Information Security Manager
Sotheby's
Established in 1744, Sotheby’s promotes access and ownership of exceptional art and luxury objects through auctions, private sales and retail. Our deep expertise across 70 selling categories is supported by a leading technology platform and a global network of specialists spanning 40 countries. Selling categories include Contemporary Art, Modern and Impressionist Art, Old Masters, Chinese Works of Art, Jewelry, Watches, Wine and Spirits and Design, as well as collectible cars and real estate through RM Sotheby’s and Concierge. Sotheby’s Financial Services is a leading art lender and provides capital solutions for collectors around the world, having originated more than $12 billion in loans since its inception. Sotheby’s new global headquarters is now open at the iconic Breuer building at 945 Madison Avenue in New York City.
THE ROLE
As an Information Security Manager, you will be responsible for executing major components of Sotheby’s information security strategy, as well as helping to define it. Reporting directly to the CISO, you will be the driving force behind accomplishing key initiatives, while working closely with managers across the globe to balance achieving business objectives with managing risk.
Rather than being confined to a narrow role, you will be a utility player, moving between different areas as needed, for example: performing risk assessments and security reviews, procuring infosec tools, managing projects, drafting policies and processes, conducting risk management meetings, designing controls, overseeing auditors, and leading incident response. And as a key part of a team dedicated to continuous improvement, you will help us get better every day.
You obsess over getting the key facts nailed down. You have an attention to detail that some might call “extreme”. And you recognize the daunting challenge of managing information security at a historic and globally recognized brand, but that challenge excites you.
RESPONSIBILITIES
- Work with IT and business unit managers to drive security initiatives to completion
- Lead business continuity and disaster recovery planning and preparation projects
- Lead internal and external security audits, acting as the primary point of contact for auditors
- Draft, update, and enforce information security policies, processes, and standards
- Conduct third-party vendor risk assessments and internal security risk assessments
- Maintain risk registers, compliance dashboards, and reports for senior leadership
- Audit internal systems to verify compliance with mandatory security controls
- Develop policies, processes, and risk assessments aligned to top frameworks such as CIS, NIST, ISO 27001, and SOC 2
- Crosswalk and harmonize controls across multiple compliance frameworks
- Document security requirements, support control implementation, and help track remediation progress
- Build risk registers, support assessments, and monitor remediation progress
- Plan, lead, and execute control validation and testing activities across various domains (e.g., access management, vulnerability management, incident response, data protection)
- Mentor junior analysts and engineers, providing guidance on control validation methodologies and best practices while fostering a culture of accountability
- Document control issues and collaborate with stakeholders to develop remediation recommendations
- Develop and enhance control testing methodologies, procedures, and reporting mechanisms
REQUIRED QUALIFICATIONS
- At least five years of hands-on experience in information security roles
- Bachelor's or Master’s in computer science, engineering, or cybersecurity
- Deep understanding of information security fundamentals
- Proven ability to manage complex projects from conception to completion
- Ability to explain complex technical risks in simple, business-friendly language
- Ability to communicate clearly, precisely, and concisely
PREFERRED QUALIFICATIONS
- At least one active credential, such as CISA, CRISC, CISM, or CISSP
- Experience performing risk assessments across diverse systems including SaaS and mobile
- Deep knowledge of frameworks and standards such as CIS, ISO 27001, and NIST
- Experience leading incident response through a cyberattack or data breach
To view our Candidate Privacy Notice for the US, please click here.
To view our Candidate Privacy Notice for the UK, Hong Kong, France and Switzerland, please click here.
The Company is an equal opportunity employer and considers all applicants for employment without regard to race (including, without limitation, traits historically associated with race, such as natural hair, hair texture, and protective and treated or untreated hairstyles), color, creed, religion, sex, sexual orientation, marital or civil partnership/union status, national origin, age, disability, pregnancy, genetic predisposition, genetic information, reproductive health decision, sexual orientation, gender identity or expression, alienage or citizenship status, domestic violence victim status, military or veteran status, or any other characteristic protected by federal, state/province or local law. The Company complies with applicable state and local laws prohibiting discrimination in employment in every jurisdiction in which it operates.
#J-18808-Ljbffr$134.5k - $265.1k
Position Summary Data Privacy ManagerAs a Manager in Deloitte’s Digital Trust & Privacy practice, you will lead the discovery,... ...functional, and business requirements and establish use cases to inform future state architecture.Architect:Navigate complex IT...SuggestedLocal area$134.5k - $265.1k
...but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address evolving threats through integrated security strategies, technologies, and managed services. By advising on how to strengthen risk management, security...SuggestedContract workLocal areaVisa sponsorship$163.4k - $322.1k
...advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities... ..., investigations, emergency communications, case and incident management, and physical security technology. The Physical Security...SuggestedLocal areaVisa sponsorship$148.2k - $292.3k
...Summary As a Full Stack Engineer Manager in Deloitte Cyber’s Digital Trust &... ...communicate effectively with business, security, privacy, legal, and compliance stakeholders... ...degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent...SuggestedLocal areaVisa sponsorship$134.5k - $265.1k
...opportunities by delivering solutions and managed services that reduce complexity,... ...You will design, implement, and optimize secure, outcome-focused solutions while collaborating... ...in Computer Science, Cybersecurity, Information Systems, or another technical field, or...SuggestedLocal areaVisa sponsorship$105.4k - $207.8k
...an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support... ..., and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation, and...Local areaVisa sponsorship$134.5k - $265.1k
...landscape. Through powerful solutions and managed services that simplify complexity, we... ...with confidence, and proactively manage to secure success.Recruiting for this role ends on... ...Saviynt.Understand complex business and information technology management processes. Execute...Local areaVisa sponsorship- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry... ..., and brings a unique perspective to the team. Hiring Manager Title SVP, Security & CISO Functions ~ Information Technology...Remote work
$105.4k - $207.8k
...ownership in privacy-by-design initiatives, Consent & Preference Management, and AI governance efforts, and large-scale technology... ...functional, and business requirements and establish use cases to inform future state architecture.General awareness of global and domestic...Local area- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information... ...cloud platform microsoft azure cloud backup posture management (cbpm) enterprise cloud storage cloud solutions...
