1

Cybersecurity Compliance Manager Jobs in Delaware

Manager, IT Audit

Wilmington, DE · On-site

$105K - $167K/yr

... cybersecurity, data and integrated audits - to ensure technology risks are effectively identified ... The Manager also supports the Audit, Risk and Compliance Committee reporting and assists the ...

next page

Showing results 1-20

Cybersecurity Compliance Manager information

What does a Cybersecurity Compliance Manager do?

A Cybersecurity Compliance Manager oversees an organization's adherence to cybersecurity laws, regulations, and industry standards. Their main responsibilities include developing policies, conducting risk assessments, implementing security controls, and ensuring that the organization meets all applicable compliance requirements. They also coordinate audits, train staff on compliance matters, and serve as a liaison between technical teams and regulatory bodies. By managing compliance, they help protect the organization from data breaches, legal penalties, and reputational damage.

What are the key skills and qualifications needed to thrive as a Cybersecurity Compliance Manager?

To thrive as a Cybersecurity Compliance Manager, you need a deep understanding of cybersecurity frameworks, regulatory requirements (such as GDPR, HIPAA, or PCI-DSS), and risk management, usually supported by a bachelor’s degree in information security or a related field. Familiarity with compliance management tools, audit software, and certifications like CISSP, CISM, or CRISC is highly valued. Strong analytical skills, attention to detail, and effective communication are essential for interpreting regulations and leading cross-functional teams. These skills ensure organizations maintain regulatory compliance, mitigate cyber risks, and protect sensitive data from threats.

How does a Cybersecurity Compliance Manager typically collaborate with other departments to ensure organization-wide compliance?

A Cybersecurity Compliance Manager regularly works with IT, legal, risk management, and business operations teams to align security practices with regulatory requirements. This often involves leading training sessions, coordinating compliance audits, and facilitating communication between technical and non-technical staff. By fostering cross-departmental collaboration, the manager ensures that security policies are understood and followed across the organization, helping to minimize risk and support business objectives. Effective communication and relationship-building are essential skills in this collaborative environment.

What is the difference between Cybersecurity Compliance Manager vs Cybersecurity Analyst?

AspectCybersecurity Compliance ManagerCybersecurity Analyst
CertificationsCISSP, CISM, CompTIA Security+CompTIA Security+, GIAC Security Essentials
Work EnvironmentPolicy development, compliance audits, risk managementMonitoring security systems, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, government sectors focusing on complianceIT departments across various industries focusing on security operations

The Cybersecurity Compliance Manager primarily focuses on ensuring organizations adhere to security standards and regulations, managing policies, and conducting audits. In contrast, the Cybersecurity Analyst concentrates on monitoring security systems, identifying vulnerabilities, and responding to incidents. Both roles require related certifications and work within the cybersecurity field, but their core responsibilities differ significantly.

What is compliance management in cybersecurity?

Compliance management in cybersecurity involves ensuring that an organization adheres to relevant laws, regulations, and standards such as GDPR, HIPAA, or ISO 27001. A Cybersecurity Compliance Manager develops policies, conducts audits, and implements controls to maintain regulatory compliance and reduce security risks.

What job categories do people searching Cybersecurity Compliance Manager jobs in Delaware look for?

The top searched job categories for Cybersecurity Compliance Manager jobs in Delaware are:

What cities in Delaware are hiring for Cybersecurity Compliance Manager jobs?

Cities in Delaware with the most Cybersecurity Compliance Manager job openings:

Cybersecurity Senior ISSO - Principal

EL-Shaddai Technologies Inc

Wilmington, DE • On-site

$97K - $125K/yr

Other

Re-posted 5 days ago


Job description

Cybersecurity Senior ISSO - Principal is responsible for providing strategic cybersecurity oversight and advisory services for assigned Agile Release Trains (ARTs) and business portfolios. This role ensures security requirements are incorporated into technology initiatives through risk assessments, architecture reviews, compliance evaluations, and security governance activities. The Senior ISSO partners with business and technology stakeholders to identify and mitigate cybersecurity risks, support secure solution delivery, and maintain alignment with enterprise policies, regulatory obligations, and industry best practices.

 •          Develop, maintain, and enforce enterprise security requirements, standards, baselines, and governance processes aligned with organizational, regulatory, and industry requirements.

•          Serve as the cybersecurity representative within Agile Release Trains (ARTs), participating in Program Increment (PI) Planning and ensuring security requirements, risks, dependencies, and remediation activities are incorporated into program and team backlogs.

