1

Information Security Manager Jobs in Nebraska (NOW HIRING)

Certified Information Security Manager (CISM) * Certified Internal Auditor (CIA) * GIAC Systems and Network Auditor (GSNA) SKILLS/KNOWLEDGE/ABILITIES: * Understanding of and familiarity with ...

Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP ...

next page

Showing results 1-20

Information Security Manager information

See Nebraska salary details

$59.6K

$129.8K

$190.7K

How much do information security manager jobs pay per year?

As of Aug 14, 2026, the average yearly pay for information security manager in Nebraska is $129,768.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,400.00 and $153,000.00 per year, depending on experience, location, and employer.

What are some common challenges information security managers face when implementing new security protocols within an organization?

Information Security Managers often encounter resistance to change from staff when introducing new security protocols, as these measures can sometimes disrupt established workflows. Balancing security requirements with business needs is also a frequent challenge, requiring negotiation and effective communication across departments. Additionally, staying ahead of constantly evolving threats and ensuring that all team members are properly trained can be demanding, but overcoming these challenges is crucial for maintaining a robust security posture.

What is the difference between Information Security Manager vs Security Analyst?

AspectInformation Security ManagerSecurity Analyst
CertificationsCISSP, CISM, CISACompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security policies, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with dedicated security teams across industriesCommon in IT departments, security operations centers

The main difference is that the Information Security Manager focuses on strategic security management and team leadership, while the Security Analyst handles day-to-day security monitoring and threat analysis. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and responsibilities.

What does an information security manager do?

An Information Security Manager is responsible for overseeing an organization's information security program, ensuring that sensitive data is protected from threats such as cyberattacks and unauthorized access. They develop and implement security policies, conduct risk assessments, and manage teams to respond to security incidents. Information Security Managers also ensure compliance with relevant laws and regulations and regularly educate staff on best security practices. Their role is critical in maintaining the confidentiality, integrity, and availability of information assets.

What is an information security manager?

The job duties of an information security manager involve overseeing the effort to protect networks, computers, and data from cyber attacks, viruses, and other security breaches. In this career, your responsibilities include creating IT security features that can protect your company’s data. In addition to building systems to protect against hacking, you must also be ready to lead the response when a security breach occurs. As an information security manager, you are responsible for creating and implementing practices and policies that employees can use to protect their employer's networks and data.

What are the most commonly searched types of Information Security jobs in Nebraska?

The most popular types of Information Security jobs in Nebraska are:

What are popular job titles related to Information Security Manager jobs in Nebraska?

For Information Security Manager jobs in Nebraska, the most frequently searched job titles are:

What job categories do people searching Information Security Manager jobs in Nebraska look for?

The top searched job categories for Information Security Manager jobs in Nebraska are:

What cities in Nebraska are hiring for Information Security Manager jobs?

Cities in Nebraska with the most Information Security Manager job openings:

Infographic showing various Information Security Manager job openings in Nebraska as of August 2026, with employment types broken down into 84% Full Time, 5% Part Time, and 11% Contract. Highlights an 95% In-person, and 5% Remote job distribution, with an average salary of $129,768 per year, or $62.4 per hour.

Director of Information Security

Sorren, Inc.

Lincoln, NE

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 9 days ago


Job description

Our Firm
Sorren is a top 50 national advisory firm that blends deep expertise with a human-first approach. We don’t just work with numbers—we work with people, building lasting relationships and delivering strategic solutions in accounting, assurance, tax, advisory, and private client services. 


At Sorren, we believe that success is a shared journey. Our culture fosters collaboration, innovation, and professional growth, ensuring that every team member has the support and opportunities they need to thrive. We offer a high-performing yet balanced work environment where career development and personal well-being go hand in hand. 


We’re committed to helping you grow, whether that means advancing your career, expanding your expertise, or achieving a fulfilling work-life balance. Because at Sorren, your success is our success. 


Your Journey
Our team members support the firm by delivering timely, accurate work and maintaining clear communication. They take ownership of their development, seek feedback, and build strong relationships. By managing responsibilities effectively and aligning their efforts with firm values, they establish a foundation for long-term success and growth.  All team members are expected to excel in Relationships, Communication, Quality Service, Operational Excellence, and Innovation & Growth, contributing to the firm’s success through collaboration, exceptional service, and continuous growth.
 

