> Markdown version of [/jobs/ext/2737536-global-it-manager-security-compliance](https://www.wearedevelopers.com/jobs/ext/2737536-global-it-manager-security-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Global IT Manager, Security & Compliance - **Company:** SERVERFARM, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Integrated Windows Authentication, OAuth, PCI Data Security Standards, Phishing, Software Vulnerability Management, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/global-it-manager-security-compliance-serverfarm-9919996 ## About the Role * Eight or more years in information security, IT compliance, or IT risk, with meaningful time spent in both compliance and technical security work. * Demonstrated ownership of an ISO 27001 program, including direct experience preparing for and defending findings with an external certification body. * Hands-on experience with at least two of: SOC 2, PCI DSS, HIPAA, NIS2, or DORA. * Genuine technical depth - you should be comfortable reading firewall and authentication logs, assessing a vulnerability scan, evaluating an OAuth consent request, and challenging an engineer's proposed remediation on its merits. * Experience with vulnerability management platforms, endpoint detection and response tooling, and enterprise identity platforms. * Experience leading security incident response through to a customer-facing or executive-facing conclusion. * Ability to communicate risk credibly to both engineers and executives, and to hold vendors and internal stakeholders accountable without formal authority over them. * Willingness to travel to sites periodically for audit, assessment, and control validation. ## Description Compliance and Risk * Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for a portfolio of approximately thirteen operating sites. * Act as IT's counterpart to external certification bodies and auditors - prepare for audits, present and defend control evidence, and own remediation of IT findings through to closure. * Manage third-party and vendor risk management for IT: vendor security assessments, a maintained vendor register with periodic reassessment. * Own customer-facing security due diligence - questionnaires, audits and assessments. * Maintain the IT risk register and opportunities-for-improvement log, and drive items to closure rather than allowing them to age. * Coordinate IT participation in business continuity and disaster recovery testing, and ensure results are documented. Security Operations * Manage vulnerability management end to end - scanning coverage, triage, remediation ownership, escalation of anything aging, and periodic reporting to leadership. * Work along side counterparts to oversee endpoint detection and response and the security alerting pipeline; ensure alerts reach an owner and that investigations are recorded and closed. * Lead security incident response - containment, investigation, root cause, customer-facing incident reporting, and post-incident hardening. * Manage email security, including domain authentication posture and secure email gateway configuration. * Run the security awareness program - monthly phishing simulation, results analysis, and targeted follow-up. Identity and Access * Contribute to identity governance across a hybrid estate spanning cloud and on-premises IdP * Oversee access review cadence, privileged access controls, and the joiner-mover-leaver process from an IT control standpoint, including third-party and contractor access. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)