Назад
Company hidden
10 дней назад

Manager Information Security & Risk Management - Cloud Security Manager (Cloud Security)

Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager Information Security & Risk Management - Cloud Security Manager (Cloud Security): Leading cloud security strategy, governance, architecture, engineering, and operations across public cloud, SaaS, cloud-native, and emerging technologies with an accent on CNAPP, CSPM, CIEM, DevSecOps, IaC, container, Kubernetes, and cloud identity security. Focus on secure-by-design initiatives, threat modeling, continuous compliance, risk management, executive reporting, and building high-performing cloud security teams.

Location: Work At Home — Pennsylvania, United States; Remote, with a physical work site required

Company

hirify.global operates within Highmark Health and provides technology and information security capabilities for the organization.

What you will do

  • Lead the Cloud Security function, including hiring, coaching, performance management, succession planning, staffing, budgeting, and resource planning.
  • Define and execute cloud security strategies, standards, roadmaps, operational plans, and secure cloud adoption initiatives.
  • Oversee cloud security architecture, engineering, and operations across cloud platforms, workloads, identities, IaC, containers, Kubernetes, monitoring, and threat detection.
  • Integrate security controls into software delivery pipelines, cloud deployments, and technology modernization programs through secure-by-design and DevSecOps practices.
  • Direct cloud security reviews, threat modeling, risk assessments, incident response support, resilience planning, and recovery activities.
  • Report security metrics, risk indicators, operational performance, budgets, and strategic investments to executive stakeholders.

Requirements

  • Bachelor’s degree in Information Security, Information Systems, Information Assurance, Computer Science, or a related field; six years of relevant experience may substitute.
  • 7–10 years of experience in information security, information risk management, or information technology.
  • 5–7 years of experience designing, implementing, securing, or governing cloud technologies and services.
  • 3–5 years of experience leading cloud security, cybersecurity, engineering, architecture, or technology teams.
  • Experience presenting information security and risk management concepts to technical, management, and executive audiences.
  • Work location: Pennsylvania, United States; a physical work site is required.

Nice to have

  • Master’s degree in Computer Science, Information Security, or a related field.
  • 10–15 years of experience in information security, information risk management, or information technology.
  • Experience with HITRUST CSF, NIST 800-83, SSAE 16, SOC 2 audits, security budgets, or industry organization leadership.
  • CISSP, CISM, CRISC, or ITIL certification.

Culture & Benefits

  • Work involves collaboration with information security, information technology, enterprise architecture, engineering, application development, cloud operations, and business stakeholders.
  • Regular travel requirement is 0%–25%.
  • The role supports regulatory compliance and security frameworks including HIPAA, HITRUST, NIST, PCI DSS, and applicable cloud security controls.
  • The position includes frequent teaching and training of others and communication with stakeholders at all organizational levels.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →