9,640 Cism jobs in the United States
Information Security Manager
Posted today
Job Viewed
Job Description
The Information Security Manager reports to the Chief Information Security Officer (CISO) and supports the implementation of security strategy that ensures Holland & Hart complies with applicable client, legal, and regulatory security requirements while safeguarding Holland & Hart's facilities and information systems. The Information Security Manager supports in the implementation of the strategy, operations and budget of the architecture, design, and implementation of IT projects to ensure availability, confidentiality, and data integrity. The Information Security Manager manages the threat landscape within Holland & Hart and designs and implements security measures tailored to address threats in a timely, efficient, and risk-managed method. The Information Security Manager is a formal contributor in enterprise-wide risk assessments and champion in security control implementation.
Essential Duties/Responsibilities:
- Drives the development and implementation of strategic, long-term information security strategy and roadmaps to ensure Holland & Hart's information assets are adequately protected.
- Critical decision maker on designated information security committees, including analyzing and managing firm risk and tracking remediation.
- Oversees incident response planning and the investigation of security breaches.
- Leads IT Security incident response. Collaborates with analysts performing incident response and remediation. Handles incident response communications within team.
- Works with employees across the firm to assess and communicate and make recommendations regarding acceptable levels of risk.
- Manages ISO 27001 certifications including evidence collection and presentation to certification bodies.
- Manages and responds to client audits and security reviews, negotiating best practices, mitigating controls, and implementing new security measures. Presents security evidence to clients to demonstrate compliance.
- Assists the CISO in maintaining the budget and operational focus of the team.
- Provides subject matter expertise on security standards and best practices.
- Oversees the implementation of Access Control solutions.
- Manages individuals within Access Control team.
- Develops and mentors information security and technology professionals.
- Develops and recommends regulatory changes on information security policies, procedures, standards and guidelines, and oversees their approval, dissemination, and maintenance.
- Ensures that the security management program is compliant with applicable laws, regulations, and contractual requirements.
- Oversees and may provide hands on support for the evaluation, selection and implementation of information security solutions that are innovative, cost-effective, and minimally disruptive.
- Partners with software developers, infrastructure, and applications teams to ensure that technologies are developed and maintained according to security policies and guidelines.
- Monitors the industry and external environment for emerging threats and advise relevant stakeholders on appropriate courses of action.
- Liaise with law enforcement and other advisory bodies to ensure that the organization maintains a strong security posture.
- Leads one or more phases of large-complexity projects.
- Strategic Thinking: Plans and makes decisions within the framework of the firm's strategic intent.
- Team Management & Results Orientation: Creates and maintains high functioning team(s).
- Communication: Understands the importance of and demonstrates verbal, written, and non-verbal communications.
- Customer/Client Experience: Creates a consistent and exceptional experience for others, whether directly to external clients/customers or indirectly through internal support, that elevates the overall perception of the firm.
- Develop and nurture a working environment that prioritizes inclusivity and a client-centric approach. Recognize and reward strong performance, teamwork, professionalism, and responsiveness. Instill confidence within the team and among the firm's professionals by celebrating hard work and success. Set clear and achievable expectations for future success.
- Effectively organize and oversee the scheduling, workload distribution, and productivity of the team to ensure efficient operations.
- In collaboration with the department head and in accordance with company policy, make informed hiring and selection decisions to build a high-performing team.
- Deliver timely and constructive performance feedback. Complete performance evaluations that help team members grow and improve.
- Actively coach, develop, and train team members to ensure they meet and exceed departmental expectations and perform their duties effectively.
- Review and approve timecards and vacation requests for direct reports, ensuring compliance with organizational policies and procedures.
- Efficiently manage daily responsibilities in alignment with departmental goals and objectives.
- With the assistance of HR and the department head, manage employee discipline and, when necessary, termination in accordance with company policy and legal guidelines.
- Bachelor's degree with technology is preferred, or applicable years of direct experience.
- Minimum 10 years of IT experience with a focus on IT Security.
- 2 years of management experience is preferred.
- At least one relevant industry certifications such as GCIH, GCED, CISSP, CISA, CISM, etc.
- Possesses an excellent knowledge and background in IT operations, security technologies and regulations.
- Must be collaborative, creative, and driven with a proven ability to be a team player
- Able to think strategically, develop solutions quickly and implement efficiently.
- Possesses business acumen and understands budgets, business-planning and balancing security and business risk.
- Skilled in conducting security reviews, audits, and analyses.
- Excellent verbal, written, and overall communication skills and ability to communicate effectively at all firm levels.
- Leadership and organizational abilities.
- Detailed oriented to ensure that the success of implementations is paramount.
- Strong analytical skills.
- Self-starter with the ability to multi-task and work in a very fast paced environment.
- Results oriented and with a strong client focus.
Physical Requirements:
While performing the duties of this position, the employee must have the ability to sit, stand and/or walk for extended periods of time; manipulate (lift, carry, move) weights of at least ten (10) pounds; have repetitive wrist/hand/finger movement to work on a computer and/or related office equipment; speak clearly and concisely so listeners can understand; and regularly understand the speech of another person.
