IT Security Manager
Sign up free to see how well your resume matches this role.
What you'll do
- Safeguarding the organization’s digital assets, infrastructure, and data through the design, implementation, and continuous improvement of a comprehensive cybersecurity program.
- Leads security strategy across governance, risk, compliance (GRC), and technical security operations.
- Ensuring alignment with industry standards such as ISO 27001, SOC 2 Type II, PCI DSS, NIST frameworks, and global data protection regulations including GDPR.
- Managing security risks, responding to threats, and driving a culture of security awareness across the organization.
- Collaborates with IT, DevOps, Legal, Risk, and Executive teams.
- May be required to support 24/7 incident response.
What they're looking for
- Bachelor’s degree in information technology or information security, Computer Science, or related field (Master’s preferred).
- 8–12+ years of IT/security experience, with at least 5 years in a leadership role.
- Proven experience implementing and managing: ISO 27001 certification programs
- SOC 2 Type II audits
- PCI DSS compliance
- NIST frameworks
- Deep understanding of cybersecurity domains, including: Network security, endpoint protection, application security
- Threat detection and incident response
- Digital forensics and root cause analysis
- Vulnerability management and risk mitigation
- Hands-on experience with security tools: SIEM (Splunk, Sentinel, QRadar, etc.)
- EDR/XDR (CrowdStrike, Defender, etc.)
Nice to have
- Master’s degree
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
- ISO 27001 Lead Implementer / Lead Auditor
- CEH, GIAC, or equivalent technical certifications
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
Job Title: IT Security Manager (Cybersecurity, Risk & Compliance)
The IT Security Manager is responsible for safeguarding the organization’s digital assets, infrastructure, and data through the design, implementation, and continuous improvement of a comprehensive cybersecurity program. This role leads security strategy across governance, risk, compliance (GRC), and technical security operations, ensuring alignment with industry standards such as ISO 27001, SOC 2 Type II, PCI DSS, NIST frameworks, and global data protection regulations including GDPR.
The ideal candidate combines deep technical expertise with strong compliance leadership, capable of managing security risks, responding to threats, and driving a culture of security awareness across the organization.
Qualifications & Experience
Required
- Bachelor’s degree in information technology or information security, Computer Science, or related field (Master’s preferred).
- 8–12+ years of IT/security experience, with at least 5 years in a leadership role.
- Proven experience implementing and managing:
- ISO 27001 certification programs
- SOC 2 Type II audits
- PCI DSS compliance
- NIST frameworks
- Deep understanding of cybersecurity domains, including:
- Network security, endpoint protection, application security
- Threat detection and incident response
- Digital forensics and root cause analysis
- Vulnerability management and risk mitigation
- Hands-on experience with security tools:
- SIEM (Splunk, Sentinel, QRadar, etc.)
- EDR/XDR (CrowdStrike, Defender, etc.)
- Vulnerability scanners (Qualys, Tenable, Rapid7)
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
- ISO 27001 Lead Implementer / Lead Auditor
- CEH, GIAC, or equivalent technical certifications
Key Skills & Competencies
- Strong knowledge of security frameworks and regulatory requirements
- Excellent analytical and risk assessment capabilities
- Proven incident response and crisis management experience
- Strong leadership, communication, and stakeholder management skills
- Ability to translate technical risks into business impact
- Expertise in cloud security and modern architectures
- Detail-oriented with strong documentation and audit readiness capabilities
Work Environment
- Collaborates with IT, DevOps, Legal, Risk, and Executive teams
- May be required to support 24/7 incident response
- Hybrid/cloud-focused enterprise environments
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.