Information Security Manager driving information security program and leading security engineering at Thndr. Collaborating cross-functionally to ensure compliance and manage cyber risks.
Responsibilities
Supervise security engineering practices and ensure their secure, efficient operations.
Lead the development, implementation, and continuous improvement of the organization’s information security program.
Lead adversary research, threat modeling, risk assessment and supervise defense control selection for products, infrastructure, and third-party services and products.
Oversee identity and access management (IAM) strategies, tooling, and implementation.
Define and monitor key performance indicators to measure technical security maturity, control effectiveness, and overall capabilities progress of the security program.
Ensure traceability and consistency across policies, risks, and controls.
Lead on the security awareness training program, tooling, and continuous KPI improvement.
Provide strategic guidance on the security implications of business initiatives, projects, and technology choices.
Implement and maintain automated supervision tooling (e.g., Sprinto or custom integrations) to support governance reporting.
Establish and maintain technical security guidelines, policies, standards, and procedures aligned with business needs, regulatory obligations (e.g., CMA, ADGM, FRA), and frameworks such as ISO 27001, NIST CSF, and PCI DSS.
Manage, maintain, and evolve the information security risk register and risk management framework (e.g., NIST RMF).
Lead, mentor, and develop members of the information security team.
Serve as a trusted advisor to senior management on information security posture.
Prepare clear, actionable reports and recommendations for executive stakeholders and governance committees.
Requirements
7+ years of experience in information security, with proven leadership in governance, risk, and compliance.
Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field.
CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer/Auditor preferred.
Strong understanding of frameworks such as ISO 27001, NIST CSF, PCI DSS, SOC 2, and relevant regional regulations (CMA, ADGM, FRA, GDPR).
Nodal Officer to handle Cybersecurity and regulatory compliance for Eutelsat in India. Liaising with government agencies, ensuring adherence to telecommunication regulations and security standards.
Assistente de Segurança Empresarial no Grupo Boticário, atuando com segurança de propriedades de beleza. Suporte na análise de riscos e vistorias técnicas na unidade.
IT/OT - Security Manager conducting risk analyses and implementing measures for business continuity management. Ensuring compliance with internal and external information security requirements.
Werkstudent im Bereich Cybersecurity bei BMW Group in München. Unterstützung bei Sicherheitslösungen für die Ladeinfrastruktur von Elektrofahrzeugen während deines Studiums.
Senior Security & Compliance Analyst at Insurify ensuring security controls align with regulations. Collaborating across teams to enhance security practices and compliance measures in the organization.
Security Guard providing routine security for facilities at L3Harris Technologies. Engaging with employees and visitors to ensure safety and adherence to policies.
Manager of Industrial Security overseeing SCIF operations and personnel security functions for L3Harris. Leading operational plans, formulating security policies, and ensuring compliance with national directives.
Manager of Industrial Security at L3Harris overseeing compliance with federal security regulations and leadership of security programs for classified materials. Responsible for audits, training, and program implementation ensuring compliance.
Security Officer protecting people and property through patrols and monitoring at Switch facilities. Responsibilities include access control, incident response, and documentation in a critical environment.
Security Officer responsible for maintaining safety at Switch facilities through patrols and access control. Ensuring effective security monitoring and incident response in a controlled environment.