The physical demands described here are representative of those that must be met by this position to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Work Environment:
Professional office atmosphere. Sedentary work that primarily involves sitting or standing for prolonged periods. Position may require occasional off-hour meetings and events.
The work environment characteristics described here are representative of those this position may encounter while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Note: This job description is intended to convey information essential to understanding the scope of the job and the general nature and level of work performed by job holders within this job. However, this job description is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position.
Holland & Hart offers of employment take into consideration a candidate's education, training, and experience, as well as the position's work location, external market and internal value, including seniority and merit systems, and internal pay alignment when determining the salary level for potential new employees. A discretionary bonus may be available based upon performance. The Colorado salary range is $125,317 to $208,862 annually. A discretionary bonus may be available based upon performance.
The application window is anticipated to close on or after Sunday, August 31, 2025.
Holland & Hart works hard to promote work/life balance with a 37.5 -hour scheduled work week for most staff employees, a robust wellness program, and generous PTO and holiday pay for eligible employees. Full-time employees become eligible for benefits on the date hire, with a benefits offering that includes medical, dental, vision, life, AD&D, EAP, STD, and LTD. Also available are voluntary income protection benefits such as supplemental life, accident, critical illness, and long-term care insurances, as well as a 401(k)-retirement plan with a company match. In addition, the firm has programs that may provide for educational assistance, free or discounted legal services, and opportunities through the Holland & Hart Foundation, which is a non-profit organization dedicated to creating volunteer opportunities for lawyers, staff, families, and friends of Holland & Hart LLP. Part-time employees may have access to some of these benefits, which may be on a pro-rated basis.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Information Security Manager
Posted today
Job Viewed
Job Description
Position Overview:
180 medical/HSG IT is looking for an experienced Information Security Manager who works independently, ensures information is protected (confidentiality, integrity, and availability) and applies practical knowledge of job obtained through education and work experience.
This role will:
- Define Information Security Risks
- Develop infosec policies, standards, and control frameworks to mitigate these risks.
- Deploy and manage information security controls.
- Investigate and enforce information security policies.
- Assist with obtaining and maintaining security certifications.
Key Responsibilities:
- Manage information security management system (ISMS).
- Identify and document information assets containing sensitive data and ensure access reviews of critical systems.
- Identify information security risks.
- Protect classified information.
- Assurance over partners (IT outsourcers and SAAS)
- Maintain retention policy and register.
- Identify, report and governance over information security risks.
- Manage DLP policy and respond to alerts.
- Monitor intended leavers for potentially risky behaviors.
- Monitor and investigate data leakage incidents.
- Implement and manage eDiscovery and Litigation Hold
- Fulfil eDiscovery and litigation hold requests and annual reviews.
- Manage information security awareness plan, deliver, and maintain information security awareness training.
- Automate collection and insertion into consolidated centralize evidence hub(Diligent as example)
- Ensure near misses and policy breaches are followed upon as necessary (with training)
- Conduct Phishing Campaigns.
- Provide security awareness and compliance metrics demonstrating effectiveness of awareness plan.
- Identify infosec risks across projects and business processes.
- Information protection across key systems.
- Provide requirements for projects to mitigate information security risks.
- Perform initial vendor assessment and ongoing assurance over key vendors and service providers.
- Assist in implementing the Information security strategy across 180 medical/HSG.
Qualifications/Education:
- Knowledge of network infrastructure, including routers, switches, firewalls, moderate Database query abilities and associated network protocols and concepts.
- Strong verbal and written communication skills
- Ability to facilitate cross-functional teams.
- Ability to translate business requirements into control objectives.
- Knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls.
- Ability to work independently with limited supervision.
- Ability to demonstrate that you can influence others (key stakeholders including business) through explanation of facts, policies, and practices.
- Bachelor's degree in computer science, Information Systems, Software Engineering, or equivalent experience
- CISA and/or CISM
- Experience in NIST Cyber Framework
- Minimum 10 years of overall experience in IT
- Minimum of four years experience in Information Security
- CISSP is reccomended but not required.
Physical Demands
- Regularly required to sit, stand, walk, and occasionally bend and move about the facility.
- Infrequent light physical effort required.
- Occasional lifting up to 30 lbs.
- Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Working Conditions
- Work performed in an office environment,
Special Factors
- This role can be performed remotely.
Beware of scams online or from individuals claiming to represent Convatec
A formal recruitment process is required for all our opportunities prior to any offer of employment. This will include an interview confirmed by an official Convatec email address.
If you receive a suspicious approach over social media, text message, email or phone call about recruitment at Convatec, do not disclose any personal information or pay any fees whatsoever. If youre unsure, please contact us at
Equal opportunities
Convatec provides equal employment opportunities for all current employees and applicants for employment. This policy means that no one will be discriminated against because of race, religion, creed, color, national origin, nationality, citizenship, ancestry, sex, age, marital status, physical or mental disability, affectional or sexual orientation, gender identity, military or veteran status, genetic predisposing characteristics or any other basis prohibited by law.
