Manager of Information Security and Compliance

iboss

United States

On-site

USD 100,000 - 130,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
Company-paid holidays

Job summary

iboss is seeking a Manager of Information Security & Compliance to lead security operations and regulatory compliance initiatives. You will manage internal security policies and serve as the primary point of contact for client assessments and audits.

The ideal candidate will have extensive experience in technology with a strong security focus, possess relevant certifications, and be skilled in communication with internal stakeholders. Benefits include health coverage, 401(k) match, and unlimited PTO.

Qualifications

  • 5–10 years’ experience in technology with a security focus.
  • Professional certification such as CISSP, CISA, CISM, or similar preferred.
  • US citizenship required.

Responsibilities

  • Lead the GRC team, ensuring alignment with security objectives.
  • Support internal information security audit activities.
  • Establish and track long-term compliance milestones.
  • Manage long-term compliance obligations independently.
  • Coordinate annual contingency exercises.

Skills

Security focus
Risk management
Compliance knowledge
Communication skills
Analytical abilities

Education

4-year college degree

Tools

ISO 27001
SOC 1/2
FedRAMP

Job description

Manager, Information Security & Compliance

The Manager of Information Security & Compliance is a key leadership role responsible for overseeing security operations and regulatory compliance initiatives. This role requires deep expertise in technology, risk management, and IT security principles, with a strong focus on protecting information systems and data. The Manager will develop and implement security policies and align organizational practices with industry frameworks such as ISO 27001, ISO 9001, SOC 1/2, Cyber Essentials, and FedRAMP to ensure continuous monitoring of security controls and incident response readiness.

In addition to managing internal security policies, the Manager will serve as the primary point of contact for client assessments and external audit engagements, ensuring all compliance obligations are met and supporting key security programs, including contingency planning, configuration management, security awareness, client assurance, and change management.

Maintaining detailed documentation of security events, policy updates, and risk management activities will be essential for driving compliance and operational transparency. A strong ability to communicate complex security concepts through well-structured documentation is critical; the Manager will assist stakeholders in drafting and refining comprehensive policy documents, ensuring they align with regulatory requirements.

The Manager will oversee system audits, leveraging automated tools and established processes to maintain compliance, manage configuration and change control processes, track system modifications, and oversee the Change Management Board. They will also monitor software usage, maintain an accurate inventory of system components, protect the Configuration Management Plan from unauthorized changes, drive security awareness efforts, coordinate third‑party audit engagements, and oversee regulatory reporting for government compliance programs.

Responsibilities
  • Lead the GRC team, ensuring alignment with organizational security and compliance objectives.
  • Support internal information security audit activities and serve as the primary interface with external auditors and third‑party assessors.
  • Collaborate with departmental stakeholders to align policies and procedures with industry security frameworks, including SOC 2, ISO 27001, ISO 9001, FedRAMP, and others.
  • Establish and track long‑term milestones for compliance activities, planning a year or more in advance.
  • Demonstrate strong written communication skills for policy articulation, documentation, and reporting.
  • Maintain detailed records of events, tasks, and timelines during incident response and bridge calls involving multiple teams.
  • Manage long‑term compliance obligations independently, without requiring direct oversight.
  • Oversee and execute security or technology projects as needed, ensuring successful delivery within scope and timeline.
  • Coordinate with technical teams to conduct annual contingency exercises, including disaster recovery tests and business continuity procedures.
  • Apply best practices in risk management to assess, mitigate, and monitor security and compliance risks effectively.
Qualifications
  • 4‑year college degree or related experience.
  • 5–10 years’ experience in technology with a security focus.
  • Network, secure application design, or systems design experience.
  • Professional certification such as CISSP, CISA, CISM, or similar preferred.
  • Professional communicator and comfortable speaking to internal shareholders and executives.
  • Possess a strong work ethic and team‑player mentality.
  • Highly developed sense of integrity.
  • Strong detail orientation and listening skills.
  • Strong decision‑making and analytical abilities.
  • US citizenship.
Benefits
  • Health, Vision, Dental – open to domestic partners.
  • 401(k) with company match.
  • Unlimited Paid Time Off (PTO).
  • Company‑paid holidays.

The duties and responsibilities described above are essential functions of the job. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a veteran, or an individual with a disability.

*This position is not eligible for sponsorship of work visas.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Security and Compliance Manager
Security and Compliance Manager

Morrison Products, Inc. • Cleveland (OH)

On-site
USD 110,000 - 140,000
Manager, Security Compliance
Manager, Security Compliance

CardWorks Servicing LLC • United States

On-site
USD 128,000 - 143,000
Competitive pay
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
+1
Senior Manager, Information Security
Senior Manager, Information Security

Uniting Holding • Houston (TX)

On-site
USD 120,000 - 150,000
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Information Security Compliance Specialist
Information Security Compliance Specialist

Securiport LLC • Reston (VA)

On-site
USD 70,000 - 95,000