Senior Information Security Manager

Fortinet

Sunnyvale (CA)

On-site

USD 167,000 - 204,000

Full time

18 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life and disability insurance
401(k)
11 paid holidays
Vacation time
Sick time
Comprehensive leave program

Job summary

Fortinet in Sunnyvale is seeking a Senior Information Security Manager to lead the ISMS program, drive compliance across FedRAMP, GovRAMP, and other frameworks, and coordinate with auditors. The role emphasizes risk governance, cloud security, and incident management while partnering with cross-functional teams to uphold Fortinet’s security posture.

Qualifications

  • 7+ years in information security with leadership experience.
  • SME of NIST SP800-53, ISO/IEC 27000 and SOC2 standards.
  • Experience with FedRAMP or GovRAMP implementations.
  • Knowledge of ISO/IEC 27001, NIST 800-53, GovRAMP, FedRAMP, PCI DSS and related regulations.
  • Strong privacy compliance knowledge (GDPR, CCPA).

Responsibilities

  • Lead ISMS design, implementation, and ongoing improvement.
  • Perform gap analyses against NIST SP800-53 and other frameworks.
  • Apply information security and privacy requirements to ISMS policies.
  • Prepare documents for FedRAMP GovRAMP.
  • Develop KPI metrics for compliance and improvement.
  • Create project plans and manage implementations.
  • Conduct risk and privacy impact assessments and report findings.
  • Collaborate with operations to ensure controls are effective.
  • Oversee daily security operations and incident handling.
  • Lead vulnerability management and patching.
  • Manage internal and external audits and responses.

Skills

NIST SP800-53
ISO/IEC 27001
SOC2
Cloud security
Risk management
Governance
Security operations
Fortinet products

Education

Bachelor’s degree in Computer Science or Information Security
CISSP
CISA
CISM
ISO 27001 Lead-Auditor
CCSP
CRISC

Tools

SIEM/log management
ID/IPS
Vulnerability management tools
Cryptography
Cloud platforms (AWS, Azure, GCP)

Job description

Job Description
Fortinet looking for a Senior Information Security manager to join the Information Security team in the U.S. This position is responsible for leading the information security team, focusing on information security compliance projects. This role will oversee the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS), coordinate security compliance initiatives across the organization, and serve as the primary liaison with external auditors and regulatory bodies. The position requires a strong understanding of ISO/IEC 27001 and NIST security frameworks, cloud security, risk management, governance, and security operations. Job Description
Fortinet looking for a Senior Information Security manager to join the Information Security team in the U.S. This position is responsible for leading the information security team, focusing on information security compliance projects. This role will oversee the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS), coordinate security compliance initiatives across the organization, and serve as the primary liaison with external auditors and regulatory bodies. The position requires a strong understanding of ISO/IEC 27001 and NIST security frameworks, cloud security, risk management, governance, and security operations.
The successful candidate must be a U.S. citizen, and work onsite at Fortinet's headquarter in Sunnyvale, California.

