Information Security Manager
Core
Hands-on Information Security Manager executing full-cycle security assessments, audit preparations, and policy development for financial institutions and regulated entities.
Role type
Senior IC Information Security Manager (GRC & Audit)
Builds
Client-ready security policies, risk assessments, audit response packages, and tabletop exercise reports
Domain
Financial Services / Cybersecurity Compliance / GRC
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
FFIEC IT Examination Handbook expertise, SOC 2 readiness assessment, security policy drafting, risk assessment execution, tabletop exercise facilitation, vendor risk management, regulatory reporting, multi-client portfolio management
Preferred skills
GRC platform proficiency (Ncontracts, LogicManager), HIPAA security rule knowledge, Microsoft 365 security controls, MSP/consulting background
Technologies
Microsoft Planner, Microsoft 365, Ncontracts, LogicManager
Responsibilities
Serve as primary point of contact for FDIC/OCC/NCUA IT examinations and draft formal responses; Lead SOC 2 Type I/II readiness assessments and produce gap analysis reports; Design and facilitate tabletop exercises for incident response and business continuity; Draft and maintain client information security policies aligned with FFIEC/NIST/SOC 2; Review third-party vendor audit reports and produce risk summaries; Manage multi-client portfolio with disciplined task tracking and deliverable completion
Seniority
Senior, hands-on IC