Senior Manager of Information Security
United States · Remote · Full-time
- Posted 3w ago
- From Plume’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 6+ years
- Department
- Information Technology
Opens the listing on plume.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Role Description:
We're looking for a Senior Manager of Information Security to lead and mature our security program at a critical inflection point. We've already achieved ISO 27001 and SOC 2 Type 1 certifications — the foundation is in place. Now we need a hands-on leader who can turn that foundation into a durable, well-run program: formalizing policies and procedures, building a high-functioning security team, and protecting our infrastructure, networks, cloud environments, and applications — all without slowing down the engineers and developers who build our products.
This is not a "policy for policy's sake" role. You'll be the person who makes security a natural part of how we build software, not an obstacle to it.
Responsibilities:
Program & Governance
- Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
- Author, formalize, and maintain the policies, standards, and procedures required to close any remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor/third-party risk, change management, business continuity, etc.).
- Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
- Manage relationships with external auditors, pen testers, and compliance partners.
Security Engineering & Operations
- Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end.
- Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response.
- Establish and continuously improve secure SDLC practices — threat modeling, secure code review, dependency and supply-chain security, CI/CD pipeline security.
- Own incident response: build the plan, run tabletop exercises, and lead the response when needed.
Team Leadership
- Lead, coach, and develop security team — establishing clear roles, workflows, and a sense of ownership.
- Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
- Define how the team engages with Engineering and Product (embedded reviews, self-service tooling, clear SLAs) to minimize friction and rework.
Cross-Functional Partnership
- Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership.
- Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no."
- Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage.
Qualifications:
- Bachelor's degree in Information Security, Computer Science, Computer Engineering or related field or equivalent work experience.
- 6-8+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
- Direct experience operating within (not just achieving) ISO 27001 and SOC 2 frameworks — you know what "audit-ready" looks like day to day, not just at renewal time.
- Strong technical depth in cloud security (AWS/GCP), network security, and modern application security (SDLC, AppSec tooling, container/Kubernetes security a plus).
- Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment.
- A track record of leading security teams that engineers actually like working with — you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates.
- Experience managing external auditors, penetration testers, and compliance vendors.
- Excellent communication skills — able to flex between a whiteboard session with engineers and a risk briefing with the board.
Nice to Have:
- CISSP, CISM, or similar certification.
- Experience implementing or operating under ISO 27701 (privacy extension to 27001) and the NIST Cybersecurity Framework (CSF).
- Experience in a company of similar size/stage (post-certification, scaling team).
Skills they ask for
Pick one to see other roles that ask for it.
About Plume
Connected-home services for internet providersPlume provides a platform for internet service providers to manage connected-home experiences and services such as Wi-Fi, security, and customer support.
See all 16 roles at PlumeMore roles at Plume
See all 16- VP, NA SalesUnited States · DirectorSales · DirectorUnited States4w
- Engineering Manager - SREHyderabad · SeniorEngineering · SeniorHyderabad, India4w
- Software EngineerHyderabad · On-siteSoftware Development · On-siteHyderabad, India1mo
- Software EngineerUnited States · SeniorSoftware Development · SeniorUnited States1mo
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.