> Markdown version of [/jobs/ext/2720668-manager-of-information-security-compliance](https://www.wearedevelopers.com/jobs/ext/2720668-manager-of-information-security-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager of Information Security & Compliance - **Company:** iBOSS, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Disaster Recovery, Usage Tracking - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/manager-of-information-security-and-compliance-iboss-8300563 ## About the Role * 4-year college degree or related experience * 5 - 10 years' experience in technology with a security focus * Network, secure application design or systems design experience * CISSP, CISA, CISM or similar industry certification preferred * Professional communicator and comfortable speaking to internal shareholders and executives * Possess a strong work ethic and team player mentality * Highly developed sense of integrity * Strong detail orientation and listening skills * Strong decision making and analytical abilities * US Citizen ## Description The Manager of Information Security & Compliance is a key leadership role responsible for overseeing security operations and regulatory compliance initiatives. This role requires deep expertise in technology, risk management, and IT security principles, with a strong focus on protecting information systems and data. The Director of Information Security & Compliance will develop and implement security policies and align organizational practices with industry frameworks such as ISO 27001, ISO 9001, SOC 1/2, Cyber Essentials, and FedRAMP to ensure continuous monitoring of security controls and incident response readiness. In addition to managing internal security policies, this role will be the primary point of contact for client assessments and external audit engagements, ensuring all compliance obligations are met and supporting key security programs, including contingency planning, configuration management, security awareness, client assurance, and change management. Maintaining detailed documentation of security events, policy updates, and risk management activities will be essential for driving compliance and operational transparency. A strong ability to communicate complex security concepts through well-structured documentation is critical. The ideal candidate will assist stakeholders in drafting and refining comprehensive policy documents, ensuring they align with regulatory requirements. Additionally, they will oversee system audits, leveraging automated tools and established processes to maintain compliance. A thorough understanding of security technologies and control objectives is pivotal in supporting the organization's security posture. Further responsibilities include managing configuration and change control processes, tracking system modifications, and overseeing the Change Management Board. The director will also monitor software usage, maintain an accurate inventory of system components, and protect the Configuration Management Plan from unauthorized changes. Additionally, they will drive security awareness efforts, coordinate third-party audit engagements, and oversee regulatory reporting for government compliance programs. This role requires a proactive, detail-oriented leader who can balance long-term security strategy with day-to-day operational needs. By fostering a culture of risk awareness and compliance, the Manager of Information Security & Compliance will play a crucial role in maintaining the integrity, confidentiality, and availability of the organization's systems and data. Responsibilities * Lead the GRC team, ensuring alignment with organizational security and compliance objectives. * Support internal information security audit activities and serve as the primary interface with external auditors and third-party assessors. * Collaborate with departmental stakeholders to align policies and procedures with industry security frameworks, including SOC 2, ISO 27001, ISO 9001, FedRAMP and others. * Establish and track long-term milestones for compliance activities, planning a year or more in advance. * Demonstrate strong written communication skills for policy articulation, documentation, and reporting. * Maintain detailed records of events, tasks, and timelines during incident response and bridge calls involving multiple teams. * Manage long-term compliance obligations independently, without requiring direct oversight. * Oversee and execute security or technology projects as needed, ensuring successful delivery within scope and timeline. * Coordinate with technical teams to conduct annual contingency exercises, including disaster recovery tests and business continuity procedures. * Apply best practices in risk management to assess, mitigate, and monitor security and compliance risks effectively. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [Metrics Handle with Care: The Paradox of Measuring Team Performance](https://www.wearedevelopers.com/videos/1131-metrics-handle-with-care-the-paradox-of-measuring-team-performance) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)