Information Security Manager (Remote)
$82.08k - $127.5kWCG
General Information
Location: Cary, NC, Remote
Organization: WCG
Job Type: Full Time - Regular
Benefits
- Comprehensive Benefits package - Health, Dental, Vision, Life Disability, 401k with match, and flexible spending accounts
- Employee Assistance Programs and additional work/life resources
- Referral Bonuses and Tuition Reimbursement
- Flexible PTO
- Volunteer Time Off to benefit the community
- Opportunities for career development with on-the-job training, certification assistance and continuing education reimbursement
Salary Range: $82,080 to $127,500.
Job Summary
The Cybersecurity Manager is a key member of the Information Security team, directly supporting the Chief Information Security Officer (CISO) in the design, implementation, and ongoing operation of the organization's security program. This role holds primary accountability for maintaining compliance with SOC 2 and ISO 27001 frameworks, facilitating governance committee activities, and acting as a liaison between the security program, internal project teams, and external customers. The Security Manager combines technical knowledge with strong organizational and communication skills to protect the organization's information assets while enabling business objectives.
Responsibilities
Framework Compliance – SOC 2 & ISO 27001
- Own and manage the organization's SOC 2 (Type I & II) and ISO 27001 compliance programs end‑to‑end, including control design, evidence collection, gap assessments, and remediation tracking.
- Serve as the primary point of contact with external auditors and certification bodies; coordinate audit readiness activities and ensure timely responses to audit requests.
- Maintain and continuously improve the Information Security Management System (ISMS) in alignment with ISO 27001 requirements.
- Monitor the regulatory and standards landscape for updates to SOC 2 Trust Services Criteria and ISO 27001:2022 and translate changes into actionable program updates.
- Develop, review, and maintain information security policies, standards, and procedures that satisfy framework requirements.
- Track and report on control effectiveness metrics, audit findings, and remediation status to the CISO and senior leadership.
Governance & Committee Management
- Plan, schedule, and facilitate Information Security Committee meetings, including agenda preparation, material distribution, minute‑taking, and action item tracking.
- Coordinate cross‑functional participation in governance bodies (e.g., Risk Committee, Change Advisory Board) and ensure security representation and follow‑through.
- Prepare governance dashboards, risk registers, and Key Risk Indicator (KRI) / Key Performance Indicator (KPI) reports for committee review.
- Drive accountability across business units by tracking and escalating open security action items through appropriate governance channels.
Security Program Management
- Support the CISO in the development, execution, and reporting of the annual information security roadmap and strategic plan.
- Maintain the security program portfolio, including project status, milestones, dependencies, risks, and resource utilization.
- Contribute to security initiatives such as vulnerability management, third‑party risk management, security awareness training, and incident response planning.
- Develop and maintain a security metrics program that provides visibility into the health and maturity of the information security function.
- Support budget planning and vendor management activities relevant to security tools, assessments, and services.
- Identify and evaluate unsanctioned or emerging AI tool use across the organization (shadow AI), and support processes to assess and approve AI applications in alignment with security and privacy requirements.
- Track developments in the AI risk and regulatory landscape and surface implications for the security program to the CISO.
Collaboration with Internal Stakeholders
- Act as the embedded security resource and advisor for internal project teams throughout the project lifecycle, from initiation through closure.
- Conduct security reviews and risk assessments for new projects, system changes, and technology implementations; provide documented risk guidance and approval recommendations to project managers.
- Ensure security requirements are captured and tracked in project plans, and that security sign‑off is obtained prior to production releases.
- Participate in project steering committees and sprint reviews to surface and address security risks promptly.
- Serve as a liaison and coordination point between CISO’s office and internal security disciplines, ensuring alignment on priorities and program goals.
- Partner with Security Architecture to incorporate security requirements into new designs and technology decisions.
- Work closely with Risk and Compliance to align risk assessment activities with enterprise risk management.
- Coordinate with Cybersecurity Operations on threat monitoring, incident escalation procedures, and operational security metrics.
- Collaborate with Security Architecture and Cybersecurity Operations to assess AI‑specific threat vectors.