Notice to Agency and Search Firm Representatives
Convatec is not accepting unsolicited resumes from agencies and/or search firms for this job posting. Resumes submitted to any Convatec employee by a third party agency and/or search firm without a valid written and signed search agreement, will become the sole property of Convatec. No fee will be paid if a candidate is hired for this position as a result of an unsolicited agency or search firm referral. Thank you.
Already a Convatec employee?
If you are an active employee at Convatec, please do not apply here. Go to the Career Worklet on your Workday home page and View "Convatec Internal Career Site - Find Jobs". Thank you!
#J-18808-LjbffrInformation Security Manager
Posted 1 day ago
Job Viewed
Job Description
This position supports the Medical Faculty Associates (“MFA”) including but not limited to assessing potential and actual risk to MFA data, business and IT infrastructures that support its clinical, academic, research, and administrative functions. The position ensures collaborative outcomes with external vendors, affiliates, and partners with internal and external stakeholders to improve processes, mitigate risks, and remediate vulnerabilities related to IT governance, risk, and compliance. This role requires hands-on experience to implement, configure, optimize, and maintain various security tools, and partner with team members to architect security solutions on emerging technologies for the organization.
Job Description
- Conduct detailed security and third-party risk assessments to ensure projects and initiatives align with MFA compliance policies, standards, and procedures as well as HIPAA, HITRUST, HITECH and other government and medical agencies regulations
- Recommend remediation strategies including risk-based prioritization of action items and identification of mitigating controls; as well as evaluate, develop, and recommend new information security assessment tools/techniques
- Develop HIPAA-related training and awareness
- Collaborate with key stakeholders to identify, manage, and track risks
- Build and enhance existing security operations capability
- Develop and implement security policies, standards and in line with HIPAA and to ensure enterprise-wide risk mitigation
- Contribute to and develop best practices, strategies, methodologies, and documentation/templates
- Support and coordinate compliance focused units and programs
- Mentor and train team on information security
- Experience in hybrid environments involving hybrid on-premises and public / private cloud as well as numerous vendor specific SaaS solutions
- Participate in 24x7 on call rotation for Information Security
- The omission of specific duties does not preclude the supervisor from assigning duties that are logically related to the position.
Education
- Bachelor’s in computer science or equivalent preferred or related experience.
- CISSP, SANS certifications, CISA, CISM or Security+ preferred
- Familiar with HIPAA security rules, NIST cyber security standards, and PCI requirements
- Understands information security best practices and security frameworks
- Experience with enterprise security operations
- Experience with virtual and cloud environment
- Familiar with Electronic Health Record systems, PACS and connected medical devices
- Experienced in hands-on implementation, operation, and maintenance of various security tools
- Ability to complete security assessments and projects independently
- Change and project management experiences preferred
Competencies
Must be able to understand IT hardware, software, network, and technical concepts. Must be able to maintain confidentiality in regard to information processed, stored, or accessed by the systems is required. Must be motivated and a self-starter. Must have excellent verbal and written communication skills, and proficient in writing technical specifications. Must be able to respect different values, and work with people from different cultures and background in a professional manner. Must be able to follow and understand instructions and react favorably in all work situations. Must have strong interpersonal skills, maintain core principles but adaptable and flexible in various situations.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
Information Security Manager
Posted 2 days ago
Job Viewed
Job Description
Information Security Manager page is loaded
Information Security Manager Apply locations New York posted on Posted 30+ Days Ago job requisition id JR101623Job Overview:
As CureMDs Information Security Manager, you will oversee the development, implementation, and management of a strategic, comprehensive enterprise information security and IT risk management program tailored to the demands of healthcare IT. You will demonstrate strong proficiency in healthcare IT information security standards, including but not limited to HIPAA, NIST, HITRUST CSF, FedRAMP, ISO/IEC 27001, PCI DSS, and other relevant standards/regulations, ensuring our organization meets compliance requirements effectively.
Job Responsibilities:
Manage and execute a strategic enterprise information security and IT risk management framework, focusing on healthcare IT information security standards.
Collaborate with business units to conduct risk assessments and manage risk, ensuring seamless integration of policies and standards across technology initiatives, systems, and services.
Provide direction to the information security team, ensuring robust measures to protect patient data and organizational assets against current and emerging threats.
Build partnerships across the company to promote risk management awareness and practices.
Implement strategies for risk assessment and mitigation, safeguarding the organizations assets and ensuring business continuity and disaster recovery.
Maintain security processes and policies to ensure compliance with local and national health, privacy, and safety regulations.
Foster a culture of security awareness through training programs and effective communication to minimize risks and liabilities across informational, physical, and financial domains.
Research and deploy advanced security solutions with a focus on AI-related risks.
Work with executive leadership to develop budgets supporting security programs, contributing to a multi-year cybersecurity roadmap with clear goals, strategies, and metrics.
Mentor and guide a skilled security team, fostering cross-functional collaboration, service excellence, and continuous improvement.
