1

Information Security Manager Jobs in Raleigh, NC

Manager,Information Security Risk -Governance, Risk, Compliance - Audit - Hybrid, Cary, North Carolina We're a leader in data and AI. Through our software and services, we inspire customers around ...

Security Operations Analyst Associate Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Certified Ethical Hacker (CEH) GIAC Security ...

Cyber - AWS Cloud Security - Manager

Raleigh, NC Β· On-site

$107K - $145K/yr

Manage security assessments, architecture reviews, and remediation planning for cloud environments ... Bachelor's degree * 6+ years of experience in cybersecurity, information security, or cloud ...

... along with IT services to small to medium size companies. AG's primary objective is to help ... security, management, and auditors. Excellent troubleshooting skills, self-motivated, results ...

InfoSec GRC - Senior Manager

Cary, NC Β· On-site

$98K - $133K/yr

Strong experience in common information security management frameworks, such as International Standards Organization (ISO) 2700x, National Institute of Standards and Technology (NIST) 800-53 ...

InfoSec GRC - Senior Manager

Cary, NC Β· Hybrid

$104K - $142K/yr

Strong experience in common information security management frameworks, such as International Standards Organization (ISO) 2700x, National Institute of Standards and Technology (NIST) 800-53 ...

Showing results 21-40

Information Security Manager information

See Raleigh, NC salary details

$60.8K

$132.3K

$194.4K

How much do information security manager jobs pay per year?

As of Sep 15, 2026, the average yearly pay for information security manager in Raleigh, NC is $132,304.00, according to ZipRecruiter salary data. Most workers in this role earn between $107,400.00 and $156,000.00 per year, depending on experience, location, and employer.

What is an information security manager?

The job duties of an information security manager involve overseeing the effort to protect networks, computers, and data from cyber attacks, viruses, and other security breaches. In this career, your responsibilities include creating IT security features that can protect your company’s data. In addition to building systems to protect against hacking, you must also be ready to lead the response when a security breach occurs. As an information security manager, you are responsible for creating and implementing practices and policies that employees can use to protect their employer's networks and data.

What does an information security manager do?

An Information Security Manager is responsible for overseeing an organization's information security program, ensuring that sensitive data is protected from threats such as cyberattacks and unauthorized access. They develop and implement security policies, conduct risk assessments, and manage teams to respond to security incidents. Information Security Managers also ensure compliance with relevant laws and regulations and regularly educate staff on best security practices. Their role is critical in maintaining the confidentiality, integrity, and availability of information assets.

What are some common challenges information security managers face when implementing new security protocols within an organization?

Information Security Managers often encounter resistance to change from staff when introducing new security protocols, as these measures can sometimes disrupt established workflows. Balancing security requirements with business needs is also a frequent challenge, requiring negotiation and effective communication across departments. Additionally, staying ahead of constantly evolving threats and ensuring that all team members are properly trained can be demanding, but overcoming these challenges is crucial for maintaining a robust security posture.

What is the difference between Information Security Manager vs Security Analyst?

AspectInformation Security ManagerSecurity Analyst
CertificationsCISSP, CISM, CISACompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security policies, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with dedicated security teams across industriesCommon in IT departments, security operations centers

The main difference is that the Information Security Manager focuses on strategic security management and team leadership, while the Security Analyst handles day-to-day security monitoring and threat analysis. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and responsibilities.

What are the most commonly searched types of Information Security jobs in Raleigh, NC?

The most popular types of Information Security jobs in Raleigh, NC are:

What are popular job titles related to Information Security Manager jobs in Raleigh, NC?

For Information Security Manager jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Information Security Manager jobs in Raleigh, NC look for?

The top searched job categories for Information Security Manager jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Information Security Manager jobs?

Cities near Raleigh, NC with the most Information Security Manager job openings:

Infographic showing various Information Security Manager job openings in Raleigh, NC as of August 2026, with employment types broken down into 100% Full Time. Highlights an 79% In-person, and 21% Remote job distribution, with an average salary of $132,304 per year, or $63.6 per hour.

Manager, GRC-A (Information Security Risk)

Cary, NC β€’ On-site

Sas
Software DevelopmentΒ β€’Β 10K+ employees

Other

Medical, Dental, Vision, Retirement, PTO

This job post hasΒ expired 1 day ago.Β Applications are no longer accepted.


Job description

Manager,Information Security Risk -Governance, Risk, Compliance – Audit - Hybrid, Cary, North Carolina

We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.

If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more.

About the job

The Manager, Governance, Risk, Compliance – Audit (GRC-A) is a hands on management role combiningtechnical risk managementexpertisewith people leadership, overseeing a team that evaluatesinformation security andcybersecurity risksacrossSAS and ourthird-parties.As a working manager, the positionisactively involved inrisk analysisand problem-solving while also guiding program execution, stakeholder engagement, and continuous improvement efforts.

