Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Manager

$115k - $125k

Acumen Technology

Acumen Technology is a security-first Managed Service Provider (MSP) founded in 2016, serving financial institutions, healthcare organizations, and other businesses that take IT and cybersecurity seriously. With more than 25 years of leadership experience in financial services technology, Acumen’s deepest roots are in community banks, credit unions, and regulated financial institutions, while also supporting clients in professional services, healthcare, and construction.

Acumen is SOC 2 Type II certified, FFIEC-aligned, and has been recognized on the Inc. 5000, CRN MSP 500/50 , and Nashville Business Journal’s Best Places to Wor k lists. Our vCISO practice provides hands-on security leadership to organizations that need more than guidance—they need execution.

Being part of the Acumen team means more than just great work. It includes weekly in-office lunches, memorable company events, a comprehensive benefits package, and, most importantly, training in the fine art of holding entire conversations using nothing but GIFs.

ROLE

This is a hands-on practitioner role. You will meet with clients, assess their security posture, and then do the work - drafting the policy, completing the risk assessment, building the remediation plan, and delivering it back to the client in a finished, usable form.

The right candidate thrives on the full cycle: client meeting → assessment → heads-down execution → polished deliverable back in the client’s hands

You will manage a portfolio of clients that is predominantly financial institutions - community banks, credit unions, and financial services firms make up approximately 80% of the practice. The remainder includes clients in professional services, healthcare, and construction.

On any given week, you might:

  • Spend a morning walking a community bank through their pre-exam request list, then spend the afternoon drafting their written response findings.
  • Design and facilitate a tabletop exercise for a bank's leadership team simulating a ransomware event, then write up the after-action report and deliver it within the week
  • Review vendor SOC 2 reports that came in for a client, assess the findings, and produce a risk summary the bank's risk committee can act on
  • Rewrite a client's outdated Acceptable Use Policy and Information Security Policy to align with current FFIEC guidance and have both ready for board approval
  • Lead a SOC 2 readiness check-in with a professional services client, update their evidence tracker, and coordinate with their external auditor on outstanding items

KEY RESPONSIBILITIES

Bank Exam & Audit Support

  • Serve as the primary point of contact for clients preparing for FDIC, OCC, NCUA, and state banking regulator IT examinations, owning the preparation process from start to finish
  • Organize and package audit requested items, complete pre-exam readiness checklists, and produce written summaries of control effectiveness that clients can hand directly to examiners
  • Review third-party audit findings and examination results, then draft formal written responses, corrective action plans, and remediation timelines on the client's behalf
  • Track open findings and recommendations to closure, producing status updates and evidence packages at each milestone
  • Maintain current knowledge of FFIEC IT Examination Handbook updates and translate regulatory changes into specific, actionable steps for each client
  • Document client check-ins using Microsoft Planner or a similar task management tool, ensuring all action items, deliverables, and blockers are clearly captured, assigned, and tracked through resolution.

SOC 2 Readiness

  • Lead clients through SOC 2 Type I and Type II readiness assessments including scoping, gap analysis, control testing, and evidence collection
  • Produce formal gap analysis reports with prioritized remediation roadmaps in finished, client-ready form
  • Build and maintain client control evidence libraries and audit packages, keeping documentation current between audit cycles
  • Coordinate with external auditors on the client's behalf and serve as the primary point of contact throughout the audit process

Tabletop Exercises

  • Design, facilitate, and debrief tabletop exercises for community bank clients covering security incident response, business continuity, and disaster recovery scenarios
  • Develop realistic, client-specific exercise scenarios based on current threat intelligence and regulatory expectations for financial institutions
  • Produce written after-action reports documenting exercise findings, gaps identified, and recommended improvements, delivered to the client within an agreed turnaround
  • Update client incident response, business continuity, and disaster recovery plans based on exercise outcomes

Third-Party & Vendor Risk

  • Review third-party vendor audit reports (SOC 2, penetration tests, security assessments) on behalf of clients and produce written summaries of findings and risk exposure
  • Draft formal vendor risk assessment responses and management memos that clients can file, present to examiners, or include in board reporting
  • Maintain client vendor inventories and assessment schedules, tracking due dates and ensuring assessments are completed on time