- Collaborate with Legal, HR, IT, Product, and Finance to embed security requirements into business processes, contracts, and change activities.
- Act as an extension of the CISO within cross‑functional forums, representing the security organization’s priorities.
Customer & External Stakeholder Engagement
- Respond to customer security questionnaires, due diligence requests, and RFP security sections professionally and promptly.
- Serve as a subject‑matter expert during customer security reviews, audits, and contract negotiations.
- Maintain and continuously improve a customer‑facing security trust package.
- Build and nurture positive relationships with customer security teams.
- Incorporate AI‑related security considerations into customer due diligence responses and vendor assessments.
CISO Support & Additional Responsibilities
- Provide direct coordination and strategic support to the CISO, including preparing briefings, board presentations, and executive reports.
- Monitor threat intelligence and summarize relevant developments for CISO review.
- Oversee and coordinate the security awareness and training program.
- Support development and testing of Incident Response and Business Continuity plans.
- Collaborate in third‑party and vendor risk assessments.
- Stay current on emerging security trends, regulations, and best practices.
- Coordinate with Legal and Privacy teams on AI adoption data‑protection implications.
- Other duties as assigned by supervisor.
Education Requirements
- Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field required.
- Master's degree or equivalent advanced education in a relevant discipline is a plus.
Certifications
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- ISO 27001 Lead Implementer or Lead Auditor
- SOC 2 / AICPA CISA or equivalent audit‑related credential
- CRISC or other relevant certifications
Qualifications / Experience
- 5+ years of progressive experience in information security, risk management, or IT compliance.
- Hands‑on experience managing SOC 2 audits and ISO 27001 certifications.
- Strong working knowledge of SOC 2 Trust Services Criteria and ISO 27001:2022 control frameworks.
- Familiarity with additional frameworks such as NIST CSF, HIPAA, GDPR, SOX, PCI DSS, and FedRAMP.
- Experience with GRC platforms such as Vanta, Drata, OneTrust, ServiceNow GRC, or similar.
- Proficiency in risk assessment methodologies and security documentation practices.
- Knowledge of cloud security concepts (AWS, Azure, GCP) and common enterprise security technologies.
- Awareness of AI‑specific security risks and familiarity with NIST AI Risk Management Framework (AI RMF 1.0) or ISO/IEC 42001.
- Experience supporting or working directly with a CISO or senior security executive in a program management capacity.
- Track record of engaging with external customers on security topics.
- Experience facilitating cross‑functional governance meetings.
- Exposure to AI risk management concepts.
- Exceptional written and verbal communication skills.
- Strong organizational and project management skills.
- Collaborative, relationship‑oriented approach with influence at all levels.
Travel Requirements
5% - 10%
Physical and Sensory Requirements
The physical and sensory requirements described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be offered to individuals with disabilities to assist in performing the essential functions of the position. Work activities involve light to moderate physical effort (for example, sitting in one place for extended periods of time, standing, walking, bending, lifting lightweight objects, intermittent to sustained periods of keyboarding). Majority of time is spent in a seated position with frequent opportunity to move about at will. Activities require a variety of easy muscle movements. Work activities involve a frequent need to concentrate on a variety of sensory inputs for moderate to lengthy durations at a time requiring diligence and attention to interpret effectively. There will be a need to attend to single or simultaneous tasks where accuracy of details is important. The need to detail and precise work is high.
Equal Employment Opportunity Statement
WCG is proud to be an equal opportunity employer – Qualified applicants will receive consideration for employment based on merit and without regard to race, color, national origin or ancestry, religion or creed, sex, sexual orientation, gender expression, gender identity, age, marital status, family or parental status, disability, genetic information, citizenship, veteran status, or any other legally recognized basis or status protected by federal, state, or local law. WCG complies with the Vietnam Era Veterans' Readjustment Act and Section 503 of the Rehabilitation Act. We promote a "One WCG" culture where all are welcome, respected, valued, and empowered to make a difference every day to advance clinical research.
