Senior Manager, Information Security
Job in
Janesville, Rock County, Wisconsin, 53546, USA
Listed on 2026-02-28
Listing for:
MTVS - Meimad TV Studios
Full Time
position Listed on 2026-02-28
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Project Manager
Job Description & How to Apply Below
Job Summary
SHINE Technologies is seeking a Senior Manager, Information Security who will lead SHINE’s enterprise information security program, focusing on cybersecurity governance, risk management, compliance, and oversight of operational security activities. The role provides strategic direction for SHINE’s security posture, ensures alignment with regulatory and contractual obligations, and manages day‑to‑day security operations performed by IT staff. The base salary range for this position is $140,000 - $175,000 per year plus a comprehensive compensation package.
Responsibilities- Lead SHINE’s information security program, ensuring policies, controls, and processes are implemented and continuously improved.
- Provide oversight and direction to Cybersecurity staff for operational tasks including monitoring, analysis, vulnerability scanning, and control implementation.
- Maintain SHINE’s Information Security Plan and ensure alignment with NIST 800‑171, CMMC, ISO 27001/27002, NRC requirements, and internal standards.
- Ensure proper integration of security requirements into IT systems, cloud platforms, and applicable OT/ICS environments.
- Governance, Risk, & Compliance (Primary Focus)
- Own the governance framework for information security, including policy management, standards, procedures, and control mappings.
- Manage SHINE’s cybersecurity risk management process, including maintaining the risk register and presenting treatment recommendations to leadership.
- Lead compliance activities for NIST 800‑171, CMMC, ISO, and other regulatory frameworks.
- Coordinate internal and external audits, ensuring evidence is complete, accurate, and audit‑ready.
- Conduct periodic assessments and internal reviews to validate ongoing compliance.
- Strategic Planning & Program Maturity
- Develop annual security improvement plans and budget recommendations based on business priorities and risk.
- Identify gaps in security posture and propose operational, technical, and procedural enhancements.
- Participate in cross‑functional project reviews and ensure security is integrated into new technologies, system changes, and enterprise initiatives.
- Incident Response Leadership
- Serve as a senior member of the Security Incident Response Team (SIRT).
- Lead incident governance: escalation, communication, documentation, decision making, and after‑action reviews.
- Direct technical incident response tasks performed by relevant IT staff.
- Maintain and improve incident response plans, communication models, and readiness processes.
- OT/ICS Security Participation (Limited Scope)
- Provide consultative security guidance for OT/ICS environments where cybersecurity risk, regulatory requirements, or system criticality justify involvement.
- Support reviews of high‑risk OT changes to assess potential security impacts.
- Partner with Engineering teams to apply appropriate security expectations to critical systems without imposing unnecessary operational burden.
- Third Party & Customer Cybersecurity Requirements
- Lead vendor security assessments and drive ongoing third‑party cybersecurity monitoring.
- Serve as the primary responder for customer cybersecurity questionnaires, attestation requests, and contract‑driven security obligations.
- Collaborate with Legal, Supply Chain, and Business Development to ensure cybersecurity terms are understood, feasible, and enforced.
- Security Awareness & Workforce Engagement
- Oversee the enterprise security awareness program.
- Ensure workforce compliance with annual cybersecurity training and role‑specific requirements.
- Coordinate with HR and Communications to deliver effective campaigns and reinforce a culture of security.
- Reporting & Executive Communication
- Produce and present information security metrics, risk summaries, and program updates for IT leadership and executive stakeholders.
- Communicate security issues in clear, actionable terms tailored to both technical and non‑technical audiences.
- 7+ years of experience in information security, cybersecurity, risk management, or GRC.
- Experience with NIST 800‑171, CMMC, ISO 27001/27002, or similar frameworks.
- Broad technical knowledge across networks, systems, cloud environments, and…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×