Manager, Information Security Management

SES
Tysons, VA, United States
9 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
9 years minimum
Compensation
$136,000.0 - $187,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Security Management PCI Data Security Standards Software Vulnerability Management Information Security Management System Cloud Platform System Information Technology

Job description

  • The jobholder owns the continuous improvement of assigned domains of the SES information security management system, manages information security risks and compliance, and delivers security projects and internal consultancy across SES and its affiliates.
  • A central part of the role is maintaining and expanding SES’s certification portfolio and performing risk assessments for new projects and initiatives.
  • The role is designed to grow into people leadership: after establishing themselves within the team and the organization, the jobholder will take on line management of the US-based team members., * Lead assigned domains of the SES ISMS end to end, while actively contributing to the development and continuous improvement of all others
  • Perform information security risk assessments for new projects, services and initiatives, and drive the resulting risk treatment to closure
  • Plan and deliver information security projects within time, cost and scope
  • Maintain and expand SES’s certification portfolio, including ISO 27001, SOC 2 and PCI DSS, and contribute to SOX audit activities
  • Build trusted working relationships with stakeholders across business and engineering, positioning security as an enabler and securing buy-in for the security agenda
  • Support compliance with US government and customer security requirements
  • Progressively take on people leadership of the US-based team

Requirements

  • Ability to explain security rationale, risks and controls convincingly to non-technical and executive audiences
  • Excellent stakeholder management: builds trust across business and engineering and secures buy-in without formal authority
  • Strong project management skills with the discipline to deliver within time, cost and scope
  • Sound analytical skills with the ability to reach practical, defensible conclusions, particularly in risk assessment
  • Consultative working style: achieves compliance through engagement rather than enforcement
  • Ability to coach, develop and give direction to team members, formally or informally, * Degree in Computer Science or related field and minimum of 9 years of industry related experience
  • US nationality is a must
  • Strong knowledge of information security standards and frameworks, including the ISO 27000 series, NIST SP-800 series, SOC 2 and PCI DSS
  • Broad technical security foundation across networks, systems, applications, cloud environments and vulnerability management
  • Hands-on experience implementing and maintaining an ISMS in accordance with ISO 27001, including certification audit cycles
  • Prior experience leading or mentoring team members is a plus
  • Relevant certifications (e.g., ISO 27001 Lead Implementer, ISO 27005 Certified Risk Manager, CISM, CISA, CISSP) and knowledge of the satellite industry are a plus

Benefits & conditions

The salary range for this full-time position is $136,000 - $187,000.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Exploring Rust for cloud and web services

Patrick Koss Patrick Koss · World Congress 2024

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

1:04 min

Centralizing automotive software development across brand portfolios

Torben Schramme · World Congress 2021

Videos

See all

Related articles

See all