- ...Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry... ...include developing and maintaining a robust security program, managing security incidents, and ensuring compliance with relevant regulations...
$105.4k - $207.8k
Position Summary As a Physical Security Senior Consultant in Deloitte’s Cyber Defense... ...preparedness, and enterprise risk management intersect.Recruiting for this role ends... ...identify vulnerabilitiesDeveloping risk-informed recommendations and client deliverables...Local areaVisa sponsorship- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI... ...agility, public sector governance, and public company risk management. Key responsibilities include developing a security vision...
$155.6k - $306.8k
...operate with resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.Work... ...’s degree in Computer Science, Engineering, Information Technology, or a related field.Limited immigration sponsorship...Local areaVisa sponsorship$171.6k - $338.3k
...operate with resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.The... ...or GCPBachelor’s degree in computer science, Engineering, Information Technology, Data Science, Applied Mathematics, Physics, Statistics...Local area$134.5k - $265.1k
...feasibilityCapturing delivery learnings to inform reusable product and platform... ...to lead projects or workstreamsAbility to manage and prioritize multiple tasks in a fast-paced... ...cybersecurity concepts (e.g., application security, cloud security, identity, detection engineering...Local areaVisa sponsorship- ...based on company business needs.CW-Cyber Security Analyst IIIThe Sr. Info Security Analyst... ..., this job works independently to manage and monitor the organization's IT systems... ...security and safety of the organization's information.Key Responsibilities and DutiesEnsures implementation...Full time
- Cyber Security Analyst As a Cyber Security Analyst, your role on the team will include leveraging your knowledge of industry best practices... ...or related field, or equivalent work experience Five years of information technology experience with two years in an information...Work experience placementShift workAfternoon shift
- CW-Cyber Security Analyst III The Sr. Info Security Analyst drafts, communicates, implements... ..., this job works independently to manage and monitor the organization's IT systems... ...security and safety of the organization's information. Key Responsibilities and Duties Ensures...Work experience placement
$50 - $52 per hour
CW-Cyber Security Analyst III Immediate need for a talented CW-Cyber Security Analyst III... ...firewalls to conceal confidential information as it is being transmitted and to keep... ...Experience: Must have skills: Vulnerability Management, Governance, Risk & Compliance (GRC),...Contract workLocal areaImmediate start- ...on the Team: Designs, tests, and implements state-of-the-art secure operating systems, networks, and database products. Conducts risk... ...vulnerability analysis of various security technologies, and information technology security research. May prepare security reports to...
$102.17k
...transforming the way water resources are managed and protected. By combining cutting-edge... .... Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst,... ...veteran status, citizenship status, genetic information or any other characteristic protected by...Work experience placementH1b$144.9k - $265.8k
...- Cybersecurity - Identity and Access Management - Manager At EY, we are all in to shape... ...identity programs. Translating business, security and regulatory needs into practical... ...sound recommendations with incomplete information and build trusted relationships with clients...Summer holidayFlexible hours$134.5k - $265.1k
Position Summary Cyber Security & Risk Strategy ManagerOur Deloitte Cyber team understands... .... Through powerful solutions and managed services that simplify complexity, we... ...administration, public policy, cybersecurity, information systems, finance, economics, or a...Local areaVisa sponsorship- ...Deputy Chief Information Security Officer (CISO), Security Technology About the Company Popular provider of revenue cycle management solutions Industry Hospital & Health Care Type Privately Held, Private Equity-backed Founded 2003 Employees 1...
- ...of day-to-day cybersecurity engineering and defense. Assists Manager with completion of cybersecurity engineering activities,... ...functions include: Leads engineering and implementation of new information security systems and controls, delivering effective and pragmatic risk...Full time
$150.55k - $218.3k
...and standards for the collection, use, retention, sharing, and management of City data, and coordinating consistent practices across... ...or university with major coursework in public administration, information technology, public policy, data science, or a related field....Full timeContract workWork at officeLocal areaMonday to Friday- ...the unique environments our customers demand to solve national security problems in the real world. Our team of software and systems... ...growth and impact. You'll collaborate with Engineering, Program Management, Business Development as well as work with a group of world...Contract workFor contractorsWork at officeRemote workRelocation packageFlexible hours
$82.6k - $162.8k
...landscape. Through powerful solutions and managed services that simplify complexity, we... ...with confidence, and proactively manage to secure success.Recruiting for this role ends on... ...in Computer Science, Cyber Security, Information Security, Engineering, Information Technology...Local areaVisa sponsorship$82.6k - $162.8k
Position Summary Cyber Security & Risk Strategy Consultant Our Deloitte Cyber team... ...landscape. Through powerful solutions and managed services that simplify complexity, we... ...transformation servicesAssessing client cyber and information technology environments, including...Local areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Manager. Be the first to apply!
- data center security officer Portland, OR
- information security lead Portland, OR
- information security Portland, OR
- senior information security analyst Portland, OR
- sr information security engineer Portland, OR
- information technology security engineer Portland, OR
- entry level information security analyst
- information system security engineer
- data center security officer
- information security internship