Security Policy Development

  • Draft, update, and maintain client information security policies, standards, and procedures written in plain language, tailored to each client's environment, and ready to adopt without further editing
  • Conduct periodic policy reviews against current FFIEC guidance, NIST CSF, and SOC 2 requirements and produce updated versions that reflect any gaps or regulatory changes
  • Manage client policy libraries to ensure all documents are versioned, reviewed on schedule, and accessible for audit purposes

Ongoing Client Engagement

  • Meet regularly with client stakeholders to review program status, prioritize the work queue, and present completed deliverables
  • Manage a multi-client portfolio with disciplined task tracking, clear timelines, and consistent follow-through on every commitment made in a client meeting
  • Serve as an advisory resource during client security incidents, providing written guidance on containment, notification obligations, and regulatory reporting requirements

Requirements

  • 3+ years of information security experience with a strong emphasis on hands-on program execution — risk assessments, policy writing, audit preparation, and control documentation
  • Deep, working knowledge of the FFIEC IT Examination Handbook requirements, including the new tools available to replace the retired Cybersecurity Assessment Tool (CAT)
  • Direct experience completing SOC 2 readiness assessments and producing formal gap analysis and remediation documentation
  • Demonstrated ability to author professional-grade security deliverables - policies, risk assessments, remediation plans, board summaries - independently and to a high standard
  • Strong written communication skills; comfortable producing polished, client-facing documents without editorial support
  • Proven ability to manage multiple client engagements simultaneously with discipline, reliability, and follow-through
  • Active CISSP, CISM, CRISC, or equivalent certification
  • Direct experience preparing financial institutions for FDIC, OCC, or NCUA IT examinations and responding to regulatory findings
  • Familiarity with GRC platforms commonly used in financial services (e.g., Ncontracts, LogicManager, or similar)
  • Working knowledge of HIPAA security rule requirements for healthcare clients and general compliance frameworks applicable to professional services environments
  • Experience with Microsoft 365 security controls as deployed in community bank and small-to-mid-market business environments
  • Background in an MSP, consulting firm, or multi-client security advisory practice

WHAT SUCCESS LOOKS LIKE

In your first 90 days:

  • Own and deliver at least two client engagements end-to-end — from intake meeting to finished deliverable — with high client satisfaction
  • Demonstrate consistent follow-through: every commitment made in a client meeting has a deliverable behind it
  • Establish your working rhythm and task management system for managing a multi-client portfolio

Within 12 months:

  • Carry a full client portfolio with strong retention and client satisfaction scores
  • Have guided at least one client through a table top exercise, 3rd party audit, a regulatory examination, or SOC 2 audit with documented, positive outcomes
  • Be the person clients call not just for advice, but because they know something finished will come back to them

Benefits

  • Annual salary between $115,000 - 125,000 depending on fit and experience.
  • 100% employer paid health insurance (medical and dental) and first $1,000 of qualified medical expenses covered
  • Company Matching 401k
  • Flexible hybrid schedule
  • Fun working environment and culture with regular activities both for employees and their families
  • Family vacation bonus at 5th year

WHY ACUMEN TECHNOLOGY

  • Security-first MSP founded in 2016, led by co-founders with 20+ years of financial services technology experience, not a feature bolted onto an IT company
  • Established credibility in financial services and community banking across the Nashville region and beyond
  • SOC 2 Type II certified, FFIEC-aligned, Inc. 5000 and CRN MSP 500/501 recognized
  • A real client portfolio ready for you - not a build-it-from-scratch assignment
  • A Leadership Team that is accessible, decisive, and invested in the success of this role
  • Consistently recognized as a Best Place to Work by Nashville Business Journal
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Information Security Manager in Nashville, TN vacancy
  •  ...The Information Security Manager position is an exciting role for the right candidate with technical know-how and leadership qualities who is eager to drive security initiatives from start to finish. This position presents opportunities to advise on our client's global... 
    Suggested

    Sebenza LLC

    Nashville, TN
    20 hours ago
  • A leading security solutions firm is looking for an Information Security Manager to drive security initiatives globally. The role requires a deep technical understanding of security architecture, leadership, and the ability to negotiate across competing priorities. Candidates... 
    Suggested

    Kinsley Power Systems

    Nashville, TN
    20 hours ago
  • $78.53k - $124.36k

     ...Therefore, you may be required to provide information about your criminal history in order to...  ...maintain and lead enforcement of data management policy, framework, and standards for TN...  ...and documentation to maintain data security and privacy. Support the development... 
    Suggested
    Work at office
    Local area

