Senior Manager of Information Security

Plume

United States

On-site

USD 180,000 - 240,000

Full time

11 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Plume is seeking a Senior Manager of Information Security to mature and run a hands-on security program. You will formalize policies, build a high-functioning team, and safeguard our infrastructure, cloud environments, and applications while enabling engineers to move quickly.

You will lead security across governance, engineering, and product, translating risk into business actions and guiding compliance with ISO 27001 and SOC 2 requirements.

Qualifications

  • Bachelor's degree in Information Security, CS, or related field or equivalent work experience.
  • 6-8+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
  • Direct experience operating within ISO 27001 and SOC 2 frameworks — audit-ready mindset.
  • Strong technical depth in cloud security (AWS/GCP), network security, and modern AppSec concepts.
  • Experience building or rebuilding policies and procedures in a scaling SaaS environment.
  • A track record of leading security teams that engineers actually enjoy working with.

Responsibilities

  • Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
  • Author, formalize, and maintain the policies, standards, and procedures required to close gaps and sustain certification readiness.
  • Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
  • Manage relationships with external auditors, pen testers, and compliance partners.
  • Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end.
  • Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response.
  • Establish and continuously improve secure SDLC practices — threat modeling, secure code review, dependency and supply-chain security, CI/CD pipeline security.
  • Own incident response: build the plan, run tabletop exercises, and lead the response when needed.
  • Lead, coach, and develop security team — establishing clear roles, workflows, and a sense of ownership.
  • Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
  • Define how the team engages with Engineering and Product to minimize friction and rework.

Skills

Security leadership
Risk management
Cloud security
ISO 27001 SOC2
Policy development
Communication

Education

Bachelor's degree in Information Security or related field

Job description

We're looking for a Senior Manager of Information Security to lead and mature our security program at a critical inflection point. We've already achieved ISO 27001 and SOC 2 Type 1 certifications — the foundation is in place. Now we need a hands-on leader who can turn that foundation into a durable, well-run program: formalizing policies and procedures, building a high-functioning security team, and protecting our infrastructure, networks, cloud environments, and applications — all without slowing down the engineers and developers who build our products.

This is not a "policy for policy's sake" role. You'll be the person who makes security a natural part of how we build software, not an obstacle to it.

Responsibilities:
Program & Governance
  • Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
  • Author, formalize, and maintain the policies, standards, and procedures required to close any remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor/third-party risk, change management, business continuity, etc.).
  • Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
  • Manage relationships with external auditors, pen testers, and compliance partners.
Security Engineering & Operations
  • Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end.
  • Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response.
  • Establish and continuously improve secure SDLC practices — threat modeling, secure code review, dependency and supply-chain security, CI/CD pipeline security.
  • Own incident response: build the plan, run tabletop exercises, and lead the response when needed.
  • Lead, coach, and develop security team — establishing clear roles, workflows, and a sense of ownership.
  • Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
  • Define how the team engages with Engineering and Product (embedded reviews, self-service tooling, clear SLAs) to minimize friction and rework.
Cross-Functional Partnership
  • Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership.
  • Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no."
  • Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage.
Qualifications:
  • Bachelor's degree in Information Security, Computer Science, Computer Engineering or related field or equivalent work experience.
  • 6-8+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
  • Direct experience operating within (not just achieving) ISO 27001 and SOC 2 frameworks — you know what "audit-ready" looks like day to day, not just at renewal time.
  • Strong technical depth in cloud security (AWS/GCP), network security, and modern application security (SDLC, AppSec tooling, container/Kubernetes security a plus).
  • Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment.
  • A track record of leading security teams that engineers actually like working with — you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates.
  • Experience managing external auditors, penetration testers, and compliance vendors.
  • Excellent communication skills — able to flex between a whiteboard session with engineers and a risk briefing with the board.
Nice to Have:
  • CISSP, CISM, or similar certification.
  • Experience implementing or operating under ISO 27701 (privacy extension to 27001) and the NIST Cybersecurity Framework (CSF).
  • Experience in a company of similar size/stage (post-certification, scaling team).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Engineer
Senior Information Security Engineer

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000
Information Security Manager
Information Security Manager

BAE Systems OneArc USA, Inc • Orlando (FL)

On-site
USD 140,000 - 190,000
Director of Cyber Security
Director of Cyber Security

KAYAK • United States

Hybrid
USD 180,000 - 240,000
Flexible work policy
Generous time off
Volunteer time off
+3
Senior Director, Information Security
Senior Director, Information Security

Landis+Gyr • Alpharetta (GA)

On-site
USD 180,000 - 240,000
Information Security Manager
Information Security Manager

Arco Solutions • Kansas

On-site
USD 120,000 - 150,000
Flexible schedule
Health insurance
Interim Cybersecurity & IT Risk Lead Consultant
Interim Cybersecurity & IT Risk Lead Consultant

Fermi-LLC • Dallas (TX)

Hybrid
USD 180,000 - 240,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Chief Information Security Officer CISO
Chief Information Security Officer CISO

Ryde Technologies, LLC • Phoenix (AZ)

On-site
USD 180,000 - 260,000