Manage critical security functions such as Incident Response, Third-Party Security Assessment, Identity & Access Management, and Privileged User Access.
Support governance and control strategies for emerging technologies, including cloud and distributed computing, staying ahead of developing security threats.
Ensure cyber compliance through collaboration with the Cyber Security Governance Committee (CSG) and Audit Committee.
Prepare and report on the organizations information security posture to Senior Management and stakeholders.
Qualifications:
Bachelors degree in Engineering, Cybersecurity, or related field (Masters preferred).
Hands-on technical experience in health IT risk management with a strong understanding of applicable standards such as HIPAA, HITRUST, and StateRAMP etc.
Proven leadership in implementing and auditing information security programs.
Strong analytical, problem-solving, and collaboration skills.
Relevant certifications (e.g., CISSP, CISM) are desirable.
Compensation and Benefits:
Salary range $125,000 - $140,000.
Comprehensive medical, dental, and vision insurance.
Up to 4% employer match for 401(k).
Commuter benefits and flexible spending account (FSA).
Generous paid time off (PTO) and paid holidays.
Hybrid schedule in a brand-new officelocated in the heart of the Financial District.
Social events such as happy hours, birthday celebrations andcompany-sponsored lunches with Grubhub.
Opportunities for professional development and career growth.
The Difference Youll Make:
At CureMD, every role, whether senior or junior, plays a pivotal part in transforming healthcare. By joining our innovative team, youll contribute to groundbreaking technology that directly impacts patient care, enhances healthcare efficiency, and saves lives globally. Your skills and passion will drive meaningful change, helping us deliver solutions that support healthcare professionals in critical, real-time settings. Together, were not just advancing technology were making a tangible difference in peoples lives. Together, lets save lives.
#LI-RL1
#LI-Onsite
#J-18808-LjbffrInformation Security Manager
Posted 2 days ago
Job Viewed
Job Description
Manage information security management system (ISMS). Identify and document information assets containing sensitive data and ensure access reviews of critical systems. Identify information security risks. Protect classified information. Assurance ove Security, Manager, Information, Manufacturing, Technology, Business
Information Security Manager
Posted 3 days ago
Job Viewed
Job Description
At ValidaTek, we modernize and optimize IT services to solve some of the most critical challenges facing federal civilian and defense agencies. From customers to partners to top-talent employees, ValidaTek puts people first, empowering them to exceed expectations and transform government organizations. Our success starts and ends with our people, so we built a company where great people can do great things, with the resources and autonomy to make decisions that transform organizations. We operate as one team of diverse people, united by a passion for continuous growth and optimization. Our commitment to quality and performance optimization is the reason why our IT Service Projects and New Development Projects have been appraised at CMMI Maturity Level 5, positioning us as one of a handful of elite companies to receive the highest form of third-party validation.
We are seeking an experienced Information Security Manager to support a Defense Information Systems Agency (DISA) Cyber Program. The ideal candidate will oversee security operations, compliance, risk management, and cyber defense initiatives to protect DoD networks and information systems. This role requires strong leadership, technical expertise, and an understanding of DISA policies and cybersecurity frameworks. Primary place of performance will be Pensacola, FL where an on-site presence is required.
ResponsibilitiesLead and manage cybersecurity efforts for the DISA Cyber Program, ensuring compliance with DoD and DISA security requirements.
Develop, implement, maintain, and ensure compliance with information security policies, standards, and procedures in accordance with NIST, RMF, and other relevant frameworks.
Oversee risk management and vulnerability assessment processes to identify, assess, and mitigate security threats.
Conduct security audits, assessments, and incident response activities to protect sensitive information.
Coordinate with internal and external stakeholders, including government officials, contractors, and cybersecurity teams, to enhance security posture.
Serve as the primary liaison between the organization and external security assessors or auditors.
Oversee system risk management, vulnerability assessments, and mitigation strategies.
Monitor emerging cyber threats and recommend proactive defense strategies.
Provide leadership and mentorship to security personnel, fostering a culture of continuous improvement and security awareness.
Manage security tools, technologies, and processes, ensuring alignment with mission requirements.
Develop and deliver reports, briefings, and security recommendations to senior leadership.
QualificationsBachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
Minimum of 8+ years of experience in information security, with at least 3 years in a managerial role.
Active DoD Secret clearance required.
ITIL certification preferred.
Strong knowledge of DoD cybersecurity policies, including DISA STIGs, RMF, NIST 800-53, and Zero Trust Architecture.
Experience with security tools such as SIEMs, IDS/IPS, vulnerability scanners, and endpoint protection solutions.
Experience with categorization and assignment of security controls and creation and maintenance of A&A packages in DISA's Enterprise Mission Assurance Support Service (eMass) system.
Proven ability to manage cyber incidents, security assessments, and compliance efforts.
Exceptional communication skills and the ability to engage with technical and non-technical stakeholders.
Active CISSP, CISM, or equivalent DoD 8570 IAM Level III certification.
Preferred Qualifications:
Experience working with DISA, DoD Cyber Operations, or similar environments.
