Senior ISMS & Compliance Leader (NIST/ISO)

Fortinet, Inc.

Sunnyvale (CA)

On-site

USD 167,000 - 204,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision
401(k)
Paid holidays & time off

Job summary

Fortinet, Inc. in Sunnyvale, California, USA, seeks a Senior Information Security Manager to lead the Information Security team onsite.

You will oversee ISMS design, implementation, operations, and continual improvement, coordinating security compliance initiatives with auditors and regulators. You will drive gap analyses against NIST SP800-53 and other frameworks, manage risk and privacy assessments, and collaborate with operations to ensure proper controls.

Qualifications

  • 7+ years of experience in information security with people and project management.
  • Subject matter expert of NIST SP800-53, ISO/IEC 27000 and SOC2 related standards, regulations and guidelines.
  • Experience of managing FedRAMP or GovRAMP implementation and compliance is highly preferred.
  • Knowledge and experience working with various information security frameworks (ISO/IEC 27001, NIST 800-53, NIST SP800-161, GovRAMP, FedRAMP, PCI DSS) and regulatory frameworks (SOX, PCI-DSS, HIPAA, GDPR, SOC, etc.).
  • Strong knowledge of and experience in privacy framework and regulatory compliance requirements (e.g., GDPR, CCPA).
  • Strong network security knowledge. Thorough understanding of current and emergent trends in information security.
  • Working knowledge of information security control technologies including access control, cryptography, vulnerability management, SIEM/log management, ID/IPS, and penetration test.
  • Working knowledge and hardening skills on information technologies including Linux, Windows, VMWare, MySQL, MSSQL, etc.
  • Working knowledge of Cloud platforms, Cloud security (AWS, Azure, GCP) and network security.
  • Experience and knowledge of Fortinet products and services are preferred.
  • Strong verbal and written communication skills. Demonstrate ability to work with team members, cross functional and external parties.
  • Ability to work independently in a fast-paced, dynamic environment. Able to establish priorities and meet deadlines.
  • Ability to provide continual attention to details. Strong analytical mindset. Able to gather and report data in meaningful format.
  • Passionate about policies, processes and documentation. Able to translate general standards to practical guidelines suitable for business operations.

Responsibilities

  • Manage information security team, lead the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS).
  • Perform gap analysis based on NIST SP800-53 and other compliance framework, create mitigation/action plans.
  • Determine the applicability and apply the information security and privacy requirements to ISMS policies.
  • Prepare required documents for supporting various compliance frameworks such as FedRAMP and GovRAMP.
  • Develop related KPI metrics for performance measurement, and for ensuring continued compliance and improvement.
  • Create compliance project plans. Manage the implementation.
  • Conduct risk and privacy impact assessments on business and operation processes. Prepare finding reports. Create and implement risk treatment plans.
  • Collaborate with operation teams to ensure that appropriate controls are implemented and operated properly.
  • Participate in and lead the daily security operation, oversee the handling of security alerts and incidents.
  • Lead vulnerability management activities, monitor remediation progress, and work closely with operations teams to ensure timely patching of identified vulnerabilities.
  • Manage internal and external audits. Develop audit plans, respond to various audits and review requests.

Skills

NIST SP800-53
ISO/IEC 27001
SOC 2
FedRAMP GovRAMP
Cloud security
Risk management
Governance
Security operations
Vulnerability management
Regulatory compliance

Education

Bachelor’s degree in Computer Science or related field
CISSP
CISA
CISM
ISO 27001 Lead-Auditor
CCSP
CRISC
NIST SP800-53 training
GovRAMP/FedRAMP training

Tools

AWS
Azure
GCP
Linux
Windows
VMware
MySQL
MSSQL

Job description

Fortinet, Inc. in Sunnyvale, California, USA, seeks a Senior Information Security Manager to lead the Information Security team onsite.

You will oversee ISMS design, implementation, operations, and continual improvement, coordinating security compliance initiatives with auditors and regulators. You will drive gap analyses against NIST SP800-53 and other frameworks, manage risk and privacy assessments, and collaborate with operations to ensure proper controls.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Leader — ISMS, Compliance & Risk
Senior Information Security Leader — ISMS, Compliance & Risk

Zoomcar • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Medical insurance
Dental insurance
Vision insurance
+9
Senior ISMS & Compliance Leader - Onsite Sunnyvale
Senior ISMS & Compliance Leader - Onsite Sunnyvale

Socket.dev • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Senior Information Security Manager
Senior Information Security Manager

Zoomcar • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Medical insurance
Dental insurance
Vision insurance
+9
Senior Information Security Manager
Senior Information Security Manager

Fortinet, Inc. • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Medical, Dental, Vision
401(k)
Paid holidays & time off
Senior Information Security Manager
Senior Information Security Manager

Fortinet • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Medical insurance
Dental insurance
Vision insurance
+6
Senior Information Security Manager
Senior Information Security Manager

Socket.dev • Sunnyvale (CA)

On-site
USD 167,000 - 204,000
Security Operations Lead - Incident Response & SIEM
Security Operations Lead - Incident Response & SIEM

Fortinet • Sunnyvale (CA)

On-site
USD 92,000 - 112,000
Equity program
Bonus eligibility
Senior ISSO & Cybersecurity Compliance Leader
Senior ISSO & Cybersecurity Compliance Leader

AIS (Applied Information Sciences) • Washington

On-site
USD 120,000 - 181,000
Onsite ISSM & Compliance Leader (CMMC/NIST)
Onsite ISSM & Compliance Leader (CMMC/NIST)

Firestorm • San Diego (CA)

On-site
USD 140,000 - 180,000
401(k) Retirement Savings Plan
Equity grants
Unlimited PTO
+3
Senior ISSM: Defense Security & Compliance Leader
Senior ISSM: Defense Security & Compliance Leader

Cypress HCM • San Diego (CA)

On-site
USD 150,000 - 175,000