1

Information Security Program Manager Jobs in Bothell, WA

Strong background and experience in policy development, program administration. In depth knowledge ... Intrusion Detection / Prevention Systems for networks and hosts Security Event Management Systems ...

Identify and report noncompliance issues to the appropriate Security Program Manager and Security ... Familiarity with personnel security, physical security, information security, or operations ...

Identify and report noncompliance issues to the appropriate Security Program Manager and Security ... Familiarity with personnel security, physical security, information security, or operations ...

Experience conducting and supporting security awareness training programs. * Experience securing ... Exposure to identity and access management (IAM) concepts or tools. * Familiarity with a scripting ...

Triage and respond to security alerts from our Managed Detection & Response (MDR) service, as well ... Experience supporting vulnerability remediation programs, including remediation tracking and ...

... management, and access governance * Design and run the security awareness program - onboarding ... years in information security * You've owned a compliance program end-to-end and not just ...

next page

Showing results 1-20

Information Security Program Manager information

See Bothell, WA salary details

$60.9K

$166.6K

$186.7K

How much do information security program manager jobs pay per year?

As of Aug 30, 2026, the average yearly pay for information security program manager in Bothell, WA is $166,580.00, according to ZipRecruiter salary data. Most workers in this role earn between $144,200.00 and $175,500.00 per year, depending on experience, location, and employer.

What is an information security program manager?

An Information Security Program Manager is responsible for overseeing and coordinating an organization’s information security initiatives. They develop, implement, and manage security policies, procedures, and programs to protect an organization's data and IT systems from threats. Their role often involves risk assessment, compliance management, incident response coordination, and ensuring that security strategies align with business objectives. Information Security Program Managers work closely with IT teams, leadership, and external partners to maintain robust security postures.

What are some typical challenges faced by information security program managers when implementing new security initiatives across an organization?

Information Security Program Managers often encounter challenges such as gaining buy-in from stakeholders, navigating organizational resistance to change, and balancing security needs with business objectives. They must coordinate with various departments to ensure consistent adherence to security policies and effectively communicate the value of new initiatives. Additionally, they manage competing priorities and tight deadlines while ensuring compliance with regulatory requirements and industry standards.

What are the key skills and qualifications needed to thrive as an information security program manager, and why are they important?

To thrive as an Information Security Program Manager, you need in-depth knowledge of cybersecurity frameworks, risk management, and governance, typically supported by a bachelor’s degree in a related field and certifications like CISSP or CISM. Familiarity with security information and event management (SIEM) tools, vulnerability assessment platforms, and compliance management systems is crucial. Exceptional leadership, communication, and project management skills help you drive cross-functional initiatives and foster a strong security culture. These competencies are vital for effectively mitigating security risks, ensuring regulatory compliance, and aligning security programs with organizational goals.

What is the difference between Information Security Program Manager vs Security Analyst?

AspectInformation Security Program ManagerSecurity Analyst
CertificationsCISSP, CISM, PMPCompTIA Security+, CISSP (optional)
Work EnvironmentOversees security programs, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with complex security needs, corporate sectorsCommon in IT departments, security operations centers

The main difference is that an Information Security Program Manager focuses on managing and coordinating security initiatives at a strategic level, while a Security Analyst primarily monitors and analyzes security threats to protect systems. The Program Manager leads security programs, whereas the Analyst executes security measures and responds to incidents.

What cities near Bothell, WA are hiring for Information Security Program Manager jobs?

Cities near Bothell, WA with the most Information Security Program Manager job openings:

Infographic showing various Information Security Program Manager job openings in Bothell, WA as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 21% Part Time, 1% Temporary, and 3% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $166,580 per year, or $80.1 per hour.