Familiarity with cloud security (AWS, Azure, DoD Cloud environments).
Hands-on experience with automation and orchestration tools for security operations.
Knowledge of Zero Trust and AI-driven cybersecurity solutions.
Posted Min Pay RateUSD $130,000.00/Yr.
Posted Max Pay RateUSD $160,000.00/Yr.
Salary DisclosureActual salary will be based on a variety of factors including but not limited to experience, geographic location, contract affordability, internal equity, education, and certifications. The upper end of the salary range may be reserved for individuals who have demonstrated tenure with the company, seniority, and proven excellent performance. This includes factors such as education, certifications, and extensive/unique experience beyond what is required.
EEO StatementValidaTek is an Equal Opportunity Employer. All qualified applicants will be considered without regard to disability, protected veteran status, or any other status protected by federal, state, or local laws. Applicants who are selected for employment will be required to verify authorization to work in the United States. Offers of employment will be contingent upon passing a post-offer background check.
Information Security Manager
Posted 3 days ago
Job Viewed
Job Description
Saab is seeking a Manager, Information Security to join our team in East Syracuse, NY. This individual will oversee information assurance activities for Saab's classified and corporate environments ensuring compliance with the National Industrial Security Program, Cyber Security Maturity Model Certification (CMMC), and International Standards Organization (ISO) standards. The Information Security Manager will provide expert advice in evaluating and designing security solutions and working with technicians throughout the company in implementing, maintaining, and constantly improving the information security practice. The right individual should be well organized with the ability to work cross functionally in a fast-paced environment.
Key Responsibilities- Development and maintenance of internal policies and procedures and incorporate industry best practices.
- Develop and maintain system security plans, risk assessments, and other Risk Management Framework related artifacts.
- Resolving vulnerabilities identified during security scans, apply required patches and Security Technical Implementation Guides (STIGs), performing self-assessments, and support third-party SCA assessments.
- Preparation of documentation to include Systems Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs)
- Planning, designing, and building security architectures that meet DoD/ISO/NIST/CMMC requirements in coordination with IT.
- Managing requirements for network and computer security and ensures compliance with corporate cybersecurity policies and procedures.
- Defining cybersecurity requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related network devices.
- Conducting risk assessments.
- Responding immediately to cybersecurity-related incidents across multiple teams and providing a thorough post-event analysis.
- Investigate intrusion incidents and conduct forensic investigations.
- Investigating security alerts to determine applicability to the environments.
- Interfacing with various government/customer representatives.
- Participation in internal proposal efforts related to cybersecurity/IA requirements.
- Manage and update the Information Security Awareness program.
- Performing security assessments based on NIST and contractual requirements.
- Participating in selection and operation of security infrastructure including vulnerability management, SEIM solution, incident response tools, etc.
- Manage team of information/cyber security professionals.
Compensation Range: $146,800-$190,800 The compensation range provided is a general guideline. When extending an offer, Saab, Inc. considers factors including (but not limited to) the role and associated responsibilities, location, and market and business considerations, as well as the candidate's work experience, key skills, and education/training.
Skills and ExperienceProven ability to network with key stakeholders outside of the security team and adapt communication style to persuade and advise others on security matters. Can lead cross-functional teams and interact effectively with various departments to achieve security objectives. Ability to present results/content to customers (internal or external) or other stakeholders. Ability to apply broad and in-depth professional knowledge to resolve complex security issues and develop new policies and procedures. Proficient in creative problem-solving and offering solutions that align with organizational objectives. Ability to analyze complex security situations and make strategic decisions based on detailed evaluations of data and risk factors. Capable of exercising independent judgment in selecting the appropriate methods and techniques for addressing multifaceted security issues. Experience performing DoD ACAS scans. Experience developing, applying, and assessing secure technical baselines for various applications and products (i.e., Windows OS, Linux OS, firewalls, switches, etc.) Strong knowledge of NIST Standards relating to information technology, cybersecurity and risk management Strong knowledge of RMF and its implementation as related to the Department of Defense (i.e. STIGs, ACAS, etc.) Ability to work under pressure and meet deadlines while managing complex security challenges is essential. Ability to plan/coordinate security and/or cybersecurity activities across multiple programs within the business Knowledge of handling required for information security violations and incidents Ability to manage internal and external customer expectations; and provide presentations to executive leadership, government members, and external customers Excellent interpersonal and analytical skills Must hold a current SECRET clearance. Education/Certifications: BA/BS degree in information assurance or related discipline 15+ years of experience Or MA/MS degree in information assurance or related discipline 13+ years of experience And DoD 8570.01 IAM Level III Certification (e.g., CISSP) This position requires a highly skilled professional with a passion for security and risk management.
Citizenship RequirementsMust be a U.S. citizen. Applicants selected may be subject to a government security investigation and must meet eligibility requirements for access to classified information.
Be The First To Know
About the latest Cism Jobs in United States !
