> Markdown version of [/jobs/ext/2999150-manager-of-information-security](https://www.wearedevelopers.com/jobs/ext/2999150-manager-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager of Information Security - **Company:** PLUME - **Location:** United States - **Experience:** Expert - **Salary:** $179,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Software as a Service, Cloud Computing Security, Cyber Security, Computer Engineering, Continuous Integration, Identity and Access Management, Network Security, Systems Development Life Cycle, Secure Coding, Software Vulnerability Management, Data Logging, Cloud Platform System, Software Security, Information Technology - **Published:** September 19, 2026 - **Apply:** https://startup.jobs/senior-manager-of-information-security-plume-company-10087220 ## About the Role * Bachelor's degree in Information Security, Computer Science, Computer Engineering or related field or equivalent work experience. * 6-8+ years in information security, with 3+ years in a leadership role owning a security program end-to-end. * Direct experience operating within (not just achieving) ISO 27001 and SOC 2 frameworks - you know what "audit-ready" looks like day to day, not just at renewal time. * Strong technical depth in cloud security (AWS/GCP), network security, and modern application security (SDLC, AppSec tooling, container/Kubernetes security a plus). * Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment. * A track record of leading security teams that engineers actually like working with - you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates. * Experience managing external auditors, penetration testers, and compliance vendors. * Excellent communication skills - able to flex between a whiteboard session with engineers and a risk briefing with the board. Nice to Have: * CISSP, CISM, or similar certification. * Experience implementing or operating under ISO 27701 (privacy extension to 27001) and the NIST Cybersecurity Framework (CSF). * Experience in a company of similar size/stage (post-certification, scaling team). ## Description Program & Governance * Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2. * Author, formalize, and maintain the policies, standards, and procedures required to close any remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor/third-party risk, change management, business continuity, etc.). * Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking. * Manage relationships with external auditors, pen testers, and compliance partners. Security Engineering & Operations * Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end. * Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response. * Establish and continuously improve secure SDLC practices - threat modeling, secure code review, dependency and supply-chain security, CI/CD pipeline security. * Own incident response: build the plan, run tabletop exercises, and lead the response when needed. Team Leadership * Lead, coach, and develop security team - establishing clear roles, workflows, and a sense of ownership. * Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around. * Define how the team engages with Engineering and Product (embedded reviews, self-service tooling, clear SLAs) to minimize friction and rework. Cross-Functional Partnership * Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership. * Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no." * Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)