Information Security Manager

Triplenet Technologies

Seattle, WA • On-site

$90 - $124/hr

Other

Posted 18 days ago


Job description

  • Guide security policy and participate in broader Information Security governance efforts.
  • Develop and maintain the Information Security Management System (ISMS) in collaboration with regional information security SMEs and technical consultants.
  • Oversee and manage the ISMS and recommend appropriate mitigating controls.
  • Oversees Information Security Risk Management activities, including risk identification, assessment, and communication to relevant interest holders.
  • Provide valuable expertise and leadership directly to the governing Joint Board executive leadership, including sharing metrics to reflect the performance of the regional security program functions, executive risk score reports, and other guidance on a variety of information security topics.
  • Facilitate a committee of Information Security SMEs across the Agencies to ensure both regional compliance and concurrence on information security-related matters, recommending solutions, and working from the regional perspective to achieve optimal solutions.
  • Collaborate with the Systems Integrator, other vendors, and partner Agencies to ensure security best practices, standards, policies, and regulatory requirements are incorporated into core payment system design, implementation, and sustainment, as well as supportother future phase projects.
  • Conduct regular security reviews of both software and processes, advising on information security practices. Reviews and creates threat models and recommends security enhancements consistent with information security strategy and evolving threats.
  • Support external IT security audits and assessments that focus on operation.
  • Develop, update, implement, and conduct information security training programs to support the ISMS objectives.
  • Manage approvals for Identity and Access Management (IAM) and Access Control Administration.
  • Act as Incident Commander for Security Incident Response activities, whenever the Information Security Incident Response Plan is invoked by the regional program; play an interest holder and oversight role if the plan is invoked by other partners or vendors.
  • Participate in information security incident investigation and response efforts; perform root-cause analysis when incidents occur and prepare incident reports.
  • Evaluate change requests to determine potential impacts to Information Security, including IT systems, processes, policies, and provideappropriate input to the Change Management process.
  • Coach future Regional Operations Team (ROOT) information security personnel as the ISMS becomes complete and mature.
  • Keep up to date on latest information security trends, "best practices", threats, and countermeasures.
Key Responsibilities and Duties:
  • Guide security policy and participate in broader Information Security governance efforts.
  • Develop and maintain the Information Security Management System (ISMS) in collaboration with regional information security SMEs and technical consultants.
  • Oversee and manage the ISMS and recommend appropriate mitigating controls.
  • Oversees Information Security Risk Management activities, including risk identification, assessment, and communication to relevant interest holders.
  • Provide valuable expertise and leadership directly to the governing Joint Board executive leadership, including sharing metrics to reflect the performance of the regional security program functions, executive risk score reports, and other guidance on a variety of information security topics.
  • Facilitate a committee of Information Security SMEs across the Agencies to ensure both regional compliance and concurrence on information security-related matters, recommending solutions, and working from the regional perspective to achieve optimal solutions.
  • Collaborate with the Systems Integrator, other vendors, and partner Agencies to ensure security best practices, standards, policies, and regulatory requirements are incorporated into core payment system design, implementation, and sustainment, as well as supportother future phase projects.
  • Conduct regular security reviews of both software and processes, advising on information security practices. Reviews and creates threat models and recommends security enhancements consistent with information security strategy and evolving threats.
  • Support external IT security audits and assessments that focus on operation.
  • Develop, update, implement, and conduct information security training programs to support the ISMS objectives.
  • Manage approvals for Identity and Access Management (IAM) and Access Control Administration.
  • Act as Incident Commander for Security Incident Response activities, whenever the Information Security Incident Response Plan is invoked by the regional program; play an interest holder and oversight role if the plan is invoked by other partners or vendors.
  • Participate in information security incident investigation and response efforts; perform root-cause analysis when incidents occur and prepare incident reports.
  • Evaluate change requests to determine potential impacts to Information Security, including IT systems, processes, policies, and provideappropriate input to the Change Management process.
  • Coach future Regional Operations Team (ROOT) information security personnel as the ISMS becomes complete and mature.
  • Keep up to date on latest information security trends, "best practices", threats, and countermeasures.
Required Skills and Qualifications:
  • Enterprise-level information security plans, policies, standards, guidelines, methods, and practices based on current industry standards, best practices, tools, and techniques.
  • Information Security Management Systems, and applicable industry standards (ISO 27001/2).
  • Pertinent federal, state, and local laws, codes, and regulations; particularly those that affect information security for payment systems.
  • Environments subject to the Payment Card Industry Data Security Standard (PCI DSS), including compliance-related duties.
  • Knowledge and understanding of developing and administering information-security standards, practices, audits, risk management, and policy compliance.
  • Information Security Audit principles and practices.
  • Knowledge of one or more governance frameworks such as COBIT 5, ISO, NIST, or COSO.
  • Strong understanding of IT Service Delivery (ITIL) core processes and methodologies.
  • Principles, methods, and techniques used in the facilitation of managing projects and leading teams.
  • Relevant experience and detailed technical knowledge in security engineering, system and network security, authentication and security protocols, cryptography.
  • In-depth knowledge of security software threats and vulnerability mitigation techniques.
  • Working knowledge of cloud platforms such as Azure/ AWS and relevant security controls.
  • Establishing and maintaining collaborative working relationships with other department staff, management, vendors, and other interest holders.
  • Documenting and explaining risks, recommendations, and incident data to technical interest holders.
  • Interpreting and administering information security policies, standards, and procedures sufficiently to administer, discuss, resolve, and explain them to staff and other constituencies.
  • <
  • Leading or supporting an Information Security Management System.
  • Generating metrics and preparing reports to facilitate decision-making on security-related activities.
  • Utilizing personal computer software programs affecting assigned work and in compiling and preparing spreadsheets and reports.
  • Responding to inquiries with effective oral and written communication.
  • Researching, analyzing, and evaluating new security processes, products, and techniques.
  • Excellent time management skills including the ability to prepare, prioritize, and complete work plans.
  • Working effectively under pressure, meeting deadlines, and adjusting to changing priorities.
  • Writing of technical documentation and standards, including skill in English usage, spelling, grammar, and punctuation
Required Certifications or Licenses:
  • At least one of the following (in valid status):
    • Certified Information Systems Security Professional (CISSP).
    • Certified Information Security Manager (CISM).
    • Certified Information Security Auditor (CISA).
  • Other industry relevant certifications in the fields of information security, project management, auditing and/ or risk management, such as the Certification in Risk and Information Systems Control (CRISC)

Preferred Skills and Qualifications:
  • Knowledge of Governance, Risk, and Compliance (GRC) tools.
  • Principles of leadership, supervision, training, and performance evaluation.
  • Extensive knowledge of risk-based methodologies, and one or more of the following frameworks: ISO 27001/2:2017, 27005:2011, and 31000; PCI-DSS; or NIST 800-53.
Duration:11/07/2025 to2/28/2026
Location: Downtown Seattle (Hybrid)
M-F: 8 AM to 5 PM
Hybrid: 3 days work onsite
Pay: $75 per hour
#J-18808-Ljbffr

Triplenet Technologies logo

About Triplenet Technologies

Sourced by ZipRecruiter

TripleNet Technologies, has been helping selected clients since 1997. Client firms range from Fortune 100 companies to new ventures and privately held firms. Our staff has over 14 years experience in completing projects for IT, Sales, Customer Service, Technical Support, Marketing, Shipping, Accounting, and Software Engineering. We have significant experience in technology management and deployment of complex information technologies.

Industry

Recruiting and staffing services

Company size

11 - 50 Employees

Headquarters location

Seattle, WA, US

Year founded

1997

Social media