Remote Jobs RockRemote Jobs Rock

Information Security Manager

🕒 29 days ago
Information SecurityIT SecuritySOC 2 Type IIISO 27001

📜 Description

  • Act as primary point of contact for all Information Security matters across the organization.
  • Implement, maintain, and own InfoSec controls compliance; lead and oversee SOC 2 Type II and ISO 27001 audit processes.
  • Partner with Development, DevOps, IT, and Product teams to align solution architectures with InfoSec best practices and mitigate security risks.
  • Collaborate with Legal on compliance with emerging InfoSec laws and security-related contract redlines.
  • Support Sales, Customer Success, and Support teams with security assessments, audit requests, and customer inquiries.
  • Drive continuous improvements to security architecture and monitoring mechanisms; own security awareness training programs.

🛠️ Requirements

  • 5+ years of proven experience as an Information / IT Security expert.
  • A track record of leading at least one successful SOC 2 Type II, ISO 27001, or similar security audit (driving the process from initial implementation, through the audit to the official report/certificate).
  • Solid knowledge of security architecture principles.
  • Familiarity with modern cloud technologies (such as GCP, AWS, Azure).
  • Ability to translate complex security and privacy concepts into clear, actionable business terms.
  • Excellent communication skills, with fluent verbal and written English language skills.
  • Experience with AI security concepts, risk frameworks, and safe AI deployment practices.
  • Relevant information security certifications
Full job description

About us

‍Insightful is a market-leading platform for workforce analytics. We process really big data, synthesize it into actionable insights, and ultimately provide an easy-to-use product that empowers enterprise customers to improve employee productivity, business processes, and overall staff well-being.

Job Description

We are looking for an Information Security Manager to join Insightful. In this role, you will act as the primary point of contact for all InfoSec matters across the organization, ensuring our security posture remains strong, compliant, and aligned with our business goals.

Key Responsibilities:

• Security Leadership & Compliance: Act as the main point of contact for all Information Security topics across the organization. Implement, maintain and own InfoSec controls compliance and lead/oversee audit processes for SOC 2 Type II and ISO 27001 certification.
• Cross-Functional Collaboration: Partner with Development, DevOps, IT, and Product teams as a subject matter expert. Ensure solution architectures align with InfoSec best practices and actively mitigate identified security risks.
• Legal Collaboration: Work closely with Legal on compliance with emerging InfoSec laws and identify security-related redlines in customer contracts.
• Customer Enablement: Partner with our Sales, Customer Success, and Support teams to address prospective or active customer inquiries, security assessment questionnaires, and audit requests.
• Incident Response: Assist and guide the Incident Response team in handling, investigating, and resolving any potential security events of interest.
• Security Architecture & Monitoring: Propose and drive continuous improvements to current security architecture and monitoring mechanisms to safeguard Insightful’s business-critical assets.
• Risk Management: Support the management team with strategic expertise in information security risk management.
• Security Awareness: Own and drive information security awareness training activities for both new and existing employees.

You are a great fit for this role if you have:

• 5+ years of proven experience as an Information / IT Security expert.
• A track record of leading at least one successful SOC 2 Type II, ISO 27001, or similar security audit (driving the process from initial implementation, through the audit to the official report/certificate).
• Solid knowledge of security architecture principles.
• Familiarity with modern cloud technologies (such as GCP, AWS, Azure).
• Ability to translate complex security and privacy concepts into clear, actionable business terms.
• Excellent communication skills, with fluent verbal and written English language skills.

Bonus points if you have:

• Experience with AI security concepts, risk frameworks, and safe AI deployment practices.
• Relevant information security certifications

Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments.

Customer TrustVendor Risk ManagementSecurity AssessmentGDPR
🕒 5 days ago

As a Senior Cybersecurity Engineer in Cyber Threat Intelligence & Response, you will lead incident response efforts, ensuring security events are effectively managed and mitigated.

Incident ResponseSecurity OperationsTriageRoot Cause Analysis
🕒 6 days ago

You’ll report into the Director, Information Security and build relationships with technology stakeholders. You’ll leverage your knowledge of secure code practices and payment systems to identify and remediate application vulnerabilities.

Application SecurityVulnerability ManagementAWSLambda

Trusted by Remote Workers