Senior Information Security Manager

Posted 5hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Information Security Manager securing Backstory’s AI answers platform for sales teams. Owning preventative controls, compliance, risk reduction, and security tooling.

Responsibilities:

  • Own and mature preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments
  • Translate broad security objectives into concrete technical requirements, controls, tooling, and implementation plans
  • Evaluate, select, configure, and deploy security platforms and tooling across DLP, insider threat, endpoint security, IAM, vulnerability management, access controls, and security monitoring
  • Continuously assess security posture, identify gaps and vulnerabilities, prioritize risk, and drive remediation through completion
  • Partner with IT, Engineering, DevOps, and Product to integrate security controls into technologies, infrastructure, and business initiatives
  • Build metrics and reporting on security control effectiveness and overall security posture
  • Partner with Security Operations on visibility and protection for threat investigation and response
  • Develop, maintain, and test incident response playbooks, business continuity processes, and disaster recovery plans
  • Partner with CISO, CIO, and CTO on security compliance initiatives and work directly with auditors
  • Translate SOC 2, ISO 27001, ISO 42001, GDPR, CCPA/CPRA, and EU AI Act requirements into practical technical controls
  • Provide technical direction and mentorship to security engineers, analysts, IT partners, and external contractors
  • Serve as a trusted security advisor across technical and non-technical stakeholders
  • Own ambiguous security challenges from strategy and evaluation through implementation, measurement, and continuous improvement

Requirements:

  • 7+ years of progressive experience in information security, with meaningful hands-on experience implementing enterprise security controls
  • 2+ years of technical leadership, team lead, or people management experience
  • Deep understanding of cloud, SaaS, endpoint, identity, network, and data security, including traditional and Agentic AI environments and workloads
  • Strong hands-on experience implementing security tooling and controls rather than solely defining policy or overseeing implementation
  • Experience with DLP, IAM, endpoint security, vulnerability management, insider threat, access management, and security monitoring
  • Strong understanding of modern cloud infrastructure, security architecture, and risk management
  • Experience operating in a modern Mac, Linux, cloud, SaaS, and open-source-heavy environment
  • Experience automating security controls and workflows through scripting (e.g., Python) and infrastructure as code security (e.g., Terraform, policy as code, CI/CD pipeline guardrails)
  • Working knowledge of NIST, CIS, ISO 27001, SOC 2, and Zero Trust
  • Experience participating in security audits, working directly with auditors, gathering technical evidence, and remediating findings
  • Deep knowledge of securing third-party API and OAuth integrations; scoping, token lifecycle management, and revocation across SaaS and data platforms
  • Ability to translate complex technical threats and vulnerabilities into actionable solutions with Engineering, Product, IT, and non-technical stakeholders
  • Strong analytical and problem-solving skills with the ability to independently evaluate security challenges and determine the right technical approach
  • Experience working within U.S.-based technology environments and familiarity with enterprise security expectations
  • Comfortable operating autonomously in a fast-moving environment where priorities and requirements will continue to evolve

Benefits:

  • Regular employees may be eligible for commissions or bonus programs (target included in OTE)
  • Equity
  • Benefits