> Markdown version of [/jobs/ext/3066560-information-security-manager](https://www.wearedevelopers.com/jobs/ext/3066560-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** Reed MIDEM - **Location:** United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Software System Penetration Testing, User Authentication, Cloud Computing Security, Cyber Security, Mobile Application Software, Open Web Application Security, Cloud Services, Mobile Security, Software Engineering, Software Vulnerability Management, Information Security Management System, Software Security - **Published:** September 25, 2026 - **Apply:** https://computerjobs.com/us/en/mob/job/546EEA3008CBBF7D15 ## About the Role * 5+ years' experience in Information Security, Cybersecurity or Product Security. * Strong experience with ISO 27001 and recognised frameworks such as NIST and OWASP. * Experience conducting risk assessments, threat modelling and vulnerability management. * Experience integrating security into software development life cycles. * Strong cloud security knowledge, ideally AWS. * Experience supporting audits, regulatory reviews or compliance activities. * Excellent stakeholder management and communication skills. * Ability to work independently and deliver pragmatic, risk-based solutions. Highly Desirable * Medical Devices, HealthTech or Software as a Medical Device (SaMD). * Product Cybersecurity experience. * Knowledge of ISO 13485, ISO 14971, GDPR, HIPAA and FDA cybersecurity guidance. * Experience with connected devices, mobile applications or cloud-hosted healthcare platforms. Qualifications Professional certifications such as CISSP, CISM, CRISC, CSSLP, ISO 27001 Lead Auditor or Lead Implementer are advantageous. The organisation is focused on finding the right person with the expertise to lead and mature its cybersecurity capability during an exciting period of growth. ## Description We are seeking an experienced Information & Cybersecurity Manager to lead information security, product cybersecurity and cyber risk management across a growing, highly regulated technology environment. This is a unique opportunity to become the organisation's security subject matter expert, taking ownership of security governance, compliance, product security and cyber risk whilst working closely with Software Development, Quality, Regulatory, Clinical, IT and Operations teams. The successful candidate will combine strategic thinking with a hands-on approach, helping strengthen existing security practices while embedding cybersecurity throughout the software and product development life cycle., * Maintain and improve the Information Security Management System (ISMS), policies, procedures and controls. * Lead cybersecurity risk assessments, threat modelling and security reviews. * Oversee penetration testing, vulnerability management and remediation activities. * Advise on secure design, cloud security, mobile security, authentication, encryption and access control. * Embed cybersecurity requirements within software and product development processes. * Support regulatory submissions, audits, inspections and customer security assessments. * Monitor emerging threats affecting applications, cloud services and connected technologies. * Manage incident response, business continuity and cyber resilience activities. * Review third-party suppliers and technology partners from a security perspective. * Provide security awareness training and guidance across the organisation. * Present security risks and recommendations to senior leadership. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)