#J-18808-Ljbffr- ibc AG sucht einen IT-Berater in Hamburg oder Aachen (Vollzeit) zur Unterstützung bei Sicherheitskonzepten und IT-Notfallmanagement. Sie beraten in Fragen des BSI-IT-Grundschutzes, führen Revisionen durch und bieten Lösungen für Informationssicherheitsrisiken. Eine offene...Remote work
- ...Date Revised: February 18, 2025 Position Summary: The Information Security Manager is a hands-on/ working manager position that defines, implements... ...and monitors security policy for on-prem, cloud, and remote access deployments. The primary duty of the job is to maintain...Remote workImmediate startVisa sponsorshipWeekend workAfternoon shift
- ...TSC has an excellent opportunity for an Information System Security Manager (ISSM) to work remotely within our Airborne Solutions and ISR Division. The role involves implementing and maintaining security policies for classified information systems while collaborating with...Remote workFlexible hours
- ...Help Shape the Future of Secure Innovation At RS21, we’re on a mission... ...to safeguard the information entrusted to us. We're looking... ...maintain our Information Security Management System, and build practices that... ...experimentation. A flexible, remote-first workplace with team...Remote workPermanent employmentContract workFlexible hours
$120k
...Overview The Information Security Manager leads the design, implementation, and continuous enhancement of the organization’s cybersecurity program... ..., or CRISC preferred. Work Environment / Travel Hybrid or remote work options are available based on business needs....Remote workContract work$130.5k - $159.5k
...About the Role Information Security Manager at Colas USA Colas IS Support is the information technology arm of the North America business for... ...fosters a security‑conscious culture. Additional Details Remote work: Fully remote within the continental United States....Remote work- ...IT Strategy, Business Process Blueprints, Enterprise Architecture, Enterprise Transformation. Role: Information Security Manager Location: Remote Job Type: Contract Job Summary: Vulnerability Inventory and Baseline Establishment: Review...Remote workContract work
$100k - $115k
...Information Security Manager (260003O4) At the Center for Health Information and Analysis (CHIA), we serve as stewards of Massachusetts health data... ..., offering a hybrid model that balances in‑person and remote work. Our hybrid model includes working from our vibrant Boston...Remote workWork experience placementWork at officeFlexible hours2 days per week$119.2k - $146.6k
...Premier Group is seeking top talent to join our team as an Information Security Manager. The Information Security Manager is responsible for... ...to field service scheduling systems, mobile device usage, remote workforce access, geographically dispersed operations, and...Remote workWork at officeLocal area- ...Job Description Position Summary: The Information Security Manager will serve as San Ysidro Health’s expert on Cybersecurity protection, detection... ...and protocols Multi‑Factor Authentication, VPN and remote access methodology Experience handling, organizing, tracking...Remote workLocal areaWeekend workAfternoon shift
- ...mission. Position Summary: DMBA is looking for an Information Security SOC Manager to join the Information Security Team. The Information Security... ...the information security program Work in a hybrid remote work and office work environment What We Offer:...Remote workWork at office
$82.08k - $127.5k
...candidate's qualifications, experience, skills, education, and geographic location. JOB SUMMARY The Cybersecurity Manager is a key member of the Information Security team, directly supporting the Chief Information Security Officer (CISO) in the design, implementation, and...Remote workContract workWork at officeLocal areaFlexible hours- ...Information Security Manager As the Information Security Manager, you will lead the strategic development and oversight of our organization's cybersecurity program within a fast-paced software development environment. You will be responsible for defining security roadmaps...Remote workShift work
- ...opportunities using state-of-the-art technology. This is Hybrid role (4 days in office /1 day remote) About your Team: The Information Security Policy Manager develops, maintains, and communicates IBKR's information security policies aligned to regulatory requirements...Remote workWork at office
- ...WCG is seeking a Cybersecurity Manager in Cary, NC to support the Chief Information Security Officer in enhancing the organization's security framework. The role involves managing SOC 2 and ISO 27001 compliance and conducting governance activities. The ideal candidate...Remote workFull time
- ...States for more than 20 years. We produce world-leading Remote Weapon Systems (RWS) for the US Army, Marine Corps, and... ...Defense & Aerospace, Inc. is seeking a dedicated and vigilant Information Systems Security Manager (ISSM) to support our growing Toano, VA location. In...Remote workFull timeRelocationFlexible hours
