewalls and network security (Check Point preferred), SIEM operations, EDR, vulnerability management, and AWS security.
  • Working knowledge of GLBA (Safeguards Rule) and SOC 2 control frameworks; demonstrated experience supporting audits and regulatory examinations.
  • Strong policy and procedure-writing skills and a track record of detailed technical documentation.
  • Valid driver’s license.
  • Four-year degree in information technology / systems, or computer and information science or equivalent experience.
  • Preferred: Check Point certification and one or more applicable security certifications (e.g., CISSP, CISM, or equivalent).
Preferred Talents
  • Analytical and detailed.
  • Effective communicator, including with executive leadership and in the board room.
  • Organized.
  • Independent with good judgment.
  • Proven ability to multitask and prioritize projects.
  • Self-directed and takes initiative.
Working Environment
  • Participates in an after-hours on-call rotation; evening and weekend work is required as needed.
  • Mostly indoor work with occasional exposure to outdoor elements or hazards.
  • Medium workload; lifting and/or carrying up to 20 pounds frequently and exerting up to 75 pounds of force occasionally.
  • Some travel required.

This is an in-office position in Cornelius, NC or Lincoln, NE. Successful candidates will live within commuting distance of one of these offices or be willing to relocate.

About Infovisa

Infovisa is a leading provider of financial technology solutions delivered to forward-thinking trust, wealth management, and retirement professionals. Infovisa’s solutions empower its clients to acquire new customers, invest assets effectively, manage trust and investment portfolios efficiently, and flexibly report results to customers. For more information about Infovisa, visit www.infovisa.com. Follow us on LinkedIn.

We are interested in every qualified candidate who is lawfully eligible to work in the United States.

We are unable to sponsor visas.

Infovisa, Inc. is an Equal Opportunity Employer.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Information Security Officer
Information Security Officer

Infovisa, Inc. • Cornelius (NC), Lincoln (NE)

Sur place
USD 120 000 - 180 000
Information Security Manager
Information Security Manager

Infovisa, Inc. • Cornelius (NC)

Sur place
USD 100 000 - 130 000
Senior Information Security Leader
Senior Information Security Leader

Infovisa, Inc. • Cornelius (NC), Lincoln (NE)

Sur place
USD 120 000 - 180 000
Vice President, Information Security
Vice President, Information Security

O'Neil Digital Solutions, LLC • Los Angeles (CA), Northern (KY)

Hybride
USD 180 000 - 280 000
Vice President, Information Security
Vice President, Information Security

O'Neil Digital Solutions, LLC • Monroe (NC)

Sur place
USD 180 000 - 280 000
Information Security Program Lead
Information Security Program Lead

Infovisa, Inc. • États-Unis

Sur place
USD 120 000 - 180 000
AVP, Information Security
AVP, Information Security

Verinext • North Haven (CT)

Sur place
USD 180 000 - 230 000
Retirement Plan (401k, IRA)
Work From Home
Health Care Plan
Chief Information Security Officer
Chief Information Security Officer

NVISO • Belgique (MO)

Sur place
USD 120 000 - 160 000
Flexible working hours
32 days of holidays
Personal coaching
+1
Information Security Analyst
Information Security Analyst

INSPYR • Carson City (NV)

Sur place
USD 69 000 - 76 000
Comprehensive medical benefits
Competitive pay
401(k) retirement plan
Cleared Information System Security Officer L3 - Lorton, VA
Cleared Information System Security Officer L3 - Lorton, VA

VetJobs • Lorton (VA)

Sur place
USD 140 000 - 180 000