Information Security Manager
Posted 4 days ago
Job Viewed
Job Description
Job DescriptionJob Description
Information Security Manager
Who You Are
You are an experienced IT security professional with a proven track record in developing and implementing robust information security policies and practices. With a passion for protecting sensitive data and ensuring regulatory compliance, you thrive in dynamic, fast-paced environments. You excel at collaborating cross-functionally with teams across quality, regulatory, and engineering, ensuring the organization’s security framework remains strong. Your strategic mindset, attention to detail, and methodical approach allow you to assess risks, enhance processes, and maintain compliance, positioning you as a key driver in safeguarding our overall security posture.
What You Will Do
As the Information Security Manager, you will own the Turing Information Security Program. This includes both the creation of policies, procedures, and guidelines as well as the implementation and improvement of the program. Your focus will be on core organizational security needs, including data protection, incident response, disaster recovery, and risk management. You will regularly assess the company’s security posture, develop training programs to educate employees on best practices, and coordinate cybersecurity audits and compliance initiatives. You will also own the corporate IT function, including the enterprise IT infrastructure, employee laptop management, IT helpdesk, and overall IT improvement roadmap.
Key responsibilities include:
- Developing, implementing, and maintaining information security and IT policies and procedures
- Ensuring compliance with relevant regulatory frameworks and standards, starting with HIPAA compliance for patient privacy and security
- Collaborating with DevOps and cloud infrastructure engineers to align security strategies
- Leading risk assessments, vulnerability management, and incident response
- Managing internal and external security audits
- Developing and delivering security awareness programs for employees
- Identifying, assessing, and mitigating security risks to protect company data and intellectual property
- Leading continuous improvement initiatives in information security processes
- Developing and executing the corporate IT roadmap, including employee laptop management, helpdesk support, and enterprise software administration
- Ensuring the reliability and performance of IT systems to minimize downtime and enhance productivity.
What You Need
- 5+ years in Healthcare Information Security or another highly regulated industry
- Demonstrated experience as an IT Specialist with a willingness to get your hands dirty
- Expertise in achieving and maintaining SOC 2 certification and compliance with standards like HIPAA and GDPR
- Experience implementing and maintaining centralized device management and IT asset management
- Demonstrated history of creating and executing and IT Roadmap & Strategy
- Experience implementing Zero Trust best practices
- Expertise in Windows network management and support
- Bachelor’s degree in computer science or information technology, or equivalent work experience
- Excellent verbal and written communication skills with exceptional attention to detail
Nice to have
- Experience with Software as a Medical Device (SaMD), including IEC 62304, FDA 21 CFR Part 820, HIPAA, GDPR, and other relevant medical cybersecurity regulations and standards
- Strong understanding of cloud security best practices (AWS )
- Basic proficiency in Python and SQL
- Masters degree in computer science or information systems
Who We Are
Turing Medical Technologies, Inc. is a pioneering medical imaging software company developing advanced solutions for magnetic resonance imaging (MRI). Our mission is to provide cost-effective imaging enhancements, drive the next of data analytics, and create a patient-centered experience in the MRI suite.
We believe in the passion of our employees and are committed to helping them achieve their goals while contributing to the success of our company. You’ll collaborate with a dedicated team of scientists, engineers, product managers, quality and regulatory professionals, and others who are united by a shared commitment to innovation and excellence. Our team is based across the United States, with headquarters in St. Louis, Missouri. Turing Medical Technologies, Inc. is an Equal Opportunity Employer.
Visit to learn more about our products and company.
Powered by JazzHR
RPzR9KGUGj
Information Security Manager
Posted 5 days ago
Job Viewed
Job Description
Location : Berkeley, CA
Job Type: Career
Job Number: 2025-08-1125
Department: Information Technology
Opening Date: 08/18/2025
Closing Date: 9/1/2025 5:00 PM Pacific
BENEFITS OF WORKING FOR BERKELEY
is a small city with a big reputation. At just ten square miles of land and seven square miles of water, Berkeley is famous around the globe as a center for academic achievement, scientific exploration, free speech, and the arts, and home to over 50 parks, a top-ranked university, and the largest public marina in the San Francisco Bay.
As an employer, the City of Berkeley offers all the benefits of a career in the public sector while fostering diversity, creativity, and innovation. Join a team of high-caliber, experienced staff with a shared mission of serving the Berkeley community and promoting an accessible, safe, healthy, environmentally-sound and culturally-rich city.
JOB OPPORTUNITY
The City of Berkeley Information Technology (IT) Department is now accepting applications for the position of Information Security Manager! In this role, you will be responsible for the comprehensive security of the City's digital assets and the strategic management of its entire IT infrastructure (including computer systems, networks, and data security measures). You'll develop and implement robust security policies while overseeing the design, deployment, and maintenance of all on-premise and cloud-based systems. You will also lead a team of security and infrastructure professionals, ensuring operational excellence, resilience, and alignment with business objectives.
See the full job specification here:
MINIMUM QUALIFICATIONS
A typical way of gaining the knowledge, skills, and abilities outlined above is:
Possession of a bachelor's degree from an accredited college or university with a major in information systems, computer science, or closely related field; and five (5) years of increasingly responsible experience in cyber security application and infrastructure, technology management, or telecommunications, including two (2) years of experience in direct support of information security programs, basic budgeting principles, and supervision of staff and/or technical project teams.
