1

Information Security Manager Jobs in Decatur, AL

IT Manager

Huntsville, AL

$93.60K - $114.80K/yr

The IT Manager will be responsible for leading and executing IT initiatives with a strong focus on AI, RPA, and information security, while supporting business operations through system development ...

... Compartmented Information (SCI) programs, while maintaining strict compliance with applicable ... management of security support across multiple contracts, ensuring the effective implementation of ...

next page

Showing results 1-20

People also search for

Information Security Manager information

See Decatur, AL salary details

$58.6K

$127.6K

$187.5K

How much do information security manager jobs pay per year?

As of May 31, 2026, the average yearly pay for information security manager in Decatur, AL is $127,591.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,600.00 and $150,500.00 per year, depending on experience, location, and employer.

What Is an Information Security Manager?

The job duties of an information security manager involve overseeing the effort to protect networks, computers, and data from cyber attacks, viruses, and other security breaches. In this career, your responsibilities include creating IT security features that can protect your company’s data. In addition to building systems to protect against hacking, you must also be ready to lead the response when a security breach occurs. As an information security manager, you are responsible for creating and implementing practices and policies that employees can use to protect their employer's networks and data.

What are the key skills and qualifications needed to thrive as an Information Security Manager, and why are they important?

To thrive as an Information Security Manager, you need a strong understanding of cybersecurity principles, risk management, and regulatory compliance, typically backed by a relevant degree and professional certifications like CISSP or CISM. Familiarity with security information and event management (SIEM) systems, vulnerability assessment tools, and incident response frameworks is essential. Leadership, strategic thinking, and excellent communication skills help you effectively manage teams and convey complex security concepts to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring regulatory compliance, and maintaining business continuity.

What are some common challenges Information Security Managers face when implementing new security protocols within an organization?

Information Security Managers often encounter resistance to change from staff when introducing new security protocols, as these measures can sometimes disrupt established workflows. Balancing security requirements with business needs is also a frequent challenge, requiring negotiation and effective communication across departments. Additionally, staying ahead of constantly evolving threats and ensuring that all team members are properly trained can be demanding, but overcoming these challenges is crucial for maintaining a robust security posture.

What does an Information Security Manager do?

An Information Security Manager is responsible for overseeing an organization's information security program, ensuring that sensitive data is protected from threats such as cyberattacks and unauthorized access. They develop and implement security policies, conduct risk assessments, and manage teams to respond to security incidents. Information Security Managers also ensure compliance with relevant laws and regulations and regularly educate staff on best security practices. Their role is critical in maintaining the confidentiality, integrity, and availability of information assets.

What is the difference between Information Security Manager vs Security Analyst?

AspectInformation Security ManagerSecurity Analyst
CertificationsCISSP, CISM, CISACompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security policies, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with dedicated security teams across industriesCommon in IT departments, security operations centers

The main difference is that the Information Security Manager focuses on strategic security management and team leadership, while the Security Analyst handles day-to-day security monitoring and threat analysis. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and responsibilities.

What cities near Decatur, AL are hiring for Information Security Manager jobs? Cities near Decatur, AL with the most Information Security Manager job openings:

Info Systems Security Mgr

Systems Planning and Analysis

Huntsville, AL • On-site

Full-time

Retirement

Posted 7 days ago


Job description

Overview
Intrepid, an SPA Company, brings more than 20 years of experience supporting the Department of Defense and U.S. Government, consistently setting the standard for excellence in the federal marketplace. Committed to advancing the mission of the U.S. Warfighter, Intrepid leverages technological superiority to deliver innovative solutions across air, space, land, and sea domains. We are proud to foster a collaborative, dynamic work environment, offering competitive compensation and an industry-leading 401k contribution. Our team is built through merit and achievement, and we're always looking for the best and brightest to join us in our growth. We treat our people like family, we are mission-focused, and we give back! Join us today.
The Cybersecurity Team under Intrepids's Information Technology Department establishes and maintains a robust cybersecurity posture and policy architecture across Intrepid's information systems. The team manages cyber policy, develops control implementations and system security plans, continuously monitors systems, and performs routine cyber operations including patching, auditing, and incident response. Cybersecurity is critical to Intrepid's mission, therefore we strive to offer secure solutions that ensure data is protected while meeting the needs of the business.
In this role, you will serve as the Information Systems Security Manager for multiple systems operating under Intrepid's Army Integrated Engineering Group (AIEG). This requires the individual to operate with autonomy while interfacing directly with ISSOs, Administrators, clients, and leaders overseeing the business unit's operation.
SPA has an immediate need for an Information Systems Security Manager. #KS
Responsibilities
With minimal supervision, the Information System Security Manager (ISSM) maintains day-to-day Cybersecurity posture and continuous monitoring of classified information systems. The ISSM conducts reviews and technical inspections to identify and mitigate potential security weaknesses and ensure that all security features applied to a system are implemented and functional. In this role, you will report to the Deputy CISO while preparing and maintaining security Assessment and Authorization (A&A) documentation, performing audits, leading incident response activities, interfacing with Government personnel, and maintaining a thorough understanding of NIST 800-53 controls and other Government directed actions. As the ISSM, you will be expected to collaborate with Intrepid and Government members to respond to data calls, support technical reviews and formal government-driven assessments.
Qualifications
Required Qualifications:
  • Active Secret security clearance
  • Master's degree in an Information Technology related field or a Bachelor's degree with equivalent work experience and certifications
  • Minimum of 10 years' experience in information system security with 5 or more year's direct experience as an ISSM, ISSP, Security Control Assessor (SCA), or equivalent position
  • Must meet Department of Defense 8140 certification requirements at IAM Level II; acceptable certifications include CISSP, CISM, GSLC, and CAP
  • A minimum of 3 years of direct experience with RMF artifacts, obtaining and maintaining system ATOs, and implementing new and complex technologies at multiple classification levels within large enterprise environments
  • A minimum of 3 years of direct experience performing a continuous monitoring and the cybersecurity hygiene of windows/linux domains and network enclaves
  • A minimum of 5 years of direct experience working with federal/government agencies in sensitive and classified environments
  • A minimum of 3 years of direct experience with Risk Management Framework (RMF), NIST 800-53, DAAPM or DAAG, and other legal and regulatory guidance
  • Ability to exercise independent judgment and to work autonomously with minimal supervision

Desired Qualifications:
  • Experience configuring systems for compliance using a myriad of Security Technical Implementation Guides (STIGs) and STIG Viewer
  • Direct experience managing Government inspections of classified systems including Command Cyber Readiness Inspections (CCRIs) and Cybersecurity Operational Readiness Assessments (CORAs)
  • Direct experience managing the system lifecycle of connected classified systems including Secret Defense Research and Engineering Network (SDREN) and Secret Internet Protocol Router Network (SIPRNET) systems