Source Job

India

  • Own end-to-end compliance strategy and operations.
  • Conduct risk assessments and identify compliance risks.
  • Build compliance programs from ground up and coordinate compliance audits.

Compliance Risk Management SaaS ISO 27001 SOC 2

18 jobs similar to Sr Manager, Information Security

Jobs ranked by similarity.

North America

  • Support CapIntel’s Governance, Risk, and Compliance program
  • Manage third-party risk and customer security reviews
  • Support operational security, privacy, and security awareness initiatives

CapIntel is a software platform built for wealth management enterprises to help financial advisors explain complex investment strategies to their clients. Since launching in 2019, CapIntel has seen rapid adoption and industry recognition, earning top placements in Deloitte’s Technology Fast 50 Canada and Fast 500 North America in 2025, ranking us among the fastest -growing technology companies.

North America 5w PTO

  • Enhances the strategic pillars of a security compliance program and facilitate day-to-day compliance operations.
  • Involved in multiple areas of the business where compliance and security impact operations.
  • Works on assignments that are complex and require professional skepticism, judgment, initiative, and knowledge of SaaS Company positions.

Optro is the leading audit, risk, ESG, and InfoSec platform on the market, surpassing $300M ARR and continuing to grow. More than 50% of the Fortune 500 leverage their award-winning technology. They inspire each other to innovate and are proud of what they are producing.

Global

  • Lead end-to-end audit execution across SOC 2, ISO 27001, ISO 42001, ISO 27701, HIPAA, and GDPR and maintain year-round audit readiness.
  • Build and mature Atlan's risk management program and turn abstract risk conversations into measurable metrics with clear ownership and quarterly leadership reviews.
  • Integrate our GRC platform with cloud infrastructure, CI/CD pipelines, HR systems, and product engineering tooling to automate evidence collection and continuous control testing.

Atlan is building the missing context layer for data and AI, helping enterprises close the AI value chasm and finally move AI pilots into production. We are backed by world-class investors including GIC, Insight Partners, Meritech, Peak XV, and Salesforce Ventures and trusted by global enterprises like Mastercard, Workday, General Motors, Unilever and others.

US Unlimited PTO

  • Manage SOC 2 Type II audits, serving as the primary point of contact for auditors and collaborators.
  • Coordinate HIPAA compliance assessments, including risk analyses, policy reviews, and Business Associate Agreement (BAA) management.
  • Conduct structured gap analyses against applicable frameworks to identify control deficiencies and develop prioritized remediation roadmaps.

Rad AI is transforming healthcare with AI-driven solutions, revolutionizing radiology to save time, reduce burnout, and improve patient care. They have secured over $140M in funding and recognized as a fast-growing company, fostering transparency, inclusion, and close collaboration.

Europe

  • Own our security and compliance documentation accurate and up to date.
  • Support our commercial teams in complex information security and compliance negotiations.
  • Take ownership of maintaining our current ISO 27001 compliance and certification.

Gearset is trusted by some of the largest companies in the world to handle their Salesforce DevOps. They are committed to protecting data through a modern approach to security and compliance.

US Unlimited PTO

  • Support security and compliance programs aligned with frameworks such as NIST, ISO, PCI DSS, and HIPAA.
  • Assist in maintaining alignment with global privacy regulations (GDPR, CCPA, and similar frameworks).
  • Assist in the development, implementation, and maintenance of security, privacy, and AI governance policies, standards, and procedures.

Hims & Hers is a health and wellness platform with a mission to help the world feel great through the power of better health. They are redefining healthcare by putting the customer first and delivering access to care that is affordable, accessible, and personal.

$220,000–$240,000/yr

  • Manage and develop staff members under Product Compliance.
  • Oversee and contribute to the vulnerability management lifecycle.
  • Assess and serve as a subject matter expert for regulatory and compliance requirements.

ExtraHop is a company that focuses on network detection and response (NDR) to help organizations stay ahead of emerging threats. They integrate network threat detection, network performance management, intrusion detection, and packet forensics into a single console.

$125,000–$140,000/yr
US

  • Collaborate with the engineering departments to implement security controls from approved security frameworks and drive best IT practices.
  • Interface with internal partner teams to help drive best practices and compliance.
  • Evaluate and perform Risk Assessments of new software solutions with internal partners.

Judi Health is an enterprise health technology company providing a comprehensive suite of solutions for employers and health plans. They consolidate all claim administration-related workflows in one scalable, secure platform and are working with clients, rebuilding trust in healthcare in the U.S.

Europe 5w PTO

  • Maintain documentation for ISO/IEC 27001 & ISO/IEC 42001; improve activities.
  • Extract security requirements from client MSAs; identify gaps and risks.
  • Coordinate internal and client audit requests; collect evidence.

