1

Information Security Governance Manager Jobs (NOW HIRING)

Sr. Information Security Governance Manager

Austin, TX · On-site

$105K - $143K/yr

As a member of the Information Security team, you will be based in Sonar's Austin office leading the Security Governance and Customer Trust domains of our security risk management program. You will ...

Sr. Information Security Governance Manager

Austin, TX · On-site

$105K - $143K/yr

As a member of the Information Security team, you will be based in Sonar's Austin office leading the Security Governance and Customer Trust domains of our security risk management program. You will ...

Job Purpose: Support the implementation, monitoring, and continuous improvement of information security governance, risk management, and compliance program. This role contributes directly to ...

WI · On-site

$102.80 - $137.06/hr

## Senior Information Security Governance ConsultantApplyremote type: Hybrid or Remotelocations ... Conduct Information Security Risk Management processes following ISO 27005 and execute ad hoc ...

New

next page

Showing results 1-20

Information Security Governance Manager information

See salary details

$62.5K

$136.1K

$200K

How much do information security governance manager jobs pay per year?

As of Aug 7, 2026, the average yearly pay for information security governance manager in the United States is $136,104.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,500.00 and $160,500.00 per year, depending on experience, location, and employer.

What does an information security governance manager do?

An Information Security Governance Manager is responsible for developing, implementing, and overseeing the policies, procedures, and frameworks that ensure an organization’s information assets are properly protected. They align information security strategies with business objectives, manage compliance with relevant laws and regulations, and coordinate risk management activities. This role often involves collaborating with various departments, leading audits, and reporting to senior management about the organization's security posture and areas for improvement.

What are the key skills and qualifications needed to thrive as an information security governance manager?

To thrive as an Information Security Governance Manager, you need a deep understanding of information security frameworks, risk management, compliance regulations, and typically a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with GRC (Governance, Risk, and Compliance) tools, audit management systems, and data protection technologies is essential. Outstanding analytical thinking, leadership, and effective communication are crucial soft skills for managing teams and influencing organizational policies. These skills and qualities ensure robust security postures, regulatory compliance, and effective risk mitigation strategies across the organization.

What are some common challenges faced by information security governance managers when implementing organization-wide security policies?

Information Security Governance Managers often encounter challenges such as gaining buy-in from various departments, balancing security requirements with business objectives, and ensuring consistent policy enforcement across all levels of the organization. They must communicate effectively with both technical and non-technical stakeholders to address concerns and promote security awareness. Additionally, keeping policies up-to-date with evolving regulations and emerging threats requires ongoing collaboration and adaptability.

What is the difference between Information Security Governance Manager vs Information Security Analyst?

AspectInformation Security Governance ManagerInformation Security Analyst
CertificationsCISSP, CISM, ISO 27001 Lead AuditorCISSP, CompTIA Security+, GIAC Security Essentials
Work EnvironmentStrategic, policy-focused, management teamsOperational, technical, security teams
Employer & Industry UsageOrganizations with formal security governance frameworksSecurity operations, incident response teams
Search & Comparison IntentUnderstanding governance roles and responsibilitiesTechnical security tasks and analysis

The main difference is that the Information Security Governance Manager focuses on establishing and maintaining security policies, compliance, and strategic oversight, while the Information Security Analyst handles technical security assessments, monitoring, and incident response. Both roles are essential but serve different functions within an organization's security framework.

What cities are hiring for Information Security Governance Manager jobs? Cities with the most Information Security Governance Manager job openings:
What are the most commonly searched types of Information Security Governance jobs? The most popular types of Information Security Governance jobs are:
What states have the most Information Security Governance Manager jobs? States with the most job openings for Information Security Governance Manager jobs include:
Infographic showing various Information Security Governance Manager job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 22% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $136,104 per year, or $65.4 per hour.

Sr. Information Security Governance Manager

Sonar

Austin, TX

$105K - $143K/yr

Full-time

Re-posted 5 days ago


Job description

Who is Sonar?

Sonar is driving the future of agent-centric software development. As the leader in AI code review and verification, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable.

Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin, we help over 75% of the Fortune 100 build trusted, reliable, compliant software. Customers who use Sonar are 44% less likely to report an outage due to AI-generated code.

We believe code verification is the critical missing link in the Agent-Centric Development Cycle (AC/DC). Industry giants like Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.count on us to provide independent, explainable, consistent review and governance of their AI-generated code via products like:

  • SonarQube: The world’s leading AI code review and verification platform.

  • SonarQube Foundation Agent: Currently topping the leaderboards for agentic software repair.

