1

Information Security Governance Manager Jobs (NOW HIRING)

The Senior Information Security GRC Analyst contributes to the continuous improvement of governance processes, compliance monitoring, and enterprise risk management activities within a regulated ...

Director, Information Security Governance, Risk and Compliance Job Type: Regular Company: Roswell ... management, and other risk functions are performed in a consistent and thorough manner aligned with ...

Showing results 21-40

Information Security Governance Manager information

See salary details

$62.5K

$136.1K

$200K

How much do information security governance manager jobs pay per year?

As of Jul 28, 2026, the average yearly pay for information security governance manager in the United States is $136,104.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,500.00 and $160,500.00 per year, depending on experience, location, and employer.

What does an Information Security Governance Manager do?

An Information Security Governance Manager is responsible for developing, implementing, and overseeing the policies, procedures, and frameworks that ensure an organization’s information assets are properly protected. They align information security strategies with business objectives, manage compliance with relevant laws and regulations, and coordinate risk management activities. This role often involves collaborating with various departments, leading audits, and reporting to senior management about the organization's security posture and areas for improvement.

What are the key skills and qualifications needed to thrive as an Information Security Governance Manager, and why are they important?

To thrive as an Information Security Governance Manager, you need a deep understanding of information security frameworks, risk management, compliance regulations, and typically a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with GRC (Governance, Risk, and Compliance) tools, audit management systems, and data protection technologies is essential. Outstanding analytical thinking, leadership, and effective communication are crucial soft skills for managing teams and influencing organizational policies. These skills and qualities ensure robust security postures, regulatory compliance, and effective risk mitigation strategies across the organization.

What are some common challenges faced by Information Security Governance Managers when implementing organization-wide security policies?

Information Security Governance Managers often encounter challenges such as gaining buy-in from various departments, balancing security requirements with business objectives, and ensuring consistent policy enforcement across all levels of the organization. They must communicate effectively with both technical and non-technical stakeholders to address concerns and promote security awareness. Additionally, keeping policies up-to-date with evolving regulations and emerging threats requires ongoing collaboration and adaptability.

What is the difference between Information Security Governance Manager vs Information Security Analyst?

AspectInformation Security Governance ManagerInformation Security Analyst
CertificationsCISSP, CISM, ISO 27001 Lead AuditorCISSP, CompTIA Security+, GIAC Security Essentials
Work EnvironmentStrategic, policy-focused, management teamsOperational, technical, security teams
Employer & Industry UsageOrganizations with formal security governance frameworksSecurity operations, incident response teams
Search & Comparison IntentUnderstanding governance roles and responsibilitiesTechnical security tasks and analysis

The main difference is that the Information Security Governance Manager focuses on establishing and maintaining security policies, compliance, and strategic oversight, while the Information Security Analyst handles technical security assessments, monitoring, and incident response. Both roles are essential but serve different functions within an organization's security framework.

What cities are hiring for Information Security Governance Manager jobs? Cities with the most Information Security Governance Manager job openings:
What are the most commonly searched types of Information Security Governance jobs? The most popular types of Information Security Governance jobs are:
What states have the most Information Security Governance Manager jobs? States with the most job openings for Information Security Governance Manager jobs include:
Infographic showing various Information Security Governance Manager job openings in the United States as of July 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $136,104 per year, or $65.4 per hour.
Sr Information Security GRC Analyst

Sr Information Security GRC Analyst

Masimo

Irvine, CA

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 21 days ago


Job description

  Job Summary:

The Senior Information Security GRC Analyst supports and advances Masimo's enterprise information security governance, risk, and compliance (GRC) program through leadership of security compliance initiatives, third-party risk management, policy governance, audit readiness, and risk assessment activities.
This role partners closely with Information Security, IT, Engineering, Quality, Legal, and business stakeholders to strengthen security governance processes, support regulatory and customer requirements, and maintain alignment with industry frameworks and healthcare security expectations.
The Senior Information Security GRC Analyst contributes to the continuous improvement of governance processes, compliance monitoring, and enterprise risk management activities within a regulated healthcare and medical device environment. This position requires strong knowledge of information security principles, compliance frameworks, and risk management practices, along with the ability to communicate effectively across both technical and non-technical audiences

Duties & Responsibilities:

