Information Security Manager
Job in
Alpharetta, Fulton County, Georgia, 30239, USA
Listed on 2026-06-11
Listing for:
Nox-Health
Full Time
position Listed on 2026-06-11
Job specializations:
-
IT/Tech
Cybersecurity, IT Project Manager, Information Security, IT Consultant
Job Description & How to Apply Below
About the role
The Information Security Manager is responsible for leading the organization’s cybersecurity program to protect systems, networks, data, and business operations from evolving threats. This role oversees security strategy execution, manages security operations, ensures regulatory compliance, and drives risk reduction initiatives across the enterprise. This role oversees the security operations program and ensures the effective execution and continuous improvement of core cybersecurity functions.
Whatyou'll do Security Program Leadership
- Lead day-to-day security operations and manage security team members, providing mentorship, performance management, and professional development.
- Help develop, implement, and maintain information security strategy and roadmap aligned with business objectives and customer commitments.
- Establish and track security KPIs and metrics; provide regular reporting to leadership.
- Promote a strong security culture across the organization.
- Serve as a trusted advisor to product, engineering, compliance, and customer success teams.
- Oversee monitoring, detection, and response to security events and incidents.
- Ensure proper management of security tools including SIEM, EDR, vulnerability management, DLP, IAM, and CSPM solutions.
- Ensure secure configuration and hardening of devices, cloud infrastructure, and SaaS platforms.
- Oversee Managed Detection and Response service.
- Collaborate with Dev Ops and engineering teams to integrate security into CI/CD pipelines.
- Support secure architecture reviews for new products and features.
- Drive continuous improvement of operational security processes.
- Monitor emerging threats and adjust defensive strategies accordingly.
- Align risk management activities with regulatory and compliance requirements.
- Conduct and oversee risk assessments across systems, applications, and vendors.
- Maintain and track the enterprise risk register and remediation plans.
- Ensure compliance with relevant regulatory and industry standards.
- Maintain policies, standards, and procedures aligned with NIST CSF, ISO 27001, HITRUST, and FedRAMP frameworks.
- Support internal and external audits to achieve certifications.
- Lead the incident response program, including preparation, detection, analysis, containment, eradication, and recovery.
- Support the development, maintenance, and testing of Incident Response Plan.
- Oversee triage and investigation of security events and alerts.
- Coordinate cross-functional teams during security incidents and internal incident exercises.
- Act as escalation point and incident commander for major security incidents.
- Conduct post-incident reviews and drive root cause analysis and corrective actions.
- Maintain and test incident response playbooks, including breach notification procedures.
- Monitor emerging healthcare and SaaS-specific threats.
- Oversee vulnerability scanning, remediation tracking, and reporting across infrastructure and applications.
- Prioritize remediation efforts based on business impact and risk.
- Coordinate penetration testing and track remediation to closure.
- Support the development, maintenance, and testing of Business Continuity and Disaster Recovery plans.
- Ensure disaster recovery testing is conducted regularly and documented.
- Ensure security considerations are embedded in resilience planning.
- Ensure backup, recovery, and resilience capabilities meet defined RTO/RPO objectives.
- Lead tabletop exercises and crisis management activities.
- Partner with IT, devops, development, engineering, legal, compliance, and business teams to embed security into projects and operations.
- Provide security guidance for new technologies, cloud deployments, and third-party integrations.
- Evaluate and recommend security technologies and solutions.
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field (or equivalent experience).
- 7+ years of progressive experience in cybersecurity.
- 3+ years of experience leading or managing security operations teams.
- Professional certifications such as CISSP, CISM, CRISC, GIAC, or equivalent (preferred).
- Hands‑on…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×