Senior Information Security Leader – ISO 27001 & GRC

PS

El Segundo (CA)

Hybrid

USD 170,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental insurance
Vision insurance
401K with company match
Paid training
Unlimited PTO
Parental benefits
Tuition reimbursement
Discount PS use
Wellness reimbursement
Cell phone reimbursement

Job summary

PS is redefining travel security and luxury, seeking a Senior Manager of Information Security to lead the ISMS and ISO 27001 roadmap for our global terminals. Reporting to the Director of IT, you will mentor the cybersecurity team, drive risk management, audits, and incident response, and partner with Legal, IT, and Operations to enable growth across new locations.

You will establish governance, run regular security assessments, and build a scalable security program to protect sensitive data and

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science or related field.
  • Minimum 7 years of progressively responsible information security experience, including leadership responsibility for security programs, audit readiness, governance, security operations, or certification initiatives.
  • Hands-on experience with ISO 27001 certification processes and audits, including working with certification bodies.
  • Strong understanding of information security governance, audit management, risk treatment methodologies, security operations, ISO 27001 controls, and security compliance frameworks.
  • Proven experience partnering across IT, Legal, HR, Finance, Operations, and other business functions to implement security and risk management requirements.
  • Demonstrated leadership experience managing teams, establishing accountability, influencing cross-functional stakeholders, and driving complex information security programs at enterprise scale.
  • Exceptional client service and communication skills and a demonstrated ability to develop and maintain strong external and internal stakeholder relationships.
  • Demonstrated experience building repeatable, evidence-driven security programs capable of supporting external certification and audit requirements.
  • Proven experience leading internal and external audits, supporting enterprise risk programs, managing certification initiatives, and navigating regulatory and contractual requirements.
  • Strong executive communication and presence, with the ability to translate technical and security risks into clear business decisions for senior leaders, auditors, customers, regulators, and external partners.
  • Industry recognized certification like CISA, CIPP, CISSP, or CRISC, is advantageous.
  • Pass a pre-employment drug screening + background check in accordance with company policy.

Responsibilities

  • Own PS's Information Security Program, ISMS, and ISO 27001 certification roadmap, including readiness assessments, remediation planning, certification activities, surveillance audits, and continuous improvement efforts.
  • Establish and maintain information security policies, standards, procedures, and governance processes aligned with ISO 27001 requirements, contractual obligations, and business needs, partnering with Legal on regulatory and privacy considerations.
  • Lead, develop, and mentor the Cybersecurity Analyst team, establishing clear accountability for security operations, continuous monitoring, logging, incident response, and risk remediation.
  • Lead regular vulnerability assessments of all PS systems including penetration testing, bug bounty and passive scanning programs.
  • Lead operational development, testing, maintenance, and audit readiness activities for backup, incident response, disaster recovery, and business continuity programs in partnership with IT, Operations, and executive leadership.
  • Respond to and manage security incidents and investigations, including coordination of incident response.
  • Conduct regular internal security audits and assessments, including disaster recovery and incident response tabletops.
  • Lead audit readiness activities, including evidence management, remediation tracking, corrective action management, certification activities, customer assessments, and external audits.
  • Establish organization‑wide evidence retention standards and processes to ensure security controls, audits, reviews, incidents, vendor assessments, training, and access management activities are consistently documented and audit‑ready.
  • Promote a strong security culture across the organization through training, awareness, and policy development.
  • Establish and operate a formal access governance program, including user provisioning controls, privileged access oversight, periodic access reviews, and evidence retention.
  • Own the Third‑Party Risk Management (TPRM) program, including vendor classification, security due diligence, remediation tracking, ongoing oversight, and executive reporting of material third‑party risks.
  • Partner with IT, Legal, HR, Finance, Operations, Airport Operations, and other business stakeholders to integrate security and vendor risk requirements into onboarding, contracting, implementations, ongoing vendor management, and business initiatives.
  • Maintain the Information Security Risk Register and provide executive reporting, governance forums, and leadership visibility into security posture, risk treatment, program maturity, and investment priorities.
  • Serve as PS's security leader in cross‑functional and executive discussions, advising on business initiatives, technology investments, new locations, cloud services, payment systems, customer platforms, and regulatory or contractual requirements.
  • Build a scalable security operating model that reduces key‑person dependency, clarifies ownership, and enables the security program to support company growth without increasing risk exposure.
  • Manage the security program roadmap, operating priorities, resource needs, and security investments in coordination with IT leadership and business stakeholders.

Skills

Leadership
Security governance
ISO 27001
Audit readiness
Third-party risk management
Vulnerability assessments
Incident response
Cross-functional collaboration
Regulatory compliance
Communication skills

Education

Bachelor’s degree in Cybersecurity, Information Systems, Computer Science or related field

Tools

ISO 27001 processes

Job description

PS is redefining travel security and luxury, seeking a Senior Manager of Information Security to lead the ISMS and ISO 27001 roadmap for our global terminals. Reporting to the Director of IT, you will mentor the cybersecurity team, drive risk management, audits, and incident response, and partner with Legal, IT, and Operations to enable growth across new locations.

You will establish governance, run regular security assessments, and build a scalable security program to protect sensitive data and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Leader (ISO 27001) — Hybrid
Senior Information Security Leader (ISO 27001) — Hybrid

Socket.dev • El Segundo (CA)

On-site
USD 170,000 - 190,000
Medical, dental, vision
401K with company matching
Unlimited PTO
+3
Senior InfoSec Leader: ISO 27001 & Governance (Hybrid)
Senior InfoSec Leader: ISO 27001 & Governance (Hybrid)

Extime PS LLC • El Segundo (CA)

Hybrid
USD 170,000 - 190,000
Medical, dental, vision
401K with company match
Unlimited PTO
+2
Senior Information Security Manager | ISO 27001 Lead
Senior Information Security Manager | ISO 27001 Lead

The Private Suite Llc • El Segundo (CA)

Hybrid
USD 170,000 - 190,000
Medical, dental, vision
401K with company matching
Unlimited PTO
+2
Head of Information Security & ISO 27001 Program
Head of Information Security & ISO 27001 Program

Reserveps • El Segundo (CA)

Hybrid
USD 170,000 - 190,000
Health insurance
401K matching
Tuition reimbursement
+5
Senior GRC ISMS Security Analyst - ISO 27001 & IAM Lead
Senior GRC ISMS Security Analyst - ISO 27001 & IAM Lead

Dorsey & Whitney LLP • Washington

On-site
USD 114,000 - 148,000
Comprehensive medical insurance
Dental insurance
Vision insurance
+2
Senior GRC & ISMS Security Analyst
Senior GRC & ISMS Security Analyst

Dorsey & Whitney LLP • Salt Lake City (UT)

On-site
USD 120,000 - 180,000
Senior GRC & ISMS Security Analyst
Senior GRC & ISMS Security Analyst

Dorsey & Whitney LLP • Minneapolis (MN)

On-site
USD 120,000 - 180,000
Remote Infosec & GRC Leader - ISO27001 & Risk
Remote Infosec & GRC Leader - ISO27001 & Risk

Avantdigitalnow • San Francisco (CA)

Remote
USD 95,000 - 130,000
Senior GRC & ISMS Security Strategist
Senior GRC & ISMS Security Strategist

Dorsey & Whitney LLP • Palo Alto (CA)

Hybrid
USD 140,000 - 190,000
Senior GRC & Information Security Lead
Senior GRC & Information Security Lead

Dorsey & Whitney LLP • Phoenix (AZ)

On-site
USD 140,000 - 180,000
Health benefits
Paid time off
Parental leave