Senior Manager of Information Security

Plume Design

United States

Hybrid

USD 160.000 - 230.000

Vollzeit

Vor 7 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Bekomme eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Health insurance
Remote/flexible work arrangements
Home-office setup allowance
Professional development opportunities
Team-building events

Zusammenfassung

Plume Design is seeking a Senior Manager of Information Security to lead the security program at a pivotal growth stage. You will own ISO 27001 and SOC 2 alignment, formalize policies, and drive a high-performing security team while enabling engineers to move fast.

You will own risk management, incident response, and security architecture across AWS/GCP, networks, and applications, delivering a proactive, audit-ready program with measurable impact.

Qualifikationen

  • Bachelor’s degree in Information Security or related field, or equivalent work experience.

Aufgaben

  • Own and mature the information security program aligned with ISO 27001 and SOC 2 requirements.
  • Lead, coach, and develop a security team to build a durable security program.
  • Translate security risk into business terms for leadership and the board.
  • Manage external auditors, pen testers, and compliance vendors.
  • Protect infrastructure, networks, cloud environments, and applications end-to-end.
  • Establish secure SDLC practices including threat modeling and secure code review.

Kenntnisse

Security leadership
Risk management
Audits & compliance
Cloud security (AWS/GCP)
Threat modeling
Security architecture
Incident response

Ausbildung

Bachelor's degree in Information Security
Bachelor's degree in Computer Science
Related field or experience

Tools

AWS
GCP
Kubernetes
CI/CD tooling

Jobbeschreibung

  • We’re looking for a Senior Manager of Information Security to lead and mature our security program at a critical inflection point
  • We’ve already achieved ISO 27001 and SOC 2 Type 1 certifications — the foundation is in place
  • Now we need a hands‑on leader who can turn that foundation into a durable, well‑run program: formalizing policies and procedures, building a high‑functioning security team, and protecting our infrastructure, networks, cloud environments, and applications — all without slowing down the engineers and developers who build our products
  • This is not a “policy for policy’s sake” role
  • You’ll be the person who makes security a natural part of how we build software, not an obstacle to it
  • Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2
  • Author, formalize, and maintain the policies, standards, and procedures required to close any remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor/third‑party risk, change management, business continuity, etc.)
  • Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking
  • Manage relationships with external auditors, pen testers, and compliance partners
  • Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end
  • Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response
  • Establish and continuously improve secure SDLC practices — threat modeling, secure code review, dependency and supply‑chain security, CI/CD pipeline security
  • Own incident response: build the plan, run tabletop exercises, and lead the response when needed
  • Lead, coach, and develop security team — establishing clear roles, workflows, and a sense of ownership
  • Build a team culture rooted in partnership rather than gate‑keeping: security as an enabler engineers want to work with, not a blocker they route around
  • Define how the team engages with Engineering and Product (embedded reviews, self‑service tooling, clear SLAs) to minimize friction and rework
  • Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership
  • Translate security risk into business terms for leadership and the board; make pragmatic, risk‑based decisions rather than defaulting to “no.”
  • Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well‑run program becomes a competitive advantage
  • How We’ll Measure Success (First 3–6 Months):
  • Policies and procedures are fully documented, approved, and operational — not just written for the audit
  • The team has clear ownership areas, workflows, and is executing proactively rather than reactively
  • SOC 2 Type 2 audit (or next relevant milestone) is on track with minimal last‑minute scrambling
  • Engineering teams report that security review and tooling add minimal friction to their workflow (measurable via review turnaround time, exception requests, or a simple satisfaction pulse)
  • A functioning incident response process exists and has been tested (tabletop or live)
Benefits
  • Public transportation reimbursement
  • Lifetime Plume HomePass membership
  • Plume employee referral bonus program
  • Retirement savings contributions
  • Allowance for home‑office set up
  • Monthly data or phone allowance
  • Employee assistance program
  • Employee discounts
  • Competitive and comprehensive health insurance coverage and extended benefits such as dental, vision, life, short/long‑term disability insurance, and FSA/HSA (detailed coverage may vary by location)
  • Patent submission support and incentive award program
  • Generous vacation policy to ensure time to recharge (open paid time off or generous accrued paid time off based on location)
  • Generous parental leave policy
  • PlumeStrong - our corporate social responsibility program designed to apply our resources (time, brainpower, product, money) for good
  • Online and in‑person team‑building events
  • Health and wellness reimbursement and a Premium Strava membership
  • Immigration support
  • Holistic health platform through Walking on Earth
  • Professional development opportunities
  • Remote/flexible work arrangements
  • Direct experience operating within (not just achieving) ISO 27001 and SOC 2 frameworks — you know what “audit-ready” looks like day to day, not just at renewal time
  • Bachelor’s degree in Information Security, Computer Science, Computer Engineering or related field or equivalent work experience
  • 6-8+ years in information security, with 3+ years in a leadership role owning a security program end‑to‑end
  • Excellent communication skills — able to flex between a whiteboard session with engineers and a risk briefing with the board
  • Experience managing external auditors, penetration testers, and compliance vendors
  • Strong technical depth in cloud security (AWS/GCP), network security, and modern application security (SDLC, AppSec tooling, container/Kubernetes security a plus)
  • A track record of leading security teams that engineers actually like working with — you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates
  • Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment
  • CISSP, CISM, or similar certification
  • Experience implementing or operating under ISO 27701 (privacy extension to 27001) and the NIST Cybersecurity Framework (CSF)
  • Experience in a company of similar size/stage (post‑certification, scaling team)
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Manager of Information Security
Senior Manager of Information Security

Plume • USA

Vor Ort
USD 180.000 - 240.000
Director of Information Security
Director of Information Security

Capmont GmbH • USA

Vor Ort
USD 179.000 - 190.000
401k with company match
Health, dental, vision benefits
Life insurance and other benefits
+1
Staff DevSecOps Engineer
Staff DevSecOps Engineer

Red Ventures • USA

Hybrid
USD 180.000 - 240.000
Hybrid Schedule
Flexible PTO
Mentorship Culture
+2
Senior Security Program Lead: ISO 27001 & SOC 2
Senior Security Program Lead: ISO 27001 & SOC 2

Plume • USA

Vor Ort
USD 180.000 - 240.000
InfoSec Program Lead - Scalable, Audit-Ready Security
InfoSec Program Lead - Scalable, Audit-Ready Security

Plume Design • USA

Hybrid
USD 160.000 - 230.000
Health insurance
Remote/flexible work arrangements
Home-office setup allowance
+2
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120.000 - 160.000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
Information Security Manager
Information Security Manager

BAE Systems OneArc USA, Inc • Orlando (FL)

Vor Ort
USD 140.000 - 190.000
InfoSec & IT Lead
InfoSec & IT Lead

Rippling, Inc. • New Orleans (LA)

Vor Ort
USD 120.000 - 160.000
Senior InfoSec Leader: Scale Secure SaaS & Cloud
Senior InfoSec Leader: Scale Secure SaaS & Cloud

Capmont GmbH • USA

Remote
USD 179.000 - 190.000
401k with company match
Health, dental, vision benefits
Life insurance and other benefits
+1
IT Security Team Lead
IT Security Team Lead

Creative Capsule • USA

Vor Ort
USD 140.000 - 180.000