Information Security Policy Manager

Solomon Page

Greenwich (CT)

On-site

USD 200,000 - 250,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Solomon Page is seeking an Information Security Policy Manager to develop, maintain, and communicate policies aligned to regulatory requirements, industry best practices, and risk appetite. This role owns the policy library and ensures the security program is supported by solid policy mandates.

The ideal candidate has 7+ years in information security, with 3+ years drafting and managing policies in regulated environments (financial services preferred), strong regulatory knowledge (DORA, FFIEC,

Qualifications

  • 7+ years of information/cyber security, including policy development in regulated environments.
  • Strong regulatory knowledge across DORA, FFIEC, NIST CSF, and ISO 27001/27002.
  • Experience owning policies or technical standards documentation.
  • Experience leading responses to regulatory examinations and audits.

Responsibilities

  • Maintain and extend information security policy library to align with regulation and risk.
  • Coordinate development, review, and update of policies and standards with defined maintenance intervals.
  • Map policies to risk and regulatory frameworks and identify gaps.
  • Support audits and client due diligence by providing evidence of compliance.
  • Partner with Controls Manager to ensure policies are supported by controls and testing.

Skills

Policy development
Regulatory compliance
NIST CSF
ISO 27001/27002
Policy ownership
Audit responses
Cross-functional collaboration
CISM

Education

Bachelor's degree in Information Security / IT / CS or related field

Tools

GRC tooling

Job description

Our client is looking to fill the role of Information Security Policy Manager. The Information Security Policy Manager develops, maintains, and communicates information security policies aligned to regulatory requirements, industry best practices, and control environment and risk appetite. This role is responsible for formal information security policy library, ensuring security program is supported by well-considered policy mandates.

  • The Base Salary range is $200k to $250k
Responsibilities:
  • Maintain and extend information security policy library to align with regulatory requirements, business risk appetite, industry-accepted risk frameworks, and control environment.
  • Coordinate and drive the development, review, and update of information security policies and standards based on identified need and defined maintenance intervals.
  • Map security policies to, and analyze gaps against, applicable risk and regulatory frameworks and laws, such as DORA, FFIEC, NIST CSF.
  • Support security-related external assessments, audits, and regulatory examinations by providing evidence of compliance.
  • Partner with the Information Security Controls Manager to ensure policies are supported by appropriate controls and testing procedures.
  • Evaluate security controls, identify opportunities for improvement, and communicate constructive recommendations.
  • Other duties, as assigned
Required skills:
  • 7+ years of experience in information / cyber security experience, including 3+ years developing and managing information security policies in a regulated industry (preferably financial services) and 3+ years hands-on, technical cybersecurity roles.
  • Fluent understanding of regulatory requirements affecting cybersecurity, including DORA, SEC, FFIEC, and common regulations issued in Europe (EBA) and APAC (SFC, MAS).
  • Working familiarity with common security frameworks, including NIST CSF and ISO 27001/27002.
  • Prior experience as owner of policies or technical standards documentation.
  • Experience as lead responder to regulatory examinations, audit requests, and client due diligence questionnaires related to policy and compliance.
  • Proven ability to write clear, actionable policies addressing complex regulatory and technical requirements, grounded in industry accepted practices and risk management concepts, and based on existing controls and technology environments
  • Experience working with GRC (Governance, Risk, and Compliance) tooling a plus.
  • Experience building cross functional consensus as an individual contributor
  • Bachelor’s degree in Information Security, Computer Science, Information Technology or a related field, or equivalent experience
  • CISM certification a plus.
To be successful:
  • Strong critical thinking, analytical, organizational, time management, and writing and editing skills – all with attention to detail.
  • Track record of building bridges with technology practitioners and translating complex technical concepts into simple, accessible language for business audiences.
  • A self-motivated, open, collaborative, client-centric, consensus-building problem-solving mentality
  • Ability to exercise good judgment when solving problems with incomplete information
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Arco Solutions • Kansas

On-site
USD 120,000 - 150,000
Flexible schedule
Health insurance
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Information Security Manager
Information Security Manager

Confidential • Pittsburgh

Hybrid
USD 140,000 - 190,000
Technical Security Manager
Technical Security Manager

Cambium Learning Group • United States

On-site
USD 120,000 - 180,000
Manager of Information Technology
Manager of Information Technology

Confidential • Pittsburgh

Hybrid
USD 150,000 - 190,000
Information Security Risk Compliance Manager
Information Security Risk Compliance Manager

Govserviceshub • New York (NY)

On-site
USD 90,000 - 120,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Information Security Manager
Information Security Manager

blueStone • Downers Grove (IL)

On-site
USD 100,000 - 130,000
Senior Manager, Information Security
Senior Manager, Information Security

Nations Lending Corporation • Kentucky

On-site
USD 120,000 - 190,000
IT Security Manager
IT Security Manager

True North Consulting, LLC • Olathe (KS)

On-site
USD 90,000 - 120,000