Senior Manager, Information Security & IT
United States · Remote · Full-time
- Posted 2w ago
- From Genea’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 7+ years
- Department
- Information Technology
Opens the listing on job-boards.greenhouse.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Job Overview
Genea is looking for a hands-on Senior Manager, Information Security & IT to lead and continuously improve our cybersecurity and corporate IT programs.
Duties and Responsibilities
Cybersecurity Compliance & Programs
- Own and continuously mature Genea's cybersecurity compliance program, including SOC 2 Type 2, policies, controls, audit readiness, evidence management, risk assessments, cybersecurity awareness, and readiness for ISO 27001 and other relevant frameworks.
- Establish practical governance and guardrails for secure enterprise adoption of AI, including approved AI technologies, data protection, third-party AI risk, responsible usage, and emerging AI cybersecurity requirements.
- Establish measurable cybersecurity KPIs, KRIs, risk reporting, and provide regular program updates to the executive team.
Cloud & Application Security
- Drive Genea's cloud and application security program in close partnership with Engineering, DevOps, Platform, and Product teams, including secure-by-design practices for traditional applications as well as AI and GenAI capabilities.
- Strengthen cybersecurity across AWS and Azure, including IAM roles and permissions, least privilege, network controls, secrets management, encryption, logging, secure configurations, infrastructure hardening, and secure access to AI models, agents, APIs, and data.
- Mature secure SDLC and DevSecOps practices, including threat modeling, architecture reviews, SAST/DAST, dependency and container scanning, software supply-chain security, and controls for emerging AI risks such as prompt injection and excessive agent permissions.
- Own vulnerability management and coordinate internal and external penetration testing, prioritizing findings and driving remediation with Engineering.
Incident Response & Cybersecurity Operations
- Own cybersecurity monitoring, detection, investigation, and incident response across cloud, applications, endpoints, corporate systems, and AI-enabled services.
- Lead incident response from triage and containment through recovery, post-incident review, and corrective actions, while maintaining playbooks and tabletop exercises.
- Leverage AI and automation to improve threat detection, investigation, alert triage, and response, while monitoring emerging AI-enabled threats and attack techniques.
Identity, Access Management & Corporate IT
- Own corporate IT operations, including employee endpoints, MDM, SaaS applications, device lifecycle management, onboarding/offboarding, hardware and software provisioning, and employee IT support.
- Manage identity and access across corporate and approved AI systems, including SSO, MFA, privileged access, least privilege, IAM policies, access reviews, API credentials, and joiner/mover/leaver processes.
- Drive automation, standardization, patching, secure configuration, endpoint cybersecurity, access governance, and appropriate controls for enterprise AI tools and data usage.
Team Leadership & Development
- Lead and develop the IT team, establishing clear ownership, operational standards, and accountability across corporate technology and cybersecurity responsibilities.
- Build the cybersecurity team as the organization grows, identifying capability gaps and hiring or developing the right talent across areas such as cybersecurity engineering, operations, compliance, and risk.
Customer, Vendor & Cybersecurity Risk
- Own customer cybersecurity questionnaires, RFP responses, customer security reviews, third-party assessments, and vendor cybersecurity risk, including material AI-related vendor and platform risks.
- Represent Genea's cybersecurity program in customer and partner discussions and clearly communicate Genea's cybersecurity posture and controls.
- Identify and track material cybersecurity risks, drive remediation, and ensure appropriate executive visibility.
Qualifications
- 7+ years of experience across cybersecurity, information security, cloud security, application security, security engineering, or IT, including 2+ years in a leadership or management role.
- Strong technical experience with cloud-native SaaS environments, including AWS and/or Azure, IAM, application security, cloud security, vulnerability management, endpoint cybersecurity, and incident response.
- Experience with secure SDLC and DevSecOps practices, including threat modeling, penetration testing, SAST/DAST, dependency scanning, container scanning, and secrets management.
