Manager, Information Security, CX
Core
Leading operational security and compliance activities for regulated environments, including FedRAMP-authorized systems and PCI-regulated environments.
Role type
Manager, Information Security Operations
Builds
Security operations processes, compliance artifacts, and audit readiness for regulated infrastructure and product environments
Domain
Cybersecurity / Compliance / Regulated Environments
Deliverable
infrastructure
Required skills
Vulnerability management, continuous monitoring, audit support, compliance operations, cross-functional coordination, risk communication, process improvement
Preferred skills
Incident response readiness, resiliency validation, public cloud environments (AWS/Azure)
Technologies
Rapid7, Tenable, Qualys
Responsibilities
Lead the Security Operations team responsible for vulnerability management, continuous monitoring, and compliance support activities; Oversee vulnerability scanning, reporting, tracking, prioritization, and remediation coordination across infrastructure and product teams; Support and maintain FedRAMP continuous monitoring activities, including recurring reporting, inventory management, and audit evidence collection; Support operational security and compliance activities related to PCI DSS and other regulatory frameworks; Coordinate and oversee STIG/CIS benchmark validation activities and remediation efforts; Support internal and external audits including FedRAMP, PCI DSS, SOC 2, ISO 27001, and customer assessments; Ensure recurring compliance deliverables, operational reporting, and audit artifacts are completed accurately and on schedule; Coordinate cross-functional remediation efforts with Security, Engineering, Infrastructure, and Product teams; Support incident response readiness activities including tabletop exercises, training coordination, and operational documentation maintenance; Maintain and improve operational security processes, procedures, and workflows; Support resiliency and disaster recovery validation activities and associated compliance reporting; Communicate operational risk, remediation status, and compliance concerns to leadership and stakeholders; Drive continuous improvement initiatives focused on operational maturity, automation, audit readiness, and vulnerability management effectiveness
Seniority
Manager, operational leadership