> Markdown version of [/jobs/ext/2268437-manager-information-security-management](https://www.wearedevelopers.com/jobs/ext/2268437-manager-information-security-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Information Security Management - **Company:** SES - **Location:** Tysons, VA, United States - **Experience:** Expert - **Salary:** $136,000.0 - $187,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, PCI Data Security Standards, Software Vulnerability Management, Information Security Management System, Cloud Platform System, Information Technology - **Published:** August 27, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18091732?backUrl=%2Fcareer%2F18091732%2FManager-Information-Security-Management-Virginia-Mclean ## About the Role * Ability to explain security rationale, risks and controls convincingly to non-technical and executive audiences * Excellent stakeholder management: builds trust across business and engineering and secures buy-in without formal authority * Strong project management skills with the discipline to deliver within time, cost and scope * Sound analytical skills with the ability to reach practical, defensible conclusions, particularly in risk assessment * Consultative working style: achieves compliance through engagement rather than enforcement * Ability to coach, develop and give direction to team members, formally or informally, * Degree in Computer Science or related field and minimum of 9 years of industry related experience * US nationality is a must * Strong knowledge of information security standards and frameworks, including the ISO 27000 series, NIST SP-800 series, SOC 2 and PCI DSS * Broad technical security foundation across networks, systems, applications, cloud environments and vulnerability management * Hands-on experience implementing and maintaining an ISMS in accordance with ISO 27001, including certification audit cycles * Prior experience leading or mentoring team members is a plus * Relevant certifications (e.g., ISO 27001 Lead Implementer, ISO 27005 Certified Risk Manager, CISM, CISA, CISSP) and knowledge of the satellite industry are a plus ## Description * The jobholder owns the continuous improvement of assigned domains of the SES information security management system, manages information security risks and compliance, and delivers security projects and internal consultancy across SES and its affiliates. * A central part of the role is maintaining and expanding SES's certification portfolio and performing risk assessments for new projects and initiatives. * The role is designed to grow into people leadership: after establishing themselves within the team and the organization, the jobholder will take on line management of the US-based team members., * Lead assigned domains of the SES ISMS end to end, while actively contributing to the development and continuous improvement of all others * Perform information security risk assessments for new projects, services and initiatives, and drive the resulting risk treatment to closure * Plan and deliver information security projects within time, cost and scope * Maintain and expand SES's certification portfolio, including ISO 27001, SOC 2 and PCI DSS, and contribute to SOX audit activities * Build trusted working relationships with stakeholders across business and engineering, positioning security as an enabler and securing buy-in for the security agenda * Support compliance with US government and customer security requirements * Progressively take on people leadership of the US-based team ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)