- Practical experience with SOC 2 Type 2, ISO 27001, NIST, or similar cybersecurity frameworks, including working with auditors, assessors, penetration-testing firms, and cybersecurity vendors.
- Working knowledge of AI/GenAI cybersecurity risks and secure AI adoption practices, including data protection, AI governance, LLM and agent security, and emerging threats such as prompt injection and excessive agent permissions.
- Strong understanding of modern identity and corporate IT environments, including SSO, MFA, endpoint management, MDM, SaaS administration, and privileged access, with the ability to communicate cybersecurity risk clearly to Engineering teams, customers, business leaders, and executives.
- Experience building or significantly maturing cybersecurity and IT programs within a growing SaaS technology company preferred.
- Experience implementing cybersecurity automation across CI/CD, cloud infrastructure, compliance, cybersecurity operations, and AI-enabled workflows preferred.
- Experience with technologies such as AWS, Azure, Okta, CrowdStrike or equivalent, SIEM, MDM, vulnerability-management platforms, and automated GRC tools preferred.
- Familiarity with AI cybersecurity frameworks and practices such as NIST AI RMF, OWASP GenAI/LLM guidance, AI red teaming, or securing agentic AI systems; CISSP, CISM, CCSP, or comparable cybersecurity certifications are preferred but not required.
What Success Looks Like
Success in this role means Genea maintains a strong, measurable, and continuously improving cybersecurity posture while supporting the speed and growth of the business.
Cybersecurity risks are clearly identified and prioritized, compliance programs remain audit-ready, cloud and application security practices are integrated into Engineering workflows, AI is adopted with appropriate cybersecurity guardrails, incidents are handled effectively, enterprise customers have confidence in Genea's cybersecurity program, and corporate IT provides employees with a reliable and secure technology environment.
The ideal candidate combines strong technical judgment, practical cybersecurity risk management, operational discipline, a builder's mindset, and a willingness to embrace AI thoughtfully. Cybersecurity should enable the business and Engineering teams to move quickly and securely rather than become a bottleneck.
Compensation
$160-180K annual base salary. This role is also bonus eligible.
This range reflects what Genea reasonably expects to pay for this role at the time of posting. Where an offer falls within the range depends on the candidate's experience, qualifications, and skills, and on internal equity.
Benefits
Full-time employees are eligible to participate in a comprehensive benefits program that includes medical, dental, and vision insurance; flexible spending accounts (FSA); life insurance; accidental death and dismemberment (AD&D) insurance; long-term disability (LTD) coverage; paid time off (PTO); and a 401(k) retirement savings plan. Eligibility is subject to plan terms and conditions.
E-Verify
Genea participates in E-Verify to confirm the employment eligibility of all new hires working in the United States. For more information about E-Verify, please visit the E-Verify website.
Equal Employment Opportunity
Genea is an equal opportunity employer. We make employment decisions based on qualifications, merit, and business need.
Genea does not discriminate on the basis of race, color, religion or religious creed, national origin, ancestry, citizenship status, sex (including pregnancy, childbirth, breastfeeding, and related medical conditions), sexual orientation, gender, gender identity or expression, age, physical or mental disability, medical condition, genetic information, marital status, military or veteran status, height, weight, or any other characteristic protected by applicable federal, state, or local law.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, compensation, benefits, training, transfer, leave of absence, and termination.
Skills they ask for
Pick one to see other roles that ask for it.
About Genea
Cloud property technology for buildingsGenea provides cloud-based property technology for access control, visitor management, submeter billing, and after-hours HVAC.
See all 4 roles at GeneaMore roles at Genea
See all 4- Talent Acquisition SpecialistUnited States · RemoteHuman Resources · RemoteUnited States2d
- Lead Product Manager (Commercial Real Estate)United States · Lead · RemoteProduct Management · Lead · RemoteUnited States2w
- Vice President, MarketingUnited States · Executive · RemoteMarketing · Executive · RemoteUnited States1mo
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.