> Markdown version of [/jobs/ext/3016796-information-security-program-manager](https://www.wearedevelopers.com/jobs/ext/3016796-information-security-program-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Program Manager - **Company:** Fisher Investments - **Location:** Camas, WA, United States (Remote available) - **Experience:** Experienced - **Salary:** $115,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Emulators, Information Security Management, Red Team (Cyber Security), Mitre Att&ck, Purple Team (Cyber Security) - **Published:** September 20, 2026 - **Apply:** https://www.oriontalent.com/search-jobs/career/11662744/information-security-program-manager-washington-wa-camas ## About the Role * Experience helping build or mature Security Assurance, Cyber Resilience, Threat Emulation, Security Validation, Adversarial Validation, Red Team, or Purple Team capabilities. * Experience conducting security assessments, attack simulations, adversarial exercises, or threat-led testing activities. * Experience working within Financial Services, Wealth Management, Banking, Insurance, or other highly regulated industries. * Familiarity with cyber resilience exercises, security control validation, and operational readiness assessments. * Experience evaluating new technologies, including cloud and frontier AI security controls. ## Description Fisher Investments is looking for a Cyber Resilience & Assurance Program Manager to help establish and mature a strategic cybersecurity program. With the capability focused on validating the effectiveness of security controls, operational readiness, technology platforms, AI security safeguards, and cyber resilience programs. You will have the unique opportunity to build a program from the ground up while partnering across the firm to develop assessment methodologies, governance frameworks, resilience exercises, executive reporting, and long-term strategies. If you're passionate about cybersecurity, continuous improvement, and helping organizations measure whether their security investments are truly effective, we'd like to talk with you! The Opportunity: We're searching for an Information Security Program Manager to help support our growing Information Security programs. Alongside Information Security leaders and program managers, you will help develop documentation, support process improvement efforts, contribute to governance and reporting activities, and assist with training and awareness programs. You'll gain exposure to multiple Information Security disciplines while expanding your technical writing, process analysis, and project coordination. You don't need to be a cybersecurity expert, but if you're passionate about documentation, organization, and continuous improvement, this is the job for you. The Day-to-Day: * Help build and mature our Cyber Resilience & Assurance program. * Develop governance frameworks, standards, operating procedures, and assessment methodologies. * Establish validation approaches for cybersecurity controls, operational readiness, technology platforms, and cyber resilience activities. * Evaluate the effectiveness of security controls across identity, infrastructure, network, cloud, application, and AI environments. * Support threat-informed security assessments, attack simulations, exercises, and security validation activities. * Analyze attack paths, control effectiveness, and organizational readiness against evolving threats. * Develop metrics, scorecards, and executive reporting to measure cyber resilience and security effectiveness. * Work with business and technology partners to identify improvement opportunities and strengthen overall cyber resilience. * Contribute to the long-term roadmap, strategy, and maturity of the Cyber Resilience & Assurance program. * Understanding of threat actor tactics, techniques, and procedures (TTPs). * Working knowledge of the MITRE ATT&CK Framework. * 3+ years of experience with modern attack methodologies. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [WeAreDevelopers LIVE – Web Scraping, Agents, Actors and more](https://www.wearedevelopers.com/videos/1764-wearedevelopers-live-web-scraping-agents-actors-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Prototyping with Hardware and the Web](https://www.wearedevelopers.com/videos/651-prototyping-with-hardware-and-the-web) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)