Why This Role Stands Out
This hybrid Information Security Manager role offers a fantastic opportunity to shape critical governance workflows and make a significant impact within a reputable company. You'll thrive here if you possess strong analytical skills and enjoy collaborating with diverse teams to build robust security frameworks. Apply now to leverage your expertise and grow your career in a dynamic environment.
Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
1 week ago
Job Description
Title: Information Security Manager
Requirements:
• Define end to end governance workflows for:
o Risk identification and intake
o Risk review and validation
o Risk acceptance, mitigation, or transfer
o Ongoing monitoring and periodic reassessment
• Establish roles and responsibilities for risk owners, reviewers, and governance bodies.
• Design escalation and reporting processes for high risk and accepted risks.
• Engage key stakeholders across business, technology, security, and governance functions to validate risk requirements and workflows.
• Facilitate working sessions or workshops to socialize the risk register and governance processes.
• Support onboarding of initial risks into the enterprise risk register.
• Produce clear, audit ready documentation covering:
o Risk register structure and data definitions
o Risk scoring methodology
o Governance workflows and decision authorities
• Provide knowledge transfer to designated security staff to ensure sustainability beyond the contract term.
The contractor shall provide the following deliverables during the engagement:
1. Enterprise Risk Register Framework
o Standardized risk register template and taxonomy
2. Risk Scoring and Prioritization Model
o Documented likelihood and impact scales
o Scoring methodology and prioritization logic
3. Risk Governance Model
o Defined workflows for risk intake, review, acceptance, and monitoring
o Roles and responsibilities matrix
4. Initial Population of Risk Register
o Initial set of documented risks reflecting current cybersecurity and technology risk posture
5. Final Documentation Package
o Consolidated guidance and operating procedures for ongoing risk management
Similar jobs
- CR
General Security Operations & Program Security Support WAO 01.5.15
NewCredence
Wright Patterson Air Force Base, Ohio🇺🇸On-site6 hours agoLESSSAP - CR
Security Manager IN - 10.42
NewCredence
Wright-Patterson Air Force Base, Ohio🇺🇸On-site11 hours agoSSOAgileCompliance+1 - OR
Director, Security Engineering
NewOracle
Anthony, New Mexico🇺🇸Hybrid18 minutes agoAdministrative - JM
Security Engineer III
NewJ.P. Morgan
Columbus, Ohio🇺🇸On-site18 minutes agoAgileGoJava+1Technology - CR
Senior Executive Protection Analyst - GSOC - Night Shift
NewControl Risks
San Jose, California🇺🇸On-site9 hours agoComplianceOnboardingTalent Acquisition - MM
Staff Security Engineer, Threat Intelligence
NewMulti Media LLC
United States🇺🇸Remote23 hours agoGCPAWSMachine Learning+6Technology