Avalere Health's mission is to ensure every patient is identified, treated, supported, and cared for. They bring Advisory, Medical, and Marketing teams together to forge unconventional connections, building a future where healthcare is not a barrier and no patient is left behind.

$100,000–$120,000/yr
US Unlimited PTO

  • Conduct ongoing risk reviews and maintain an up-to-date risk register.
  • Support risk assessments across critical business processes and systems.
  • Partner with stakeholders to develop and track risk mitigation plans through resolution.

Radicle Health offers human services software products to foster collaboration and innovation, aiding organizations in better serving communities. They believe technology is crucial for the human services sector's success, housing mission-driven products that support organizations in delivering essential services.

$83,430–$109,232/yr
US Unlimited PTO

  • Implement and manage the NIST Risk Management Framework (RMF) to achieve and maintain compliance.
  • Drive the data privacy program by conducting Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs).
  • Design and execute a continuous internal audit program to validate the effectiveness of controls.

IonQ delivers solutions to solve the world’s most complex problems with quantum computing. IonQ's newest generation quantum computers, IonQ Tempo and IonQ Forte Enterprise, help customers and partners such as Amazon Web Services, AstraZeneca, and NVIDIA achieve 20x performance results.

4w paternity

  • Oversee third-party and internal risk assessments to support enterprise information security and governance, risk, and compliance (GRC) initiatives.
  • Manage vendor due diligence, maintains an accurate risk register, partners with internal stakeholders on mitigation strategies.
  • Drive continuous improvement of the risk and compliance framework.

Concorde Career Colleges is committed to a policy of Equal Employment Opportunity and will not discriminate against an applicant or employee based on race, color, religion, religious creed, national origin, ancestry, sex, age, veteran or military status, or any other legally protected characteristic. Concorde Career Colleges offer short career-focused programs preparing students for the healthcare industry.

US

  • Lead the organization’s cybersecurity strategy, governance, and operational security programs.
  • Protect company systems, networks, and data by developing security policies and managing risk.
  • Oversee security operations and lead incident response efforts.

Lightcast is a global leader in labor market insights with headquarters in Moscow, ID (US) and offices in the United Kingdom, Europe, and India. They drive economic prosperity and mobility by providing insights to build and develop people, institutions, companies, and communities.

US Unlimited PTO

  • Ownership of our SOC 2 and Privacy compliance roadmap, from problem framing to tracking adoption.
  • Gap analysis and consulting with clients to assess their InfoSec posture and provide actionable paths to certification.
  • Internal playbook development, creating the checklists, policy templates, and controls that will be automated within our software.

Greenplaces helps companies navigate reporting requirements. They empower businesses to measure their carbon emissions and act as the definitive source of truth for all sustainability and compliance activity. They are headquartered in Raleigh, NC, with a distributed team across the country and backed by world-class investors.

Europe

  • Implement security policies and standards into the company environment.
  • Develop and improve security concepts, policies, processes and awareness.
  • Act as main admin for respective Security Management systems and applications.

Deutsche Telekom IT Solutions Slovakia is a company providing innovative information and communication technology services. They are the second largest employer in the eastern part of Slovakia with more than 3900 employees and aim to proactively improve and transform.

US

  • Conduct structured interviews with partner organizations, operational teams, and technical stakeholders.
  • Documents end‑to‑end operational workflows and surface implicit, non‑documented practices.
  • Identify workflow fragility zones, handoff risks, and transition‑period vulnerabilities.

Element serves as a partner at the intersection of innovation and our clients' needs, efficiently crafting meaningful user experiences for government and commercial customers. Our talented professionals bring unparalleled energy engagement, setting a higher standard for impactful work.

US Unlimited PTO

  • Lead, mentor, and coach a team of high-performing Vanta for Government Account Executives.
  • Drive new business growth for CMMC, FedRAMP, NIST frameworks through strategic selling.
  • Develop clear business plans and identify necessary resources to effectively close new business.

Vanta helps businesses earn and prove trust by ensuring security is monitored and verified continuously. They empower companies to practice better security and prove it with ease, creating a kind and talented team, even for those without prior security experience.

$125,000–$155,000/yr

  • Responsible for managing and growing a comprehensive third-party risk management program across the organization.
  • Ensuring that Privia Health's information assets are safeguarded against cyber threats originating from third and fourth parties.
  • Leading the Third Party Access Committee (TPAC), driving compliance with regulations and implementing industry best practices for vendor risk management.

Privia Health is a technology-driven, national physician enablement company that collaborates with medical groups, health plans, and health systems to optimize physician practices, improve patient experiences, and reward doctors for delivering high-value care. The Privia Platform is led by top industry talent and exceptional physician leadership.