Senior Information Security Manager
Leads information security governance, compliance, security operations, risk management, and incident response for a healthcare AI company. Requires 5+ years of security experience and hands-on expertise with major compliance frameworks, SIEM, incident response, and third-party risk.
About the job
Responsibilities
- Lead and maintain certification and compliance efforts for SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, and CIS benchmarks.
- Serve as the primary contact for internal and external security questions.
- Own the global security awareness strategy, including annual training, awareness campaigns, and phishing simulations.
- Respond to customer and prospect security questionnaires within agreed turnaround times.
- Oversee Security Operations Center operations, including log-source coverage, detection-rule creation and tuning, and SLA/KPI management.
- Build and manage Third-Party Risk Management, Business Continuity, and Disaster Recovery programs.
- Run vulnerability steering committees across corporate and production environments.
- Manage vendor risk and the security risk register.
- Monitor and manage the company’s external digital footprint using attack-surface-management tools.
- Act as incident commander for security incidents, coordinating analysis, escalation, response, and remediation.
- Help design and execute the annual security roadmap.
- Manage the company Trust Center.
- Lead the internal security policy lifecycle, including creation, updates, approvals, and distribution.
- Audit onboarding and offboarding processes from a security perspective.
Requirements
- 5+ years of experience in information security, including meaningful experience in GRC, security operations, or a hybrid role.
- Hands-on experience leading or supporting SOC 2, ISO 27001, HIPAA, and GDPR certifications and audits.
- Strong understanding of SOC operations, SIEM tooling, detection engineering concepts, and incident response.
- Experience building or running a Third-Party Risk Management program.
- Experience acting as an incident commander or lead responder for security incidents.
- Familiarity with vulnerability management programs across cloud and corporate environments.
- Strong written and verbal communication skills in English, with the ability to represent security to customers, auditors, and executives.
Benefits and Compensation
- Competitive cash compensation, equity, and benefits based on location, role scope and complexity, experience, and expertise.
- Israel benefits include dental insurance, performance-based bonuses, Cibus meal allowance, meals at the office, and additional benefits.
Skills
SOC 2, ISO 27001, Iso 42001, HIPAA, GDPR, Cis Benchmarks, SIEM, Detection Engineering, Incident Response, Third-Party Risk Management, Vulnerability Management, Business Continuity, Disaster Recovery, Security Awareness, Attack Surface Management
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.