Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
iboss is seeking a Manager of Information Security & Compliance to lead security operations and regulatory compliance initiatives. You will manage internal security policies and serve as the primary point of contact for client assessments and audits.
The ideal candidate will have extensive experience in technology with a strong security focus, possess relevant certifications, and be skilled in communication with internal stakeholders. Benefits include health coverage, 401(k) match, and unlimited PTO.
The Manager of Information Security & Compliance is a key leadership role responsible for overseeing security operations and regulatory compliance initiatives. This role requires deep expertise in technology, risk management, and IT security principles, with a strong focus on protecting information systems and data. The Manager will develop and implement security policies and align organizational practices with industry frameworks such as ISO 27001, ISO 9001, SOC 1/2, Cyber Essentials, and FedRAMP to ensure continuous monitoring of security controls and incident response readiness.
In addition to managing internal security policies, the Manager will serve as the primary point of contact for client assessments and external audit engagements, ensuring all compliance obligations are met and supporting key security programs, including contingency planning, configuration management, security awareness, client assurance, and change management.
Maintaining detailed documentation of security events, policy updates, and risk management activities will be essential for driving compliance and operational transparency. A strong ability to communicate complex security concepts through well-structured documentation is critical; the Manager will assist stakeholders in drafting and refining comprehensive policy documents, ensuring they align with regulatory requirements.
The Manager will oversee system audits, leveraging automated tools and established processes to maintain compliance, manage configuration and change control processes, track system modifications, and oversee the Change Management Board. They will also monitor software usage, maintain an accurate inventory of system components, protect the Configuration Management Plan from unauthorized changes, drive security awareness efforts, coordinate third‑party audit engagements, and oversee regulatory reporting for government compliance programs.
The duties and responsibilities described above are essential functions of the job. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a veteran, or an individual with a disability.
*This position is not eligible for sponsorship of work visas.