Source Job

US

  • Lead execution of the enterprise information security program.
  • Oversee threat detection/response, vulnerability management, and incident response processes.
  • Partner with Engineering and Infrastructure teams to secure cloud environments and CI/CD pipelines.

HIPAA SOC 2 SIEM Cloud Security

20 jobs similar to Senior Manager, Information Security

Jobs ranked by similarity.

Global

  • Lead and mature Material Bank’s enterprise information security program.
  • Own the security risk management framework, including risk identification, scoring, tracking, and executive reporting.
  • Own detection, incident response, and resilience strategy.

Material Bank operates the world’s largest material marketplace for the architecture and design industry, connecting designers with materials from leading brands. They operate in 37 countries and their platform is the standard for design professionals around the globe.

US

  • Own vulnerability management, SIEM tuning and monitoring, incident response, and threat investigation.
  • Maintain secure baseline configurations based on industry standards.
  • Oversee AWS security controls and enforce cloud security guardrails.

Jobgether posts this position on behalf of a partner company. They use an AI-powered matching process to ensure applications are reviewed quickly and fairly.

$200,000–$260,000/yr
US

  • Mentor and develop security engineers and analysts.
  • Define and own the security strategy and roadmap.
  • Lead and scale the security function across vulnerability management.

Attentive is the AI marketing platform for 1:1 personalization redefining the way brands and people connect. They combine technology with human expertise to build authentic customer relationships, partnering with more than 8,000 customers across 70+ industries.

US

  • Establish and maintain the organization’s enterprise-wide information security program.
  • Ensure compliance with healthcare and international security standards.
  • Develop and deliver security awareness training to employees.

MIE provides solutions that make a meaningful difference in healthcare. Founded in 1995, MIE serves as the innovation engine for business units that serve hospitals and health systems, physician practices, Fortune 500 employers, government agencies, and consumers.

5w PTO

  • Own our information security strategy and build our security roadmap.
  • Maintain our ISO 27001 certification, preparing for SOC 2 readiness.
  • Operate strategically and tactically, developing policy and reviewing cloud configurations.

ApprovalMax is redefining how finance teams manage the Money Out cycle — from purchase orders and supplier bills to employee expense management and payroll. Trusted by 18,000+ businesses worldwide, our platform empowers companies to automate financial controls, ensure compliance, and scale efficiently.

US

  • Design and automate Azure security controls.
  • Build “secure‑by‑default” CI/CD and tooling.
  • Lead incident response and ensure compliance with HIPAA, SOC 2, and HITRUST.

IntusCare is dedicated to providing a HIPAA-compliant healthcare platform for vulnerable elderly populations. As a fast-growing startup, they are scaling to support hundreds of customers and prioritize security.

CISO

ButterflyMX
US 5w PTO

  • Lead and scale a small, talented security team.
  • Shape our security strategy, implementing practical controls.
  • Partner with Engineering, Product, and Infrastructure leaders.

ButterflyMX empowers people to open and manage doors & gates from a smartphone. As a distributed, primarily remote workforce, they're looking for more intelligent, passionate, collaborative, ai-forward, and down-to-earth individuals to join their growing team.

Canada

  • Lead, develop, and mentor the Platform Security team, setting direction, managing performance, and ensuring strong communication and execution across distributed time zones.
  • Design, implement, and operate cloud security controls for AWS, GCP, and Azure to protect infrastructure, services, and applications from evolving threats.
  • Partner with engineering and product leadership to influence architecture decisions, define security requirements, and ensure alignment with Affirm’s technical strategy.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Security is critical to Affirm’s mission, and they aim to embed a strong security culture across the company so they can build and operate honest financial products.

Global

  • Perform internal audits and vulnerability testing, ensuring security controls are monitored.
  • Lead security architecture governance for internal IT and projects, using Unified Architecture Framework.
  • Maintain compliance with security requirements and develop roadmaps to address evolving threats.

Jobgether is a platform connecting job seekers with companies. It uses AI-powered matching to ensure applications are reviewed quickly and fairly, identifying top candidates for employers.

Global

  • Lead development of security strategy aligned to client business goals.
  • Guide risk management practices including risk registers and threat modeling.
  • Provide executive-level oversight of regulatory compliance programs.

Jobgether uses an AI-powered matching process to ensure applications are reviewed fairly. Their system identifies the top-fitting candidates and shares this shortlist with the hiring company.

