remote
Information Security Manager - Marathon Health
Software Engineer
Lead a security team to protect enterprise data, develop risk‑based security strategies, and ensure compliance across cloud and on‑prem environments using modern security frameworks and tools.
About the role
Key Responsibilities
- Lead and mentor a cross‑functional security team, driving the execution of security programs and initiatives.
- Develop and maintain risk‑based security strategies, policies, and procedures aligned with industry standards and regulatory requirements.
- Oversee security architecture design, including cloud, network, and application security controls, ensuring robust protection of sensitive data.
- Coordinate incident response activities, conduct root‑cause analysis, and implement remediation plans to minimize impact.
- Collaborate with IT, legal, and business units to embed security best practices into product development and operational processes.
Requirements
- 5+ years of experience in information security, with at least 2 years in a managerial role.
- Deep knowledge of security frameworks (NIST, ISO 27001, CIS Controls) and compliance regulations (HIPAA, GDPR, SOC 2).
- Hands‑on experience with cloud security (AWS, Azure, GCP) and security tooling (SIEM, SOAR, vulnerability management).
- Strong analytical, communication, and stakeholder management skills.
- Relevant certifications such as CISSP, CISM, or equivalent are highly desirable.