> Markdown version of [/jobs/ext/1896255-information-security-policy-manager](https://www.wearedevelopers.com/jobs/ext/1896255-information-security-policy-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Policy Manager - **Company:** Interactive Brokers - **Location:** Greenwich, CT, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Technology - **Published:** August 1, 2026 - **Apply:** https://www.dice.com/job-detail/f8001537-858e-4883-b07d-bb9631be31ee ## About the Role * 7+ years of experience in information / cyber security experience, including 3+ years developing and managing information security policies in a regulated industry (preferably financial services) and 3+ years hands-on, technical cybersecurity roles. * Fluent understanding of regulatory requirements affecting cybersecurity, including DORA, SEC, FFIEC, and common regulations issued in Europe (EBA) and APAC (SFC, MAS). * Working familiarity with common security frameworks, including NIST CSF and ISO 27001/27002. * Prior experience as owner of policies or technical standards documentation. * Experience as lead responder to regulatory examinations, audit requests, and client due diligence questionnaires related to policy and compliance. * Proven ability to write clear, actionable policies addressing complex regulatory and technical requirements, grounded in industry accepted practices and risk management concepts, and based on existing controls and technology environments * Experience working with GRC (Governance, Risk, and Compliance) tooling a plus. * Experience building cross functional consensus as an individual contributor * Bachelor's degree in Information Security, Computer Science, Information Technology or a related field, or equivalent experience * CISM certification a plus. To be successful in this position, you will have the following: * Strong critical thinking, analytical, organizational, time management, and writing and editing skills - all with attention to detail. * Track record of building bridges with technology practitioners and translating complex technical concepts into simple, accessible language for business audiences. * A self-motivated, open, collaborative, client-centric, consensus-building problem-solving mentality * Ability to exercise good judgment when solving problems with incomplete information ## Description The Information Security Policy Manager develops, maintains, and communicates IBKR's information security policies aligned to regulatory requirements, industry best practices, and IBKR's control environment and risk appetite. This role is responsible for IBKR's formal information security policy library, ensuring IBKR's security program is supported by well-considered policy mandates. What will be your responsibilities within IBKR: * Maintain and extend IBKR's information security policy library to align with regulatory requirements, business risk appetite, industry-accepted risk frameworks, and IBKR's control environment. * Coordinate and drive the development, review, and update of information security policies and standards based on identified need and defined maintenance intervals. * Map IBKR's security policies to, and analyze gaps against, applicable risk and regulatory frameworks and laws, such as DORA, FFIEC, NIST CSF. * Support security-related external assessments, audits, and regulatory examinations by providing evidence of compliance. * Partner with the Information Security Controls Manager to ensure policies are supported by appropriate controls and testing procedures. * Evaluate security controls, identify opportunities for improvement, and communicate constructive recommendations. * Other duties, as assigned ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Microservices architecture as a key element in building trading systems for global finance markets](https://www.wearedevelopers.com/videos/1196-microservices-architecture-as-a-key-element-in-building-trading-systems-for-global-finance-markets) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)