> Markdown version of [/jobs/ext/1301165-information-security-manager](https://www.wearedevelopers.com/jobs/ext/1301165-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** Vertex, Inc. - **Location:** New York, NY, United States (Remote available) - **Salary:** $109,000.0 - $299,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Information Leak Prevention, Identity and Access Management, Information Security Management, IT Management, Information Technology Operations, Network Security, Microsoft Security Essentials, Cloud Services, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Classification - **Published:** July 16, 2026 - **Apply:** https://www.disabledperson.com/jobs/73674827-information-security-manager ## About the Role * Bachelor's degree and 8 years of related experience, a Master's degree and 6 years of related experience, or 11 years of related experience and no degree. * Experience managing or supporting enterprise security programs and day-to-day security operations. * Strong hands on experience with security monitoring, incident response, vulnerability management, and risk management. * Experience working with SOC/SIEM platforms, MDR/SOC providers, and cloud security technologies. * Hands-on experience supporting compliance initiatives such as SOC 2, GDPR, HIPPA, or similar frameworks. * Experience conducting third-party/vendor security risk assessments. * Experience partnering closely with Infrastructure, Cloud, and IT Operations teams to implement security controls. Knowledge & Skills * Hands on Microsoft 365 E5 / Azure security technologies * Security operations and SIEM management * Incident response and investigation * IAM, DLP, CASB, Zero Trust, Cloud Security , Data classification & vulnerability management * Endpoint security and vulnerability management * Cloud and SaaS security * Third party risk management * Strong execution and project-driving capability. * Ability to independently manage priorities and push initiatives to completion. * Strong communication and stakeholder management skills. * Ability to work effectively across technical and non-technical teams. * Strong analytical, organizational, and problem-solving skills. * Comfortable operating in fast-paced and evolving environments. Preferred Certifications * CISSP * CISM * Security+ * ISO 27001 Lead Implementer/Auditor * GIAC certifications * Microsoft Security certifications ## Description Vertex is seeking a highly driven and hands-on Information Security Manager to lead and manage the company's overall Information Security Program. This role requires a strong operator and execution-focused leader who can both strategically execute security initiatives and actively drive implementation across the organization. The ideal candidate is someone who can independently lead initiatives, coordinate across business and IT teams, hold vendors accountable, and ensure security controls are effectively implemented, monitored, and continuously improved. This role will work in collaboration with CTO/CISO, business stakeholders, external vendors, managed security providers, and compliance partners to strengthen the company's security posture while supporting operational and business objectives. Core Responsibilities Work Product Creation, Project Management, Coordination with Team Members, Operations * Lead the day-to-day operation and continuous improvement of the company's Information Security Program. * Strong hands-on experience implementing and managing enterprise security controls across the Microsoft 365 E5 security ecosystem. * Hands-on experience implementing and managing Data Loss Prevention (DLP), CASB, Zero Trust, Conditional Access Policies, EDR/XDR, Vulnerability management and network security. * Proven experience designing, implementing, and operationalizing Security Information and Event Management (SIEM) platforms, including alert tuning, log correlation, incident investigation, automation, and response workflows. * Partner with IT leadership and business stakeholders to implement and operationalize security controls across systems, applications, endpoints, cloud services, and infrastructure. * Maintain and enforce information security policies, standards, procedures, and guidelines aligned with business and compliance requirements. * Track security risks, vulnerabilities, remediation plans, and mitigation activities across the organization. * Oversee day-to-day security operations, including monitoring, alert management, escalation, and response coordination. * Manage relationships and operational performance of external SOC/MDR providers and security vendors. * Review, tune, and optimize security alerts, detection rules, and monitoring configurations to reduce noise and improve effectiveness. * Lead and coordinate incident response activities, including investigation, containment, remediation, recovery, and post-incident reviews. * Coordinate tabletop exercises and security testing activities. * Lead third party risk management program by conducting security reviews of vendors, SaaS platforms, and technology partners by reviewing SOC reports, security questionnaires, risk findings, and remediation plans. * Lead and support compliance initiatives including SOC 2, GDPR, privacy, and other regulatory/security frameworks. * Coordinate audit readiness activities, evidence collection, remediation tracking, and compliance reporting. * Work cross-functionally to ensure security controls are properly documented, implemented, and operating effectively. * Support security awareness and education initiatives across the organization. ## Related Videos - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)