1

Information Security Governance Manager Jobs (NOW HIRING)

next page

Showing results 1-20

Information Security Governance Manager information

See salary details

$62.5K

$136.1K

$200K

How much do information security governance manager jobs pay per year?

As of Jun 11, 2026, the average yearly pay for information security governance manager in the United States is $136,104.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,500.00 and $160,500.00 per year, depending on experience, location, and employer.

What does an Information Security Governance Manager do?

An Information Security Governance Manager is responsible for developing, implementing, and overseeing the policies, procedures, and frameworks that ensure an organization’s information assets are properly protected. They align information security strategies with business objectives, manage compliance with relevant laws and regulations, and coordinate risk management activities. This role often involves collaborating with various departments, leading audits, and reporting to senior management about the organization's security posture and areas for improvement.

What are the key skills and qualifications needed to thrive as an Information Security Governance Manager, and why are they important?

To thrive as an Information Security Governance Manager, you need a deep understanding of information security frameworks, risk management, compliance regulations, and typically a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with GRC (Governance, Risk, and Compliance) tools, audit management systems, and data protection technologies is essential. Outstanding analytical thinking, leadership, and effective communication are crucial soft skills for managing teams and influencing organizational policies. These skills and qualities ensure robust security postures, regulatory compliance, and effective risk mitigation strategies across the organization.

What are some common challenges faced by Information Security Governance Managers when implementing organization-wide security policies?

Information Security Governance Managers often encounter challenges such as gaining buy-in from various departments, balancing security requirements with business objectives, and ensuring consistent policy enforcement across all levels of the organization. They must communicate effectively with both technical and non-technical stakeholders to address concerns and promote security awareness. Additionally, keeping policies up-to-date with evolving regulations and emerging threats requires ongoing collaboration and adaptability.

What is the difference between Information Security Governance Manager vs Information Security Analyst?

AspectInformation Security Governance ManagerInformation Security Analyst
CertificationsCISSP, CISM, ISO 27001 Lead AuditorCISSP, CompTIA Security+, GIAC Security Essentials
Work EnvironmentStrategic, policy-focused, management teamsOperational, technical, security teams
Employer & Industry UsageOrganizations with formal security governance frameworksSecurity operations, incident response teams
Search & Comparison IntentUnderstanding governance roles and responsibilitiesTechnical security tasks and analysis

The main difference is that the Information Security Governance Manager focuses on establishing and maintaining security policies, compliance, and strategic oversight, while the Information Security Analyst handles technical security assessments, monitoring, and incident response. Both roles are essential but serve different functions within an organization's security framework.

What cities are hiring for Information Security Governance Manager jobs? Cities with the most Information Security Governance Manager job openings:
What are the most commonly searched types of Information Security Governance jobs? The most popular types of Information Security Governance jobs are:
What states have the most Information Security Governance Manager jobs? States with the most job openings for Information Security Governance Manager jobs include:
Infographic showing various Information Security Governance Manager job openings in the United States as of June 2026, with employment types broken down into 3% As Needed, 15% Full Time, 70% Part Time, 3% Temporary, and 9% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $136,104 per year, or $65.4 per hour.
IT & Security Governance Manager

IT & Security Governance Manager

Communication Service for the Deaf, Inc

Austin, TX • On-site

$90K - $100K/yr

Full-time

Posted 6 days ago


Job description

Description:

The IT & Security Governance Manager is responsible for advancing enterprise-wide technology maturity across corporate IT, cloud and product environments, and operational systems. This role strengthens governance structures, data stewardship practices, security controls, and operational risk management to ensure that systems and data effectively support the organization's mission, strategic partnerships, and sustainable growth.


This position operationalizes compliance frameworks as structured tools to enhance efficiency, accountability, and resilience — leveraging them to improve processes, mitigate risk, and elevate overall technology governance rather than treating compliance as the sole objective.