    State of Tennessee Jobs

    Nashville, TN
    4 days ago
  • $190k

     ...Software, Cybersecurity, and Technology Risk Management. Our Tech Advisory and Delivery Chapter...  ...our BCG Culture and Values for more information. BCG Platinion's presence spans...  ...functional stakeholder groups to existing security teams. You're Good At:... 
    Suggested
    Work at office

    Boston Consulting Group

    Nashville, TN
    4 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Mission-driven online provider of musculoskeletal therapy Industry Health...  ...millions. The CISO will be responsible for developing and managing a global security strategy and program, with a focus on... 
    Suggested

    Confidential

    Nashville, TN
    1 day ago
  •  ...Virtual Chief Information Security Officer (CISO) About the Company Flourishing provider of market research & business intelligence services...  ...enterprise cybersecurity programs. Strong governance, risk management, and executive communication skills are essential, as is... 
    Part time

    Confidential

    Nashville, TN
    4 days ago
  • $247k - $325k

     ...digitally transforming firm? Cherry Bekaert is seeking a Chief Information Security Officer (CISO) to shape and execute a strategic security...  ...security into all technology and business decisions. Assess and manage information security risks through a detailed risk register... 
    Work experience placement
    Local area

    Cherry Bekaert

    Nashville, TN
    1 day ago
  •  ...Chief Information Security Officer (CISO) About the Company Accomplished executive search firm Industry Staffing and Recruiting...  ...of security policies, procedures, and standards, as well as managing security awareness and training programs. The CISO will also... 

    Confidential

    Nashville, TN
    2 days ago
  • $106.61k - $284.28k

     ...Resiliency Specialist to drive strategies in cybersecurity for their Digital, Data, Analytics & Technology team. Responsibilities include managing processes for resilience activities, developing audits, and providing compliance education. Required qualifications include 7+... 

    Hispanic Alliance for Career Enhancement

    Nashville, TN
    3 days ago
  • $106.61k - $284.28k

    CVS Health is seeking a Cyber Resiliency Manager to oversee operational activities and strategic direction for cyber resiliency within its Digital, Data, Analytics & Technology Cybersecurity team. Candidates should have over 7 years of experience in cyber resiliency and... 
    Full time

    Koitecc Solutions

    Nashville, TN
    2 days ago
  • Trellix is seeking a Competitive Intelligence Manager in Nashville, Tennessee. This role involves transforming market data into actionable insights, monitoring competitors, and providing strategic analysis to executive teams. The ideal candidate should have over 3 years... 

    Trellix

    Nashville, TN
    1 day ago
  •  ...solutions to address the needs of a broad range of customers and industries. Job Category Information Technology Position Summary The Senior Manager, Cyber Security Engineering for Manufacturing & Retail Security establishes and governs safeguards for... 
    Temporary work
    Local area

    Bridgestone Americas

    Nashville, TN
    3 days ago
  • ITCON Services is seeking an experienced and highly skilled Information Security Analyst / ISSO to support a new program for the Client, in...  ...knowledge of federal cybersecurity standards, vulnerability management, cloud security, and the Risk Management Framework (RMF).... 
    Permanent employment

    Creative Solutions Services, LLC

    Nashville, TN
    20 hours ago
  • $20 per hour

     ...Title: Temporary - Cyber Security Analyst POSITION SUMMARY Under the directive of the Information Security Officer, the cyber security analyst will implement security strategies and best practices in accordance with regulatory standards. ESSENTIAL... 
    Hourly pay
    Temporary work
    Flexible hours

    The Tennessee Board of Regents

    Nashville, TN
    3 days ago
  • $168.09k

     ...to safeguard and protect private and personally identifiable information you submit. The information that you submit will be...  ...of the system. Job Description: At Regions, the Cyber Security Manager is responsible for leading a diverse team of engineers and analysts... 
    Full time
    Work at office
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    3 days per week

    Regions Bank

    Nashville, TN
    5 days ago
  •  .../ Telephony Engineer in Nashville, TN. In this role, you will manage the CCaaS environment, ensuring seamless call routing for critical...  ...include designing IVR menus, administering voice security, and providing technical support for telecom systems. Candidates... 

