1

Information Security Management Jobs (NOW HIRING)

Description: As the Information Security Manager, you will lead the strategic development and ... Risk Management & Governance: Lead comprehensive risk assessments and vendor security reviews to ...

Description: As the Information Security Manager, you will lead the strategic development and ... Risk Management & Governance: Lead comprehensive risk assessments and vendor security reviews to ...

This position performs activities that are critical to managing IT security risk; and assist in creating an internal culture of privacy and security that preserve the confidentiality, integrity, and ...

Showing results 41-60

Information Security Management information

See salary details

$62.5K

$136.1K

$200K

How much do information security management jobs pay per year?

As of Aug 12, 2026, the average yearly pay for information security management in the United States is $136,104.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,500.00 and $160,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an information security management professional, and why are they important?

To thrive in Information Security Management, you need a solid understanding of cybersecurity principles, risk assessment, and compliance frameworks, often backed by a degree in information technology or a related field. Familiarity with tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, leadership, and communication skills help you effectively manage teams and convey security policies. These competencies are crucial for protecting organizational assets, ensuring regulatory compliance, and responding proactively to security threats.

What is information security management?

Information Security Management refers to the processes and policies put in place to protect an organization's information assets from threats such as unauthorized access, data breaches, and cyberattacks. It involves identifying risks, implementing security controls, and ensuring compliance with relevant regulations and standards. Effective information security management helps organizations safeguard sensitive data, maintain business continuity, and build trust with clients and stakeholders.

What is the difference between Information Security Management vs Security Analyst?

AspectInformation Security ManagementSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentStrategic, policy development, management teamsOperational, monitoring security systems, incident response
Employer & Industry UsageOrganizations implementing security frameworks, management rolesIT departments, security teams, cybersecurity firms

While both roles focus on cybersecurity, Information Security Management involves overseeing security policies, strategies, and compliance at a managerial level. Security Analysts primarily handle day-to-day security monitoring, threat detection, and incident response. The management role is more strategic, whereas the analyst role is operational, but both require relevant certifications and work within the same industry environment.

What do information security managers do?

Information security managers oversee an organization’s cybersecurity strategy, develop policies to protect data and systems, and coordinate security efforts across teams. They analyze risks, implement security measures, and ensure compliance with regulations, often using tools like firewalls and intrusion detection systems. Strong leadership, technical knowledge, and certifications such as CISSP are common requirements for this role.

What are some common challenges faced by professionals in information security management, and how can they be addressed?

Professionals in Information Security Management often face challenges such as balancing security requirements with business goals, keeping up with evolving cyber threats, and ensuring employee compliance with security policies. To address these, effective communication with stakeholders, ongoing employee training, and regular risk assessments are critical. Additionally, fostering a culture of security awareness and collaborating closely with IT, legal, and business teams can help proactively manage risks and ensure organizational resilience.
More about Information Security Management jobs
What states have the most Information Security Management jobs? States with the most job openings for Information Security Management jobs include:
What job categories do people searching Information Security Management jobs look for? The top searched job categories for Information Security Management jobs are:
Infographic showing various Information Security Management job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $136,104 per year, or $65.4 per hour.

Information Security Manager

OneArc

Pittsburgh, PA • On-site

Full-time

Re-posted 27 days ago


Job description

Description:
As the Information Security Manager, you will lead the strategic development and oversight of our organization's cybersecurity program within a fast-paced software development environment. You will be responsible for defining security roadmaps, managing risk across our software delivery pipeline, and ensuring our products meet the highest standards of data protection. You will bridge the gap between technical engineering teams and executive leadership, translating complex security threats into actionable business risk assessments. This role is pivotal in maintaining our competitive edge by ensuring that security is a core component of our brand and customer trust.
Key Areas of Responsibility:
  • Security Program Leadership: Design and manage the enterprise-wide information security strategy, aligning security initiatives with software development lifecycles (SDLC) and business goals.
  • Risk Management & Governance: Lead comprehensive risk assessments and vendor security reviews to identify and mitigate vulnerabilities across third-party integrations and internal systems.
  • DevSecOps Integration: Collaborate with engineering leads to integrate security automation (SAST/DAST) into CI/CD pipelines, promoting a "shift-left" security culture.
  • Incident Response Management: Oversee the security incident response program, acting as the primary point of escalation and lead investigator during high-priority security events.
  • Regulatory & Compliance Oversight: Ensure continuous compliance with industry-standard frameworks such as SOC2, ISO 27001, and GDPR, managing external audits and certification processes.
  • Security Awareness & Culture: Develop and lead security training programs for non-technical staff and specialized secure-coding workshops for developers.
  • Stakeholder Communication: Present regular security posture reports to senior management and board members, providing data-driven recommendations for security investments.

Objectives:
  • Maintain the confidentiality, integrity, and availability of our SaaS platforms and customer data environments.
  • Minimize organizational risk by implementing robust security controls across the software development and deployment processes.
  • Achieve and maintain industry-leading security certifications (e.g., SOC2 Type II, ISO 27001, NIST) along with compliance with our parent company's policies
  • Foster a proactive security-first mindset across all departments through education and transparent reporting.

Skills:
  • Strategic Leadership: Ability to lead technical teams and influence organizational change without direct authority.
  • Complex Problem-Solving: Expert at analyzing evolving cyber threats and designing creative, scalable mitigation strategies.
  • Effective Communication: Translating deeply technical security vulnerabilities into business-impact terms for executive stakeholders.
  • Regulatory Knowledge: Deep understanding of software-relevant compliance standards (NIST, SOC2, ISO).
  • Technical Proficiency: Familiarity with cloud security (AWS/Azure/GCP), containerization, and automated security testing tools.

Education and Experience:
  • Bachelor's degree in Computer Science, Cybersecurity, Management Information Systems, or a related field.
  • Master's degree in a specific area of specialization, such as IT security, may be beneficial.
  • 7-10+ years of experience in information security, with at least 3 years in a leadership or management capacity.
  • Proven experience in a software development or "Software as a Service" (SaaS) environment.
  • Relevant Certifications: CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) is highly preferred.

Additional Attributes:
  • Innovative and creative thinking: Ability to anticipate future security trends and prepare the organization accordingly.
  • Composure: Ability to work in a fast-paced environment and remain calm during active security incidents.
  • Strong attention to detail: Ensuring precision in security policy and implementation.
  • Empathy: Balances the need for strict security controls with developers' operational needs to remain productive.

Travel:
  • Occasional travel between Orlando and Pittsburgh offices or for security conferences and audits.