Other requirements: Must be able to travel to various locations within and outside the City of Berkeley to meet the program needs and to fulfill the job responsibilities. When driving on City business, the incumbent is required to maintain a valid California driver's license as well as a satisfactory driving record.
APPLICATION PROCESS
Applications must be received by 5:00 PM Pacific on September 1, 2025 and must include a completed application and responses to supplemental questions. Please note that resumes are not a substitute for a completed application.
Applications are available in alternative formats (audio-format, braille, large print, electronic text, etc.) upon request to Please allow 10 days for production of the material in an alternative format.
EXAM PROCESS
The exam process will include, but may not be limited to:
- Application review for minimum qualifications and answers to the supplemental questions
- Oral Board Exam (tentatively scheduled for the week of September 22, 2025)
Tests may consist of any combination of written, oral or other exercises or assessment procedures that test content and may include, but are not necessarily limited to, typing, math, reading, writing and analytical skills; problem solving ability; computer and software proficiency, or any other job-related knowledge, skill, ability or qualification. The examination process and dates are subject to change. The City may, without notice, change or eliminate any assessment component as needs dictate. Applicants passing all examination phases will have their names placed on an employment eligible list that hiring departments will use to conduct final selection interviews.
Reasonable Accommodations: The City is committed to making reasonable accommodations in the examination process and in the work environment. Individuals requesting reasonable accommodations in the examination process must submit a request in writing to at the time of application.
PRE-EMPLOYMENT PROCESS
Candidates under final consideration for employment with the City will undergo an employment background/reference check that may include, but is not limited to: employment history, confirmation of educational credentials and degrees, licenses including driver's license, registrations, certificates, other credentials, credit check, criminal history check, and Live Scan fingerprinting.
EQUAL EMPLOYMENT OPPORTUNITY (EEO) EMPLOYER
The City of Berkeley is an Equal Employment Opportunity (EEO) employer. All employment actions shall be administered regardless of race, color, national origin, ancestry, religion, age, physical or mental disability or medical condition, sex, gender, gender identity, gender expression, sexual orientation, genetic information, marital status, pregnancy, political affiliation, veterans' status, or any other status protected under federal, state, or local law.
DISASTER SERVICE WORKER
All City employees are required to provide services as Disaster Service Workers in the event of an emergency/disaster.
Benefited employees receive a myriad of financial and other , including CalPERS pension and other retirement plans, medical and dental coverage, tuition reimbursement, paid time off and more.
Benefit-eligible employees include those with a regular work schedule of at least 20 hours per week. Employees working less than 30 hours per week may receive pro-rated benefits.
NOTE: For executive Police and Fire classifications, benefits may differ from those listed below. Contact Human Resources for details:
Retirement
CalPERS
City employees are included in the California Public Employees Retirement System (CalPERS). The retirement formula is either 2% at age 62 (PEPRA members) or 2.7% at age 55 (Classic members).
Deferred Compensation
The City offers voluntary 457 deferred compensation plans with CalPERS or Empower. Employees may contribute up to the IRS maximum on a pre-tax basis.
Medical Plans
Employees can choose coverage under Kaiser HMO or Sutter Health Plus HMO. The City contributes up to the full family premium for the Kaiser plan, or up to 99% of the full family premium for the Sutter Health Plus plan. Employees who have medical coverage under another group plan may choose to waive City-provided medical coverage and receive a monthly stipend.
Dental Plan
The City provides group dental benefits through Delta Dental of California. The City contributes up to the family coverage for the plan, which covers 90% of the dental charges up to 3,000 annually per person. Orthodontic benefits are offered at a 3,000 lifetime maximum per person. Employees who have dental coverage under another group plan may choose to waive City-provided dental coverage and receive a monthly stipend.
Life Insurance
The City provides employees with a 25,000 Life Insurance and Accidental Death & Dismemberment policy. Employees have the option to purchase additional term life insurance up to a maximum of 300,000.
Sick Leave
Employees earn one day of paid sick leave per month.
Vacation
New employees accrue 2 weeks of vacation annually, with an increase to 3 weeks annually after 3 years of service.
Holidays
15 paid holidays and 3 floating holidays annually
(UNREP - EXEC Z1)
01
Please indicate your highest level of education completed.
- Some High School
- High School or Equivalent
- Some College
- Associate's Degree
- Bachelor's Degree
- Master's Degree or Higher
02
Please indicate degree and/or major coursework.
03
Please describe how you meet the minimum requirement of five (5) years of experience in cybersecurity applications and infrastructure, technology management, or telecommunications. In your response, include your job title(s), date(s) of employment, and a very brief description of your duties. Please note that a detailed summary of your experience must also be provided in the Work Experience section of this application.