    Support the strategic execution and continuous improvement of the enterprise information security governance, risk, and compliance (GRC) program  
    Lead coordination of external security audits and certification activities, including HITRUST, ISO 27001, SOC 2, and related compliance initiatives 
    Partner with internal stakeholders to gather documentation, evidence, remediation updates, and corrective action plans for audits and assessments 
    Conduct third-party and supply chain cybersecurity risk assessments, including evaluation of vendor security posture, due diligence questionnaires, and supporting security documentation 
    Collaborate with business and technical teams to respond to customer security assessments, compliance inquiries, and due diligence requests 
    Lead information security risk assessments and track remediation activities through resolution 
    Manage the review and tracking of security exceptions and risk acceptance requests, ensuring appropriate compensating controls and approvals are documented 
    Assist in the development, maintenance, and communication of information security policies, standards, procedures, and guidelines 
    Collaborate with technical teams to evaluate, document, and validate security controls and compliance requirements 
    Maintain audit findings, remediation plans, compliance documentation, risk registers, and governance tracking records 
    Develop and maintain compliance monitoring processes, governance reporting metrics, dashboards, and ongoing reporting activities 
    Conduct internal security assessments, readiness reviews, and governance maturity initiatives 
    Support governance and risk management activities related to cloud platforms, SaaS environments, emerging technologies, and evolving cybersecurity threats 
    Partner with leadership and cross-functional stakeholders to promote a risk-aware security culture and support enterprise governance initiatives 
    Stay informed of evolving cybersecurity threats, regulatory requirements, and industry best practices relevant to healthcare and medical device environments 
    Support cross-functional initiatives related to information security awareness, governance, operational maturity, and compliance readiness
Minimum & Preferred Qualifications and Experience: 
 

Minimum Qualifications:


    7+ years of experience in information security governance, risk, and compliance (GRC), cybersecurity risk management, IT audit, compliance, or related areas 
    Experience leading or managing security audits or compliance initiatives related to HITRUST, ISO 27001, SOC 2, NIST, or similar frameworks 
    Experience conducting third-party security assessments and vendor risk reviews 
    Strong understanding of information security principles, risk management concepts, and security control frameworks 
    Ability to understand and discuss technical security concepts including identity and access management (IAM), encryption, vulnerability management, endpoint security, logging/monitoring, cloud security, and network security 
    Strong analytical, organizational, documentation, communication, and stakeholder management skills 
    Ability to manage multiple priorities and work collaboratively in a fast-paced, highly regulated environment
Preferred Qualifications:
    Experience within healthcare, medical device, biotechnology, or other highly regulated industries 
    Familiarity with HIPAA, FDA-regulated environments, HITRUST, NIST CSF, PCI DSS, UK Cyber Essentials, NIS2 Directive, or related cybersecurity and privacy requirements 
    Experience using GRC tools and platforms for audit, compliance, risk management, or governance reporting activities 
    Experience supporting enterprise security governance or compliance maturity initiatives 
    Industry-recognized certifications such as CISSP, CISA, CRISC, CISM, or similar preferred
Education:


Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, or related field required; or equivalent combination of education, certifications, and relevant experience 
 

Language requirements:

    Ability to read, write, and communicate effectively in English.
    Ability to interpret technical documents, schematics, and written instructions.
    Ability to clearly document technical findings and communicate with cross-functional team members.

Compensation: 

The anticipated range for this position is $130,000 - $170,000. Actual placement within the range is dependent on multiple factors, including but not limited to skills, education, and experience. This position also qualifies for up to 10% annual bonus based on Company, department, and individual performance.

Masimo offers benefits such as Medical, Dental, Vision, Life/AD&D, Disability Insurance, 401(k), Vacation, Sick, Holiday, Paid Maternity Leave, Flexible Spending Accounts, voluntary Accident, Critical Illness, Hospital, Long-Term Care, Employee Assistance Program, Pet Insurance, on-site Wellness Clinic, Fitness Center, Cafe. All benefits are subject to eligibility requirements.

Physical requirements/Work Environment 


This position primarily works in an office environment and requires frequent sitting, standing, and walking. Daily use of a computer and other digital devices is required. This role may require standing for extended periods when facilitating meetings or walking through facilities.
The physical demands of the position described herein are essential functions of the job and employees must be able to successfully perform these tasks for extended periods.  Reasonable accommodations may be made for those individuals with real or perceived disabilities to perform the essential functions of the job described.
Masimo is proud to be an EEOE/, M/F/D/V, and we are committed to Diversity at the corporate level.             
 


Masimo logo

About Masimo

Sourced by ZipRecruiter

Industry

Medical equipment and supplies manufacturing

Company size

1,001 - 5,000 Employees

Headquarters location

Irvine, CA, US

Year founded

1989

Social media