IT Governance, Risk & Reporting

  • Maintain an organization-wide IT and security roadmap aligned to mission priorities and partner obligations
  • Own and manage the organization’s technology risk register (security, data, vendor, and operational risks)
  • Define and maintain IT and security policies (access control, logging, data handling, endpoint standards, secure development expectations)
  • Establish system ownership documentation and accountability structures
  • Provide leadership with clear, actionable reporting on technology health, risk posture, and audit readiness

Data Governance & System Oversight

  • Define and implement data classification, access governance, and retention standards
  • Map key data flows across internal systems, partner integrations, and cloud environments
  • Ensure encryption, logging, and access controls align with data sensitivity and contractual requirements
  • Partner with Engineering and program teams to embed secure, scalable system design patterns
  • Maintain architecture documentation, data flow diagrams, and control mappings

Identity, Access & Organizational IT Foundations

  • Strengthen identity and access management (SSO, MFA, least privilege, access reviews, joiner-mover-leaver processes)
  • Oversee endpoint and device management fundamentals (MDM, encryption, patching, configuration baselines, EDR/AV)
  • Improve SaaS governance and reduce shadow IT risk
  • Establish and validate backup, recovery, and resilience expectations for critical systems
  • Deliver practical security and data-handling guidance across departments

Cloud, Application & Vulnerability Management

  • Support the implementation of a practical Secure SDLC in partnership with Engineering
  • Own vulnerability management workflows (scanning, triage, prioritization, remediation tracking, verification)
  • Maintain cloud security guardrails (IAM standards, key management, logging, monitoring, network controls)
  • Participate in secure architecture and security reviews for major initiatives

Incident Response, Vendor Risk & Partner Assurance

  • Maintain incident response readiness, runbooks, and severity definitions
  • Lead tabletop exercises and track follow-up actions to closure
  • Support business continuity and disaster recovery validation
  • Conduct vendor and partner security reviews and remediation follow-ups
  • Support audits, customer trust requests, and partner assurance needs
  • Partner with Legal to operationalize data protection and security requirements
  • Other Duties as Assigned


Requirements:

To perform the essential functions of this position successfully, an individual should demonstrate the following competencies with one or more of each:

  • Strategic IT Governance & Risk Management – Ability to develop and maintain enterprise IT roadmaps, manage technology risk registers, and translate complex risk posture into clear, actionable reporting for leadership.
  • Policy Development & Control Implementation – Experience designing, implementing, and operationalizing IT and security policies, standards, and accountability frameworks across access control, data handling, and system governance.
  • Data Governance & Systems Oversight – Strong understanding of data classification, retention, encryption, access governance, and data flow mapping to ensure controls align with contractual and operational requirements.
  • Identity, Access & Infrastructure Security Foundations – Proficiency in IAM best practices (SSO, MFA, least privilege, access reviews), endpoint management fundamentals, SaaS governance, and resilience planning.
  • Cloud, Application & Vulnerability Management – Experience supporting Secure SDLC practices, maintaining cloud security guardrails, and leading vulnerability management workflows from identification through remediation and verification.
  • Incident Response & Third-Party Risk Management – Ability to maintain incident readiness, conduct tabletop exercises, support business continuity validation, and manage vendor security reviews, audit support, and partner assurance obligations.

Qualifications:

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field, or a minimum of five (5) years of progressive experience in IT governance, security, or risk management.
  • Experience operating across multiple security and IT domains, including corporate IT security, cloud security, application security, incident response, and risk/compliance functions.
  • Strong understanding of identity and access management principles, including SSO, MFA, least privilege, and access review processes.
  • Working knowledge of common security controls and their implementation in operational environments, including logging, endpoint hardening, network controls, encryption, and backup management.
  • Experience contributing to IT governance, data governance, or system oversight in addition to security operations.
  • Ability to translate complex technical risk into clear, actionable plans for both technical and non-technical stakeholders.
  • Demonstrated ability to work effectively in a lean, mission-driven environment, prioritizing initiatives based on risk, impact, and organizational needs.
  • Experience leading or supporting audits and security frameworks such as PCI-DSS, SOC 2, ISO 27001, NIST 800-53 Rev. 5, or HIPAA-adjacent controls (preferred).
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP) and modern CI/CD pipelines (preferred).
  • Experience with endpoint management (MDM) and security tooling, including EDR, vulnerability scanners, and SIEM/log management platforms (preferred).
  • Familiarity with secure software development practices and threat modeling methodologies (preferred).
  • Relevant industry certifications such as Security+, SSCP, CISSP, CISM, CCSP, or equivalent (preferred).
  • Experience supporting grant-funded initiatives, multi-partner collaborations, or externally funded programs.