Manager, Information Security

Synack | unspecified

Manager, Information Security opportunity at Synack.

Job description

Manager, Information Security is a contract role with Synack, based in Remote in the US. The position contributes to the employer's work through the function described in the vacancy, with day-to-day focus on We are committed to making the world more secure by harnessing a talented, vetted community of security researchers to deliver continuous penetration testing and vulnerability management, with actionable results. Keep reading…</p> <p><strong><em>**Please note that due to federal government contract requirements, we can only hire a citizen of the United States into this role.</em></strong></p> <p><strong>Here’s what you'll do</strong></p> <ul> <li>Automate generation of System Security Plans (SSP), including Security Concept of Operations, Risk Management Matrix, Security Control Traceability Matrix, and conduct Security Impact Analysis (SIA) on major system changes.</li> <li>Develop and maintain automated Plans of Action and Milestones (POAMs).</li> <li>Contribute to the adoption and implementation of automation and use of Artificial Intelligence (AI) within Synack's Information Security operations.</li> <li>Own the inventory and risk assessments of AI/agentic systems used across Synack, aligned to NIST AI RMF and ISO 42001, including data handling, model and agent change control, non-human identity and credential scoping.</li> <li>Build and own automated evidence collection and control-drift around security controls.</li> <li>Communicate regularly with stakeholders on security compliance issues aligning to CIS and NIST standards, track mitigation/remediation tasks, and assisting in generation of reports and metrics.</li> <li>Codify security controls into IaC guardrails, CNAPP policies, and CI/CD checks to prevent risks at commit and deploy time.</li> <li>Working with Project Managers and Software Engineers in a collaborative and enabling (non-obstructive) manner; Ensuring appropriate information security policies, standards, procedures, and guidelines

Requirements

  • Keep reading…</p> <p><strong><em>**Please note that due to federal government contract requirements
  • we can only hire a citizen of the United States into this role.</em></strong></p> <p><strong>Here’s what you'll do</strong></p> <ul> <li>Automate generation of System Security Plans (SSP)
  • including Security Concept of Operations
  • Risk Management Matrix
  • Security Control Traceability Matrix
  • and conduct Security Impact Analysis (SIA) on major system changes.</li> <li>Develop and maintain automated Plans of Action and Milestones (POAMs).</li> <li>Contribute to the adoption and implementation of automation and use of Artificial Intelligence (AI) within Synack's Information Security operations.</li> <li>Own the inventory and risk assessments of AI/agentic systems used across Synack
  • aligned to NIST AI RMF and ISO 42001
  • including data handling
  • model and agent change control
  • non-human identity and credential scoping.</li> <li>Build and own automated evidence collection and control-drift around security controls.</li> <li>Communicate regularly with stakeholders on security compliance issues aligning to CIS and NIST standards
  • track mitigation/remediation tasks
  • and assisting in generation of reports and metrics.</li> <li>Codify security controls into IaC guardrails
  • CNAPP policies
  • and CI/CD checks to prevent risks at commit and deploy time.</li> <li>Working with Project Managers and Software Engineers in a collaborative and enabling (non-obstructive) manner; Ensuring appropriate information security policies
  • standards
  • procedures
  • and guidelines are being incorporated across Synack hosted services and infrastructure
  • with a focus on hardening and adhering to DevSecOps principles.</li> <li>Coordinate with the field teams to respond to vendor security assessments and conduct 3rd party risk assessments of Synack vendors.</li> </ul> <p><strong>Here’s what you’ll need</strong></p> <ul> <li>8+ years of experience IT Security Strategy
  • Risk Management
  • IT Audit and Compliance with a Cloud Service Provider</li> <li>Experience with Python
  • Terraform
  • and CI/CD pipelines
  • plus comfort integrating tools with AI.</li> <li>Experience with Enterprise Governance
  • Risk Management
  • and Compliance (GRC) tools.</li> <li>Experience with event monitoring and alerting tools such as Datadog
  • Stackdriver
  • and Azure Sentinel.</li> <li>Experience with SOAR or auto-remediation platforms and detection engineering / SIEM query languages.</li> <li>Experience with Cloud Native Application Protection Platforms (CNAPP).</li> <li>Experience with leveraging security tools within the Software Development Lifecycle (SDLC).</li> <li>Familiarity with secrets management and workload identity (non-human).</li> <li>Working knowledge of security regulations
  • standards
  • and frameworks
  • including but not limited to ISO27000
  • ISO42001
  • OWASP
  • SOC2
  • GDPR
  • CMMC
  • FedRAMP
  • and NIST.</li> <li>Excellent written and verbal communication skills with the ability to accurately communicate security and risk-related information to technical and non-technical audiences.</li> </ul> <p><strong>Ready to join us?</strong></p> <p>Synack is committed to embracing diversity.

Skills

  • Python
  • Azure