Job Responsibilities:
  • Manage information security team, lead the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS).
  • Perform gap analysis based on NIST SP800-53 and other compliance framework, create mitigation/action plans.
  • Determine the applicability and apply the information security and privacy requirements to ISMS policies.
  • Prepare required documents for supporting various compliance frameworks such as FedRAMP and GovRAMP.
  • Develop related KPI metrics for performance measurement, and for ensuring continued compliance and improvement.
  • Create compliance project plans. Manage the implementation.
  • Conduct risk and privacy impact assessments on business and operation processes. Prepare finding reports. Create and implement risk treatment plans.
  • Collaborate with operation teams to ensure that appropriate controls are implemented and operated properly.
  • Participate in and lead the daily security operation, oversee the handling of security alerts and incidents.
  • Lead vulnerability management activities, monitor remediation progress, and work closely with operations teams to ensure timely patching of identified vulnerabilities.
  • Manage internal and external audits. Develop audit plans, respond to various audits and review requests.
Skills and Qualifications:
  • 7+ years of experience in information security area, with people and project management experience.
  • Subject matter expert of NIST SP800-53, ISO/IEC 27000 and SOC2 related standards, regulations and guidelines.
  • Experience of managing FedRAMP or GovRAMP implementation and compliance is highly preferred.
  • Knowledge and experience working with various information security frameworks (ISO/IEC 27001, NIST 800-53, NIST SP800-161, GovRAMP, FedRAMP, PCI DSS) and regulatory frameworks (SOX, PCI-DSS, HIPAA, GDPR, SOC, etc.)
  • Strong knowledge of and experience in privacy framework and regulatory compliance requirements (e.g., GDPR, CCPA).
  • Strong network security knowledge. Thorough understanding of current and emergent trends in information security
  • Working knowledge of information security control technologies including access control, cryptography, vulnerability management, SIEM/log management, ID/IPS, and penetration test.
  • Working knowledge and hardening skills on information technologies including Linux, Windows, VMWare, MySQL, MSSQL, etc.
  • Working knowledge of Cloud platforms, Cloud security (AWS, Azure, GCP) and network security.
  • Experience and knowledge of Fortinet products and services are preferred.
  • Strong verbal and written communication skills. Demonstrate ability to work with team members, cross functional and external parties.
  • Ability to work independently in a fast-paced, dynamic environment. Able to establish priorities and meet deadlines.
  • Ability to provide continual attention to details. Strong analytical mindset. Able to gather and report data in meaningful format.
  • Passionate about policies, processes and documentation. Able to translate general standards to practical guidelines suitable for business operations.
Educational & Certification Requirements:
  • Bachelor’s degree in computer science, Information Security or related field;
  • A certification in one or more of the following desirable:
    • CISSP
    • CISA, CISM
    • ISO 27001 Lead-Auditor
    • VCP
    • CCSP
    • CRISC
  • NIST SP800-53 related training program.
  • GovRAMP/FedRAMP related training program.
About Our Team:
Join our team, known for its collaborative ethos, working seamlessly with global customers, internal engineering teams and product development groups. Our team culture emphasizes continuous learning, innovation, and a strong commitment to customer satisfaction. We embrace Fortinet’s core values of openness, teamwork and innovation, fostering an environment where team members support each other, share knowledge, and leverage AI to solve complex technical challenges. Our inclusive and dynamic team thrives on collaboration and is driven by the shared goal of maintaining Fortinet’s high standards of excellence in cybersecurity solutions.
Must be authorized to work in the U.S. without sponsorship.
The US base salary range for this full-time position is $166,500-$203,500. Fortinet offers employees a variety of benefits, including medical, dental, vision, life and disability insurance, 401(k), 11 paid holidays, vacation time, and sick time, as well as a comprehensive leave program.
Wage ranges are based on various factors, including the labour market, job type, and job level. Exact salary offers will be determined by factors such as the candidate's subject knowledge, skill level, qualifications, experience, and geographic location.
All roles are eligible to participate in the Fortinet equity program. Bonus eligibility is reviewed at the time of hire and annually at the Company’s discretion.
Why Join Us:
We encourage candidates from all backgrounds and identities to apply. We offer a supportive work environment and a competitive Total Rewards package to support you with your overall health and financial well-being.
Embark on a challenging, enjoyable, and rewarding career journey with Fortinet. Join us in bringing solutions that make a meaningful and lasting impact to our 890,000+ customers around the globe.
About Us
Fortinet (NASDAQ: FTNT) secures the largest enterprise, service provider, and government organizations around the world. Fortinet empowers its customers with intelligent, seamless protection across the expanding attack surface and the power to take on ever-increasing performance requirements of the borderless network - today and into the future. Only the Fortinet Security Fabric architecture can deliver security without compromise to address the most critical security challenges, whether in networked, application, cloud or mobile environments. Fortinet ranks number one in the most security appliances shipped worldwide and more than 500,000 customers trust Fortinet to protect their businesses.
We are committed to providing reasonable accommodations for all qualified individuals with disabilities. If you require assistance or accommodation due to a disability, please contact us at accommodations@fortinet.com.Fortinet is an equal opportunity employer. We value diversity in our company, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, military/veteran status or any other applicable legally protected characteristics in the location in which the candidate is applying.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Manager
Senior Information Security Manager

Socket.dev • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Senior Information Security Manager
Senior Information Security Manager

Fortinet, Inc. • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Medical, Dental, Vision
401(k)
Paid holidays & time off
Staff Software Engineer - Cloud Platform (FortiSIEM)
Staff Software Engineer - Cloud Platform (FortiSIEM)

Zoomcar • Santa Clara (CA)

On-site
USD 179,000 - 219,000
Health insurance
Dental insurance
Vision insurance
+3
Staff Software Development Engineer
Staff Software Development Engineer

Zoomcar • Sunnyvale (CA)

On-site
USD 150,000 - 215,000
Medical, dental, and vision insurance
401(k)
Paid holidays and vacation time
Staff Software Development Engineer
Staff Software Development Engineer

Fortinet • Sunnyvale (CA)

On-site
USD 150,000 - 200,000
Medical, dental, vision insurance
401(k) plan
Paid holidays and vacation
+1
Software Development Engineer (SASE)
Software Development Engineer (SASE)

Fortinet • Santa Clara (CA)

On-site
USD 123,000 - 151,000
Medical insurance
Dental insurance
Vision insurance
+5
Staff Software Engineer – Cloud Platform (FortiSIEM)
Staff Software Engineer – Cloud Platform (FortiSIEM)

Fortinet • Santa Clara (CA)

On-site
USD 179,000 - 219,000
Project Manager
Project Manager

Zoomcar • Sunnyvale (CA)

On-site
USD 136,000 - 166,000
Medical, dental, vision insurance
401(k)
Paid holidays
+1
Staff Software Developer
Staff Software Developer

Zoomcar • Santa Clara (CA)

On-site
USD 179,000 - 219,000
Medical, dental, and vision insurance
401(k) plan
Paid holidays and vacation time
Sales Engineer, Enterprise Named
Sales Engineer, Enterprise Named

Fortinet, Inc. • Washington

On-site
USD 200,000 - 320,000
Medical, dental, and vision insurance
401(k)
Paid holidays and vacation time
+1