04
Please describe how you meet the minimum requirement of two (2) years of experience directly supporting information security programs, applying basic budgeting principles, and supervising staff and/or technical project teams. In your response, include your job title(s), date(s) of employment, and a very brief description of your duties. Please note that a detailed summary of your experience must also be provided in the Work Experience section of this application.
05
I acknowledge that I have reviewed my application and my answers to all above supplemental questions for accuracy.
- Yes
Required Question
Information Security Manager
Posted 5 days ago
Job Viewed
Job Description
As part of the Church Mutual team, you'll work with some of the most experienced and knowledgeable people in the industry and achieve your own growth and career satisfaction while finding fulfillment in serving those who serve others. We foster a workplace where all employees are treated with dignity and respect; diversity, inclusion and belonging are woven into the fabric of our company through our customers, employees, leadership, business relationships and outreach programs. Join us and Stand for Good .
What youll be doing:The Information Security Manager position manages and ensures the effective use of assigned resources to provide optimal support of the information security program, and ensures that the information assets of the CM Group are adequately protected.
This position is responsible for identifying, evaluating, and reporting information security risks, ensuring CMG is maintaining compliance with regulatory requirements, operational support, service level management and budget management. Supervisor responsibilities to include staffing, training and development, performance management, and work force planning.
On any given day, youll:Supervisor/Manager responsibilities may include all of the following: Staffing needs, to include interviewing and onboarding for new employees. Training and development, as well as coaching and motivation for staff. Performance Management, goal setting, employee engagement, and salary administration. Workforce Management to include; unit equipment, software, and space needs, approving time off and overtime usage, and budget recommendations. Manage and allocate resources to IT areas to ensure the achievement of business goals. Accountable for team service delivery performance and for the impact of the results on IT and the business. Communicate strategy and develop plans to foster high level of staff engagement. Responsible for the effective acquisition, deployment, and integration of information technology solutions. Ensure effective deployment and flexibility in meeting changing business needs. Develop plans and completion criteria and coordinate efforts of team members, vendors, subcontractors, and CM Group personnel. Enable the organization's flexibility through effective leadership and direction. Ensure availability of technology resources with the appropriate knowledge and skills. Lead through collaboration, partnering, and clear decision making. Provide leadership and guidance to individual contributors. Maintain contact with senior IT management and communicate problem progress/status, risk management, and business satisfaction updates. Provide regular reporting on the current status of the information security program and significant incidents to senior IT management and the Board of Directors. Create and manage a targeted information security awareness training program for all employees, contractors, and approved system users, and establish metrics to measure the effectiveness of this security training program for the different audiences. Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems and services, including privacy, risk management, compliance, and business continuity management. Assist departments if fulfilling their information security requirements and assessing department-level compliance. Develop an information security vision and strategy that is aligned to organizational priorities and enables and facilitates the organization's business objectives, and ensure senior stakeholder buy-in and mandate. Oversee the approval and publication of information security policies and practices. Provide input for the IT section of the company's code of conduct. Work with the compliance staff to ensure that all information owned, collected, or controlled by or on behalf of the company is processed and stored in accordance with applicable laws and other global regulatory requirements, such as data privacy. Collaborate with Compliance for reporting and escalating security incidents, as necessary, lead security incident response efforts. Establish security metrics, tracking the progress of the Corporate Information Security Program, and coordinate with other corporate governance and risk entities. Establish and document information security standards in the PMLC and SDLC processes and provide appropriate review of projects to assess information security policies, practices, and guidelines. Oversee technology dependencies outside of direct organizational control. This includes reviewing contracts and the creation of alternatives for managing risk. Conduct vulnerability scanning, facilitate the vulnerability management process, and escalate as required for critical vulnerabilities and threats. Participate in department capital, expense, and compensation budgeting. Perform vendor negotiations, contract management, escalation, purchase request, and invoice verification.
Heres what we expectBachelor's degree in related field (e.g., business, finance, or technical) or equivalent experience required. 1+ years IT organization experience required. 1+ years leadership/management experience required. Insurance industry experience preferred. Experience with contract and vendor negotiations. Professional security management certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or other similar credentials. Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework. Knowledge of SDLC methodologies. Knowledge of insurance industry. Knowledge of insurance IT systems. Knowledge of financial management. Knowledge of management techniques. Knowledge of business risk management. Strong knowledge around creating business value. Strong knowledge of MS Office tools. Strong ability to build trust. Strong ability to deliver capabilities. Strong ability to adapt. Ability to manage resources. Ability to manage vendors. Ability to delegate. Ability to lead/mentor less experienced staff. Strategic thinking and planning skills. Negotiation skills. Strong collaboration and partnering skills. Strong communication skills. Strong problem solving skills. Strong decision making skills. Strong systemic thinking skills. Strong leadership skills. Strong teamwork skills. Ability to learn CM Group IT systems, methodologies and processes, and policies, products, etc. associated with the business.
Church Mutual is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Exact compensation will vary based on consideration of a variety of factors including education, skills, experience, and location.
Minimum Compensation USD $113,200.00/Yr. Maximum Compensation USD $169,800.00/Yr.#J-18808-Ljbffr