North America

  • Own the 24‑month global security roadmap developed with an external partner; drive planning, resource allocation, cross‑region rollout, milestone tracking, and KPI delivery.
  • Lead the cybersecurity transformation: redesign the security operating model, establish regional capability hubs, hire and upskill teams, and integrate security into engineering and product lifecycles.
  • Modernize security tooling and architecture: define global architecture for IAM, cloud security, vulnerability management, SIEM/XDR, DLP, and secure SDLC integrations; manage vendor selection and lifecycle.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. With a combination of industry-leading tools, services, and expertise, Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

$120,000–$160,000/yr
US Unlimited PTO 12w maternity

  • Own and lead Impiricus’s security architecture across AWS.
  • Design and implement application and infrastructure security controls across the SDLC.
  • Build and operate detection and response capabilities, including logging, monitoring, and alerting.

Impiricus is an AI-powered HCP Engagement Engine transforming how life sciences companies support physicians. They ethically connect HCPs to pharma resources and are known for their unique access to a large network of HCP advisors.

US Canada Unlimited PTO

  • Own and lead the delivery of large, multi-quarter Application Security and Engineering initiatives.
  • Improve existing complex application security architectures and provide guidance for securing AI-based workflows.
  • Proactively identify emerging industry threats and act as Incident Commander for large-scale security incidents.

Wrapbook provides a unified payroll platform that seamlessly connects your entire team in one place. It empowers production teams to manage projects, pay cast and crew, track expenses, and generate data-driven insights. With a growing team of 250+ people across the USA and Canada, Wrapbook is backed by top-tier investors and has raised $130M.

$120,000–$165,000/yr
US

  • Serve as the system Security Manager / ISSO for My HealtheVet and act as the primary security point of contact for internal leadership and VA stakeholders.
  • Drive a risk-based security approach appropriate for a FISMA High / HVA system.
  • Coordinate incident response activities, including investigation support, escalation, documentation, and communication with VA security operations and CISO teams.

Oddball believes that the best products are built when companies understand and value the things they are working on. They value learning and growth and the ability to make a big impact at a small company.

Europe US

  • Collaborate with cross-functional teams to maintain and improve the company's comprehensive compliance program.
  • Manage the end-to-end audit process for SOC 2 compliance, ensuring timely and accurate completion.
  • Oversee the Information Security Risk Management Program, documenting identified risks, coordinating mitigation efforts.

airSlate is a global SaaS technology company that develops no-code workflow automation, electronic signature, and document management solutions. They have teammates in more than 20 countries across three continents and main hubs in the United States, Poland, Romania, Ukraine and Philippines.

US

  • Develop and execute tailored security strategies for each client.
  • Advise clients on security policies and governance structures.
  • Lead risk management and incident response initiatives.

Jobgether uses an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company.

$162,000–$253,000/yr
US

  • Define security detection program strategy and roadmap.
  • Oversee development, testing, and maintenance of detection logic.
  • Lead and mentor a high-performing team of security operators.

Cribl helps solve IT and Security's data needs. They foster a collaborative, curious, and motivated team environment where employees are passionate about putting customers first and believe in empowering our employees to do their best work, wherever they are.

Unlimited PTO

  • Monitor alerts and notifications from cloud services, security tools, and our SOC/MSSP partners.
  • Triage and analyze potential security incidents, determine severity and scope, and coordinate response and remediation.
  • Establish and enforce security standards, guidelines, and best practices across product, engineering, and IT.

Meshy is a leading 3D generative AI company on a mission to Unleash 3D Creativity by transforming the content creation pipeline, making it effortless for both professional artists and hobbyists to create unique 3D assets. Meshy's talent spans the globe and they are trusted by top developers.

US 4w PTO

  • Lead the development, implementation, and continuous improvement of a comprehensive healthcare privacy and compliance program.
  • Ensure all organizational operations meet and exceed regulatory, governance, and client standards, including HIPAA, HITRUST, SOC2, and Medicare/Medicaid requirements.
  • Proactively identify and mitigate compliance risks across the enterprise.

EPIC Insurance Brokers & Consultants is one of the fastest-growing firms in the insurance industry. They have over 3,000 employees nationwide and are headquartered in San Francisco. Their core values are: Owner mindset, Inspire trust, Think big, and Drive results.

US

  • Coordinate compliance with standards (PCI, HIPAA, ISO 27002, SOC 1/2/3, FISMA/FedRAMP, etc.) under guidance.
  • Maintain evidence repositories and partner with SMEs to refresh artifacts.
  • Coordinate audits and certification efforts, partnering with support teams on timelines and resourcing.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), they have a team of 22,500 people across 32 countries.