  • SonarSweep & Sonar Context Augmentation: Providing the enterprise-grade context and constraints agents need to be truly effective.

Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE:

  • Committed to our customers and community.

  • Obsessed with quality.

  • Deliberate in our decisions.

  • Effective as one team.

With over $400M in revenue and profitable, fast-paced growth, we are building the backbone of the AI software revolution. If you’re hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.

Position description
 
The primary goal of the Information Security team is to build trust with our rapidly growing customer base by ensuring the Sonar organization meets a high level of security to protect our customers. As a member of the Information Security team, you will be based in Sonar’s Austin office leading the Security Governance and Customer Trust domains of our security risk management program. You will also support security incidents from time to time as needed. Your positive contributions will significantly impact the growth of the business through Sonar’s “collective intelligence” mindset.
What you will do
  • Customer Interaction: Manage and participate in a clear process to provide clear security answers to our customers and internal users.  This includes information on our Trust Center and also meeting with customers to provide required information.
  • Trust System Management: Ensure our customer trust systems are accurate and support federated security support across Sonar. Drive improvements and enhanced capability implementation in our tooling.

  • AI Prompt Engineering: Develop and refine prompts and automated workflows using LLMs to enhance our abilities in ensuring security information systems are valid and up to date.

  • Security Initiative Leadership: Support assigned security initiatives, ensuring they are delivered on time, within scope, and aligned with the broader InfoSec roadmap. Take part in critical, high-impact technical and strategic decisions, proactively influencing cross-functional teams to achieve ambitious objectives.

  • Coaching & Cross-Functional Quality: Coach and mentor team members and cross-functional colleagues on complex problem-solving, risk management methodologies, and security best practices. Take ownership of broader cross-functional execution and quality standards to raise the bar across the InfoSec program.

  • Security Governance: Own and maintain Sonar’s security governance program and associated artifacts.
Experience and qualifications
  • Unwavering Customer Obsession: You view security as an enabler. You are dedicated to building solutions that allow teams to move fast and innovate without compromising the safety of the organization or our users.
  • Extensive Multi-Domain InfoSec Expertise: Deep, extensive experience and knowledge across multiple security domains, examples include Cloud Security, GRC (Governance, Risk, and Compliance), Identity & Access Management (IAM), or Application Security. You are considered a reference by teams and leaders in your areas of expertise.

  • AI Proficiency: Demonstrated ability to leverage AI tools and develop complex prompts to solve non-linear security problems and automate repetitive governance tasks. Ability to establish best practices for AI-driven security workflows that others can adopt.

  • Strategic Security Documentation: Ability to draft sophisticated policy language, control descriptions, and executive-level reports that bridge the gap between technical reality and business risk. Able to communicate strategic matters effectively to varying and diverse audiences.

  • Technical Diplomacy & Strategic Communication: Exceptional communication skills with the ability to influence cross-functional stakeholders, explain complex security requirements to non-technical peers in a way that fosters collaboration, and fully own complex problem resolution from communication through execution.

  • Autonomous Leadership & Organizational Acumen: Strong organizational skills to manage multiple high-stakes remediation projects simultaneously under broad objectives with minimal supervision. Ability to take part in critical, high-impact decisions, mitigate risk within the domain, and proactively influence cross-functional teams to achieve ambitious objectives and model best practices.
Additional comments
This role is based in Austin, TX. We are unable to consider candidates unwilling to be in Austin, but we are willing to relocate the right candidate.
Benefits
  • Flexible comprehensive employee benefit package.
  • We encourage usage of our robust time-off allocations. You will receive  23 days of PTO per calendar year (on a pro-rated basis depending on your employment start date), with additional time provided for sickness, life events and holidays.
  • We offer an exciting 401(k) plan that has a 4% match.
  • Generous discretionary Company Growth Bonus, paid annually.  
  • Fully paid parking in the heart of downtown Austin, Texas.
  • Global workforce with employees in 20+ countries representing 35+ unique nationalities.
  • We have an annual kick-off somewhere in the world where we meet to build relationships and goals for the company.
  • Monthly catered events, and team events.
We value diversity, equity, and inclusion

At Sonar, we believe that our diversity is our strength. We are a global company that values and respects different backgrounds, perspectives, and cultures. We are committed to fostering a diverse and inclusive work environment where everyone feels valued and empowered to contribute their best. We are proud to be an equal opportunity employer and welcome all qualified applicants, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

If you need any accommodation, please reach out to us at hiring@sonarsource.com. 

All offers of employment at Sonar are contingent upon the results of a comprehensive background check and reference verification conducted before the start date. 

Applications that are submitted through agencies or third party recruiters will not be considered.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.