•          Collaborate with Product Management, Product Owners, Release Train Engineers (RTEs), Solution Architects, engineers, and development teams to integrate security-by-design principles and DevSecOps practices throughout the system development lifecycle.

•          Conduct security risk assessments, threat analyses, vulnerability assessments, and security control evaluations for applications, systems, networks, cloud environments, and emerging technologies.

•          Perform security architecture and design reviews to identify security gaps, evaluate risks, and recommend appropriate mitigating and compensating controls.

•          Provide cybersecurity advisory services and risk-based recommendations to business leaders, project teams, architects, and technology stakeholders.

•          Lead and support security governance activities, including security requirements reviews, exception evaluations, risk acceptance decisions, and compliance assessments.

•          Review vulnerability assessment and penetration testing results, prioritize remediation efforts, and track corrective actions through resolution.

•          Partner with Security Operations, Infrastructure, Cloud, Network, and Application teams to address security findings, control deficiencies, incidents, and emerging risks.

•          Support incident response activities by providing security expertise, risk analysis, and guidance for containment, remediation, and lessons learned.

•          Monitor the evolving threat landscape, industry trends, and emerging technologies, and recommend improvements to strengthen the organization''s security posture.

•          Develop and maintain security documentation, including System Security Plans (SSPs), Security Design Reviews, Secure Design Directives (SDDs), risk assessments, exception requests, and remediation plans.

•          Support internal, external, and regulatory audits by validating security control implementation and providing required evidence and documentation.

•          Promote cybersecurity awareness, secure development practices, and risk management principles across the organization.

•          Provide after-hours support for critical security incidents, high-risk vulnerabilities, and business-critical security assessments as required.

•          Work effectively in a multi-office environment and travel as necessary to support security assessments, stakeholder engagements, and strategic initiatives.

•          Enterprise security requirements, standards, baselines, governance recommendations, and Secure Design Directives (SDDs) aligned with organizational, regulatory, and industry frameworks.

•          Security risk assessments, threat models, security impact analyses, and risk treatment recommendations.

•          Security architecture and design review reports identifying security risks, mitigation strategies, and compensating controls.

•          Cybersecurity exception reviews, risk acceptance recommendations, vulnerability assessment reviews, and remediation tracking reports.

•          Security authorization, compliance, and audit artifacts, including System Security Plans (SSPs), risk assessments, security exceptions, and supporting audit evidence.

•          Security governance reports, executive risk summaries, and security posture recommendations supporting business, technology, and Agile delivery initiatives.

•          Demonstrated alignment with NIST RMF, NIST CSF, CIS Controls, UCF, and applicable organizational security standards.

•          10+ years of experience in cybersecurity, information security, security architecture, engineering, risk management, or related security disciplines.

•          Demonstrated experience performing security architecture reviews, risk assessments, threat modeling, vulnerability management, and security control evaluations across applications, infrastructure, networks, and cloud environments.

•          Strong knowledge of cybersecurity frameworks and standards, including NIST RMF, NIST CSF, CIS Controls, UCF, and other applicable industry and regulatory frameworks.

•          Experience supporting Agile delivery methodologies, including Agile Release Trains (ARTs), Program Increment (PI) Planning, and DevSecOps practices.

•          In-depth understanding of secure architecture principles and the ability to translate business requirements into security requirements and technical controls.

•          Knowledge of common cyber threats, attack techniques, vulnerabilities, and risk mitigation strategies.

•          Experience with vulnerability assessment, security testing, and risk analysis tools such as Nessus, Checkmarx, Nmap, Burp Suite, Tenable, Qualys, or equivalent solutions.

•          Familiarity with security technologies and concepts, including network security, cloud security, firewalls, SIEM platforms, identity and access management, vulnerability management, and security monitoring.

•          Proven ability to document and communicate security risks, findings, remediation recommendations, and compliance requirements to technical and executive stakeholders.

•          Strong analytical, problem-solving, stakeholder management, and written/verbal communication skills.

•          CISSP (Certified Information Systems Security Professional) required.

•          Experience supporting cybersecurity engineering projects for a large enterprise

•          Experience implementing automation in cybersecurity toolchains

•          Any of the industry standard cybersecurity certifications such as CISM, CISA, CRISC, GCIH, GPEN, CEH, CHFI, Security+, CASP, OSCP, etc.