    ITCON Services

    Nashville, TN
    20 hours ago
  • $70.3k

    Job Description At Regions, the Cyber Security Analyst is responsible for analyzing, identifying...  ...support a feedback loop related to information and events to identify and support the...  ...using Security and Incident Event Management (SIEM) systems. Understanding of MITRE... 
    Full time
    Work at office
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work
    3 days per week

    Regions Bank

    Nashville, TN
    3 days ago
  • $87.7k - $164k

    Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider...  ...and assessment on perceived security threats Maintain, manage, improve and update security incident process and protocol documentation... 
    Summer holiday
    Local area
    Flexible hours

    Ernst & Young Oman

    Nashville, TN
    1 day ago
  • $105.79k - $141.05k

     ...network and connected ecosystem. We enable secure, high‑performance connectivity across...  ...(Audit) is an experienced member of the Information Security Compliance and Audit team with...  ...and as an experienced member of a team to manage the execution of multiple security... 
    Temporary work
    Remote work

    Lumen Inc

    Nashville, TN
    2 days ago
  • $207.95k

    Job Description At Regions, the Cyber Security Group Manager is responsible for leading a diverse team of managers, engineers and analysts...  ...Requirements Bachelor's degree in Computer Science, Management Information Systems, or related technology or business area Fifteen (1... 
    Full time
    For contractors
    Work at office
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    3 days per week

    Regions Bank

    Nashville, TN
    4 days ago
  • $144.9k - $265.8k

     ...Entra, Okta, Ping, Saviynt Design cloud security and IAM architectures for Azure, AWS,...  ...authentication, authorization, identity management) Design and re‑engineer processes for...  ...identity/expression, pregnancy, genetic information, national origin, protected veteran... 
    Work experience placement
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Nashville, TN
    4 days ago
  • $104k - $156k

     ...Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security,...  ...~ Partner with IT on device management, deployment, and lifecycle security...  ...~ Bachelor's in Computer Science, Information Security, or equivalent experience.... 
    Remote work

    Relativity

    Nashville, TN
    4 days ago
  • A prominent tire and rubber company is seeking a Senior Manager, Cyber Security Engineering for Manufacturing & Retail Security. The role involves establishing and governing cybersecurity measures for IT systems in manufacturing and retail environments. A focus on compliance... 

    Bridgestone Americas, Inc.

    Nashville, TN
    20 hours ago
  • The Director of IT Operations & Security is accountable for reliable, scalable day-to-day IT operations across QualDerm’s multi-state...  ...clinics and corporate teams: incident, request, problem, and change management. Lead service desk performance (triage quality, first-contact... 
    Full time
    Temporary work
    Immediate start
    Remote work

    QualDerm Partners, LLC

    Brentwood, TN
    4 days ago
  • $40 per hour

     ...A cybersecurity training firm is seeking experienced professionals to evaluate AI-generated security content and provide feedback to enhance AI systems. Responsibilities include solving technical cybersecurity problems and writing clear technical explanations. The position... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Nashville, TN
    4 days ago
  • $85k - $95k

     ...environment. We also specialize in helping organizations engineer secure clouds to meet FedRAMP's demanding requirements. Job...  ...assessing and analyzing cybersecurity documentation for client information systems. You'll apply your scripting skills to develop and improve... 
    Remote work
    Relocation

    Motorola Solutions

    Nashville, TN
    2 days ago
  • $85k - $95k

    Motorola Solutions is looking for a Cybersecurity Analyst in Nashville, TN. The successful candidate will assess cybersecurity documentation and develop automations to enhance processes. This role demands a Bachelor's degree in a related field and at least 1 year of experience...

    Motorola Solutions

    Nashville, TN
    2 days ago
  • A leading cybersecurity company is seeking a Solutions Consultant to provide technical leadership and expertise in cybersecurity solutions. This role involves defining technical solutions, driving customer adoption, and leveraging strong communication skills to present ...
    Full time

    Palo Alto Networks

    Nashville, TN
    20 hours ago
  • Palo Alto Networks is seeking a Solutions Consultant to drive customer success in cybersecurity transformation. This role involves providing technical leadership, developing customer relationships, and delivering presentations to influence key stakeholders. Applicants should...
    Remote job

    Palo Alto Networks

    Nashville, TN
    4 days ago
  • $18 per hour

     ...Unarmed Security Licensed Officer - Antioch Area Antioch, TN Marksman Security is built on serving our clients and building careers – just like yours. We are trusted by some of the most well-known companies and properties in the country while remaining dedicated... 
    Bi-weekly pay
    Temporary work
    Shift work

    Marksman Security

    Antioch, TN
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Manager. Be the first to apply!