> Markdown version of [/jobs/ext/3107842-manager-information-security-compliance](https://www.wearedevelopers.com/jobs/ext/3107842-manager-information-security-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager - Information Security Compliance - **Company:** VeriSign - **Location:** Reston, VA, United States - **Experience:** Experienced - **Salary:** $135,800.0 - $183,800.0 - **Contract:** Permanent contract - **Skills:** Automation of Tests, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Information Security Management, Information Systems Security Architecture Professional, Information Technology, CIS Benchmarks - **Published:** September 27, 2026 - **Apply:** https://www.juju.com/job/21_01a05a9b-c723-7a94-8888-381a084691b4 ## About the Role * Domain expertise in cyber security standard methodologies and security control frameworks such as CIS Controls, SOC 2/3 Trust Services Criteria, NIST Cybersecurity Framework, and NIST SP800-53; with hands-on experience testing and mapping controls across frameworks * Experience in a public company environment managing compliance across multiple regulatory and security frameworks * Technical understanding of security controls, identifying control objectives, and how to implement them in a complex enterprise IT environment * Ability to creatively develop and refine control tests tailored to specific control implementations * 8+ years progressively responsible experience in information security governance, risk, compliance, or security assessment/audit * 4+ years of security control assessment experience required * 2+ years of related experience leading or managing others * Professional security management certification, such as a Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC) are preferred * Bachelor's degree in Information Systems, Computer Science, or related field, or equivalent experience, required ## Description We are a mission focused, values driven company where each individual can contribute to building a stronger, more secure internet. We offer a dynamic and flexible work environment with competitive benefits and the ability to grow your career. Verisign is seeking a hands-on technical manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. In this role, you will support an enterprise-wide governance, risk, and compliance program focusing on security control assurance, security risk management, policies and standards, continuous control monitoring, and ensuring compliance with internal and external security requirements. Some immediate focus areas include: * Reviewing information security control design and conducting tests * Standing up automated evidence collection practices * Responding to external regulatory information requests An ideal candidate cares deeply about automation and reducing friction. We expect the candidate to possess competencies that allow them to bring noticeable and measurable improvements in some of the above-mentioned areas. This position requires the technical depth and communication range to brief audiences from system engineers to senior leadership., * Manage a security control assurance program, including planning and executing test procedures, assessing design and operating effectiveness, and driving identified gaps to remediation. * Manage compliance with external regulatory obligations, translating requirement into control objectives, coordinating regulator information requests, and tracking remediation commitments. * Build a continuous control monitoring program by collaborating with control and system owners and translating security control requirements into automated tests. * Interface directly with technical engineering teams to design and improve security controls, define implementation requirements, and determine what effective security control operations should look like. * Report on compliance and control assessment results, risk trends, and remediation priorities to audiences ranging from controls owners to senior leadership through clear reporting, executive briefings, and dashboards. * Assist with the development of enterprise information security policies and standards. * Lead a team of practitioners, setting priorities and quality standards, and ensuring commitments are met. ## Related Videos - [How to add test automation to your project: The good, the bad, and the ugly](https://www.wearedevelopers.com/videos/1668-how-to-add-test-automation-to-your-project-the-good-the-bad-and-the-ugly) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Plants vs. Thieves: Automated Tests in the World of Web Security](https://www.wearedevelopers.com/videos/1282-plants-vs-thieves-automated-tests-in-the-world-of-web-security) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)