The Governance, Risk, Compliance - Audit team provides independent assessment and advisory services,facilitatescompliance with regulatory and security requirements, performs assurance activities, and delivers information that enables informed business and risk decisions. Through collaboration, innovation, and practical risk management, the team helps protect SAS while enabling business success.

you will:
  • Lead and continuously mature the information security risk management andthird-partysecurity risk assessment programs, providing direction to team members while driving initiatives that enhance SAS's risk managementprogram.
  • Partner with business, technology, and service provider stakeholders toidentify, assess,monitor, and manage information securityrisks.
  • Monitor evolving regulatory and industry requirements affecting cybersecurity, technology risk, privacy, operational resilience, and third-party risk management, and incorporate applicable requirements into program practices.
Internal Information Security Risk
  • Perform information security risk assessments and document threats, vulnerabilities, controls, and residual risks across internal systems, cloud services, third-party vendors, and enterprise initiatives.
  • Oversee risk assessment activities and risk treatment plans, ensuring clear ownership,timelyremediation, and accountability for mitigation actions.
  • Maintain and enhance risk management methodologies, risk scoring models, governance processes, and therisk register to support consistent and effective risk decision-making.
  • Define, track, and communicate cybersecurity risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reportingfor senior leadership.
Third-Party Risk Management (TPRM) –Information Security
  • Managethethird-partysecurity risk assessment team, providing guidance on complex assessments and ensuring cybersecurity, privacy, compliance, and operational risks are consistentlyidentified, evaluated, reported, and managed.
  • Collaborate with Procurement, Legal, and Third-Party Risk Management (TPRM) stakeholders to integrate security and compliance requirements throughout vendor onboarding, contracting, and ongoing oversight processes.
  • Define, track, and communicate third-party security risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for seniorleadership.Embracecuriosity, passion,authenticityand accountability. These are our values and influence everything we do.
Required qualifications
  • Bachelor'sorMaster’s degree in Business, IT, Cybersecurity, ProjectManagementor related field.
  • Typically requires 4-8 years ofdemonstratedsuccess performing riskmanagement.Experience in a regulated (pharmaceutical, banking, insurance, government) industry (may be concurrent with the above functionalexperience).
  • Demonstrated strong management and leadership skills.
  • Excellent awareness ofGRCtooling, such as ServiceNowIRM
  • Excellent ability to handle multiple projects at the same time.
  • Excellent ability to supervise and train employees with varying skill sets in a high-pressure environment.
  • Excellent verbal, written, and interpersonal skills.
  • Demonstrated ability to solve complex problems.
  • Equivalentcombination of related education, training and experience may be considered in place of the above qualifications.
  • Deep understanding of information security risk frameworks (NIST CSF, CRI Profile, PCI DSS, CIS Controls, etc.) and enterprise risk management principles, with practical experience applying them across systems, processes, and third-party vendors.
  • Ability to lead projects from start to finish, working independently, escalating issues, asappropriateand being flexible, when needed.
Additional competencies, knowledge and skills
  • Strategic Planning-Obtains information andidentifieskey issues and relationships relevant to achieving a long-range goal; committing to a course of action toaccomplisha long-range goal after developing alternatives based on logical assumptions, facts, available resources, constraints, and organizational values.
  • Leading Change-Drives organizational and cultural changes needed to achieve strategicobjectives; catalyzingnew approachesto improve results by transforming organizational culture, systems, or products/services; helping others overcome resistance to change
  • Global Perspective-Demonstrates awareness of and sensitivity to the international market, cultural, technological, political, and legal factors that impact individual and work group priorities and results; leveraging own understanding of the organization’s global strategy, global business trends, and regional differences to enhance individual and work group results.
  • Ability to interview and manage staff, providingappropriate trainingand guidance as well as ongoing performance management.
  • Strong management, leadership, and executive presentation skills.
  • Experience applying enterprise risk management (ERM) principles and methodologies to identify, assess, prioritize, and communicate technology, cybersecurity, operational, or third-party risks.
  • Ability to build strong partnerships with security and technology teams across the enterprise.
World-class benefits

Highlights include...

  • Comprehensive medical, prescription, dental and vision plans.
  • Medical plan options include:
    • PPO with low annual deductible and copays.
    • HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
  • Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
  • An industry-leading 401k plan.
  • Tuition Assistance Program and programs and resources to support your development
  • Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
  • Volunteer Time Off, parental leave and unlimited paid sick days.
  • Generous childcare benefits for all full-time employees.
You are welcome here.

At SAS, it’s not about fitting into our culture – it’s about adding to it. We believe our people make the difference. Our inclusive workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers.

Additional Information:

To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer. All qualified applicants are considered for employment without regard to any characteristic protected by law. Read more: Know Your Rights.

#J-18808-Ljbffr