Position Summary:

Key Responsibilities:

•    Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations.
•    Define the security configuration and hardening standards for Microsoft 365 and Entra ID and work in conjunction with the infrastructure team to ensure they are met.
•    Set the AV and EDR configuration baseline and make sure security alerting and reporting scale as we grow.
•    Define and put in place data protection controls across platforms, including classification, retention, encryption, and DLP.
•    Set our email filtering and security posture standards and work with the infrastructure team to ensure they are met. Oversee firewall and network-device patch and update compliance.
•    Maintain security policies, technical standards, controls, exceptions, and mature how we audit against them.
•    Lead risk assessments[JD1.1], control reviews, and security planning activities across the firm’s infrastructure, applications, endpoints, and cloud services.  This includes identifying risks, prioritizing remediation, tracking corrective actions, and validating closure
•    Own risk register and tracking and run security and vendor risk assessments as the practice matures.
•    Build and run the firm’s GLBA and FTC Safeguards program, accounting for other requirements such as HIPAA, PCI DSS, and state privacy laws (for example CCPA and CPRA) where applicable.
•    Support client security reviews, cyber insurance requirements, and regulatory or contractual compliance efforts by preparing evidence, documenting controls, and coordinating remediation plans.
•    Set up recurring system access reviews and support internal and external audit needs, including evidence collection.
•    Maintain the incident response plan and be the point person for incident response activities, including any communication, coordinating external responders, and documentation. 
•    Plan and facilitate periodic incident response tabletop exercises and post-exercise improvement activities.
•    Run and coordinate vulnerability scans and penetration tests and track remediation to closure.
•    Own the security awareness and phishing simulation program, including strategy, reporting, and continuous improvement.
•    Evaluate, direct, and hold managed-security and security-tool vendors accountable for results, while continuously assessing the effectiveness of current security partnerships and recommending changes where appropriate.
•    Conduct security and risk assessments of proposed software, services, and vendor relationships as part of the software request and approval process.
•    Take part in security due diligence on acquisition targets and document their security posture to inform integration.
•    Maintain awareness of evolving cyber threats, regulatory developments, and leading practices relevant to professional services and accounting firms, and translate them into practical improvements.


Required Qualifications:

•    7+ years of progressive IT and security experience, including 3 or more years hands on in information security. 
•    Proven ability to plan security controls and implement them yourself.
•    Deep hands-on experience securing Microsoft 365 and Entra ID (Conditional Access, MFA, Microsoft Defender, mail-flow and email authentication) and managing endpoints with Intune.
•    Practical experience with EDR and AV, vulnerability scanning, access reviews, and coordinating incident response.
•    A track record of delivering results through managed-security and vendor partners, including evaluating them, directing their work, and holding them accountable.
•    Working knowledge of regulatory and compliance requirements for financial or professional services data, including GLBA and FTC Safeguards and general privacy and compliance frameworks.
•    Experience maintaining security policies and a risk register and turning them into implemented controls.
•    Strong communication and collaboration skills, with the ability to coordinate across the Infrastructure, Support, and business teams to get changes done.

Preferred Qualifications:

•    Experience in professional services, accounting, or another regulated, financial-data environment.
•    Experience integrating or standardizing security across a multi-location or acquisitive (M&A) organization.
•    Familiarity with hosted or virtual desktop platforms and the vendor management that goes with them.
•    Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials.

Compensation range for this role is $135,000 - $160,000.

Actual compensation is influenced by a variety of factors including but not limited to skills, experience, qualifications, and geographic location. Discretionary incentive compensation is based on firm, group, and individual performance.

Why Choose Us? 

At Sorren, we’re invested in your growth—both personally and professionally. We’ll support you as you advance in your career while also giving you the flexibility to enjoy life outside of work. We believe balance fuels success, and we’ve designed our culture and benefits to reflect that.


What We Offer*:

  • Generous paid time off
  • Comprehensive medical, dental, and vision coverage, plus life and disability insurance
  • 401(k) retirement savings plan
  • Paid holidays, including a firmwide winter break (December 24 – January 1)
  • Paid parental leave (available after one year of service)
  • Mentorship and career development programs
  • CPA exam support to help you succeed on the path to licensure
  • Firm-sponsored events and spontaneous team activities
  • Celebrations to mark milestones like the end of busy season and the holidays

*Benefits are available to full-time employees regularly scheduled to work at least 30 hours per week.


© 2025 “Sorren” is the brand name under which Sorren CPAs, P.C. and Sorren, Inc. and its subsidiary entities provide professional services. Sorren CPAs P.C. and Sorren, Inc. and its subsidiary entities practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable laws, regulations, and professional standards. Sorren CPAs P.C. is a licensed independent CPA firm that provides attest services to its clients, and Sorren, Inc. and its subsidiary entities provide tax and business consulting services to their clients. Sorren, Inc. and its subsidiary entities are not licensed CPA firms.