- Baptist Health is seeking a Manager, Information Security, for a remote work position that requires residency in Kentucky or Indiana. The role involves overseeing the organization’s security operations and implementing security policies and compliance measures to safeguard...Remote job
- ...Solutions | Recruiting Expert We are currently hiring a Information Security Manager for our client HD Supply. This is a direct hire, full time... ...Consulting Director, DFIR, Reactive Services (Unit 42) - Remote Atlanta, GA $170,000.00-$240,000.00 1 week ago Identity...Remote workFull timeCurrently hiringNight shift
- ...A staffing solutions company in Cleveland is seeking an experienced Information Security Manager to oversee security projects and ensure the safety of data. The role involves managing IT security incidents, collaborating with various departments, and reporting on security...Remote workWork from homeFlexible hours
$150k - $190k
...Senior Cybersecurity Analyst / Information Security Manager We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security... ..., a group of Alaska natives from one of the most remote and harshest environments in the United States. For our...Remote workFull timeContract workPart timeFor contractors- ...specialists and customer-facing programme managers. We are looking for mission-driven... ...edge defence technology and classified information security, working on some of the most sensitive... ...of paid family emergency leave, 100% remote work option during pregnancy and phased...Remote workFull timeTemporary workWork at officeRelocationRelocation packageDay shift
- ...Information Security Program Manager (Remote US) Reporting to the regional Practice Manager of Customer Experience (CX), the Information Security Program Manager will be responsible for managing a portfolio of customers, and will be tasked with maintaining client satisfaction...Remote work
- ...position. Job Overview Support Cyber Security Operations. Essential Functions... ...documentation skills Ability to handle sensitive information with discretion Education /... ...world by providing full-spectrum aviation, remote sensing, and analysis solutions. The...Remote workFull timeWork at officeLocal area
- ...ITCON Services is looking for a bright, motivated Information Systems Security Manager (ISSM) with FMCSA (Federal Motor Carrier Safety Administration) experience to join our team. n Information Systems Security Manager (ISSM) is responsible for the overall...Remote work
- ...Description SAIC is seeking a hands-on Cybersecurity Information System Security Manager (ISSM) to support a part-time program within the... ...methodologies aligned with contract requirements. This is a remote / work from home position, approximately 10 hours per...Remote workContract workPart timeWork from home10 hours per week
$100k - $174k
...Information Systems Security Manager Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right... ...productivity. Based on business need, a few roles allow for “Remote” work on an exceptional basis. If you are applying for...Remote workWork experience placementWork at officeWork from homeRelocation package- AI, Security, Intelligence, and Risk Management Futurist | Security risk management strategy and program developer... ..., and cyber security experience. REMOTE positions available for stock... ...Employment type Full-time Job function Information Technology Industries: Software...Remote workFull time
$180k - $200k
...Everforth ECS is seeking a Senior Information System Security Officer (ISSM) to work out of the customer... ...Information System Security Manager (ISSM) to support DISA-owned Impact... ...This role operates in a hybrid onsite/remote capacity. The ISSM serves as the senior...Remote work1 day per week- ...Information System Security Manager (ISSM) The Information System Security Manager (ISSM) is responsible for overseeing the cybersecurity posture... ...shareholders, a group of Alaska natives from one of the most remote and harshest environments in the United States. For...Remote workFor contractors
- ...About the Job Information System Security Manager (ISSM) Falls Church, Virginia Full-time IMPORTANT NOTICE: This position is contingent... ...required at Suffolk Building, Falls Church, VA. No remote work options available. Standard business hours with...Remote workFull timeContract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Manager (Remote). Be the first to apply!
- remote design intern Cary, NC
- remote legal internship Cary, NC
- software engineer internship remote Cary, NC
- remote coding manager Cary, NC
- remote hotel sales manager Cary, NC
- data science remote Cary, NC
- remote customer service agent Cary, NC
- remote customer service advisor Cary, NC
- customer service associate remote Cary, NC
- localization project manager remote Cary, NC


