Senior IT Security Manager I

GoFormz

San Diego (CA)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GoFormz is seeking a hands-on Senior IT Security Manager to own our cybersecurity posture while providing tactical IT operations support. This senior individual contributor role may evolve into team leadership as the organization grows.

Approximately 75% of this role is focused on cybersecurity—strategy, implementation, monitoring, and compliance. The remaining 25% covers core IT support and systems administration to keep the organization running smoothly.

Qualifications

  • 7+ years IT and cybersecurity experience with senior/lead responsibilities.
  • Hands-on with security tools and cloud security principles.
  • Experience with compliance frameworks and security audits.

Responsibilities

  • Own and mature the information security program, policies, and roadmap.
  • Monitor, detect, respond to security events, and lead incident response.
  • Manage vulnerability scanning and remediation with stakeholders.
  • Provide security guidance on cloud infra and SaaS adoption.
  • Oversee IAM, provisioning and least-privilege enforcement.
  • Lead compliance efforts for SOC 2, HIPAA, PCI-DSS, GDPR as applicable.
  • Run security awareness programs and phishing simulations.
  • Support IT operations across core systems and devices.

Skills

IT security
Security program mgmt
Incident response
Cloud security
IAM
Vulnerability management
Compliance & audits

Tools

EDR
SIEM
MFA/SSO
DLP
Firewall
VPN
Microsoft 365
Google Workspace

Job description

Description

We are looking for a hands‑on Senior IT Security Manager to own our cybersecurity posture while providing tactical IT operations support. This is a senior individual contributor role with potential team leadership responsibilities as the organization grows. The right candidate thrives in a small‑team environment, is comfortable wearing multiple hats, and brings deep security expertise alongside solid IT fundamentals.

Approximately 75% of this role is focused on cybersecurity — strategy, implementation, monitoring, and compliance. The remaining 25% covers core IT support and systems administration to keep the organization running smoothly.

Key Responsibilities
Cybersecurity (75%)

Security Program Ownership

  • Own and continuously mature the organization’s information security program, policies, and roadmap
  • Develop, implement, and enforce security policies, standards, and procedures aligned with industry frameworks (NIST CSF, ISO 27001, CIS Controls, or equivalent)
  • Conduct regular risk assessments and maintain a risk register; prioritize remediation based on business impact

Threat Detection & Incident Response

  • Monitor, triage, and respond to security events and alerts across endpoints, network, cloud, and SaaS environments
  • Own the incident response plan; lead investigation, containment, and post-incident review for security events
  • Manage vulnerability scanning programs and drive timely remediation with internal stakeholders

Security Architecture & Engineering

  • Evaluate, deploy, and manage security tooling (EDR, SIEM, MFA/SSO, email security, DLP, firewall, VPN, etc.)
  • Provide security guidance on cloud infrastructure (Azure/GCP), SaaS adoption, and new technology onboarding
  • Oversee identity and access management (IAM) including provisioning, deprovisioning, and least‑privilege enforcement

Compliance & Third-Party Risk

  • Lead and support compliance efforts for applicable frameworks or regulations (SOC 2, HIPAA, PCI-DSS, CMMC, GDPR, etc.)
  • Manage the vendor security review process and maintain third‑party risk inventory
  • Coordinate with external auditors, penetration testers, and security consultants

Security Awareness

  • Develop and run the organization’s security awareness training program
  • Conduct phishing simulations and track outcomes; deliver targeted education where needed
  • Act as a security advocate internally — advising leadership and employees on security best practices
IT Support & Systems Administration (25%)
  • Serve as escalation point for complex IT support issues across hardware, software, and connectivity
  • Administer core systems: Microsoft 365 / Google Workspace, Active Directory / Entra ID, MDM (Intune, Jamf, or similar)
  • Manage software vendor relationships
  • Manage user lifecycle (onboarding/offboarding), device provisioning, and access reviews
  • Maintain IT asset inventory and ensure systems remain patched and up to date
  • Support network infrastructure including firewalls, switches, and wireless access points
  • Document IT processes, runbooks, and system configurations

Requirements

Qualifications

Required

  • 7+ years of progressive IT and cybersecurity experience, with at least 3 years in a senior or lead security role
  • Demonstrated experience managing security programs end-to-end in a resource-constrained environment
  • Hands‑on experience with security tools: EDR, SIEM, vulnerability scanners, email security gateways, payment fraud systems, and identity platforms
  • Working knowledge of one or more compliance frameworks (SOC 2, NIST, ISO 27001, etc.)
  • Strong incident response skills — you’ve handled real events, not just tabletops
  • Prior involvement in security audits, penetration tests, or regulatory reviews
  • Experience administering Microsoft 365 or Google Workspace and cloud environments (AWS, Azure, or GCP)
  • Experience managing security and compliance planforms, such as Drata
  • Excellent written and verbal communication; able to present risk to non‑technical leadership clearly

Preferred

  • Relevant certifications: CISSP, CISM, Security+, CEH, GCIA, GCIH, or equivalent
  • Experience at a company with 50-500 employees; comfortable being the primary security resource
  • Familiarity with zero trust architecture principles
  • Experience managing or mentoring junior IT/security staff
Physical Requirements
  • Prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift up to 25 pounds at times.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Security Manager
Senior IT Security Manager

GoFormz • San Diego (CA)

On-site
USD 140,000 - 190,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Senior Cyber Security & Infrastructure Lead
Senior Cyber Security & Infrastructure Lead

eTeam • Cuyahoga Falls (OH)

Hybrid
USD 140,000 - 190,000
Cybersecurity Lead
Cybersecurity Lead

21 Air LLC. • Miami (FL)

Hybrid
USD 120,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
IT Security Administrator
IT Security Administrator

Daikin Comfort • Waller (TX)

On-site
USD 65,000 - 90,000
Senior Security Program Lead
Senior Security Program Lead

GlobalSource IT • Columbia (SC)

On-site
USD 90,000 - 120,000
Competitive compensation
Professional growth opportunities
Collaborative team environment
+1
Senior Cyber Security Analyst
Senior Cyber Security Analyst

BinaryBees Business Solutions LLC • Bloomingdale (IL)

On-site
USD 100,000 - 150,000
IT Security - Sr. Analyst
IT Security - Sr. Analyst

CKE Restaurants, Inc. • Franklin (TN)

On-site
USD 85,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000