Information Systems Security Manager
This is an opportunity in the exciting and fast-growing transportation technology industry. Public transit is being transformed from a system of static, scheduled fixed-routes, to a dynamic on-demand network, and you will be one of the pioneers shaping this transformation.
The Information Systems Security Manager will be responsible for protecting Ride Co’s data and IT infrastructure by designing, implementing, maintaining, and enforcing security policies and protocols. Key responsibilities include monitoring systems, performing risk assessments, ensuring regulatory compliance (NIST, SOC2, GDPR, HIPAA), and leading incident response efforts to mitigate threats.
Your day-to-day responsibilities will include:
Strategic Security Management:
Developing and enforcing comprehensive security policies and procedures, ensuring they align with business objectives and legal compliance.
Own and maintain the organizational security roadmap using NIST SP 800-53 and NIST CSF 2.0, ensuring all security controls map directly to business risk and operational resilience.
Lead the strategy and annual audit for SOC2 type 2 certification and compliance (including all Trust Services Criteria - Security, Availability, Confidentiality, Processing Integrity, Privacy), and Ride Co’s Privacy Program.
Risk Mitigation & Assessment:
Conducting regular threat assessments, vulnerability scanning, and audits to identify weaknesses and implement countermeasures
Develop and enforce governance policies for the secure adoption of AI
Security Operations:
Monitoring network traffic, firewalls, endpoints, and data systems for suspicious activity
Procedural Governance:
Conduct reviews and provide feedback on contracts, RFPs, security questionnaires, and ensure existing program components are regularly reviewed and functioning according to their criteria
Establish and maintain agency-based security and privacy procedures to ensure consistent security hygiene across all departments and platforms.
Incident Response:
Leading efforts to identify, contain, and remediate security breaches or attempts.
Employee Training and Awareness:
Overseeing security awareness programs to train staff on cybersecurity best practices.
Implement specialized training to protect employees against evolving AI-generated threats, including deepfake audio/video scams and sophisticated phishing.
Technical Oversight:
Overseeing the deployment of security technologies, including encryption tools, antivirus software, and access controls
Vendor
Risk Management:
Assessing the security protocols of third-party vendors.
Your Playground / What You’ll Learn:
At Ride Co you’ll get a chance to play, learn and build with the following tools and technologies, and as part of a team that is the world’s foremost innovator in on-demand transit software.
Windows 11, Linux (Debian/Ubuntu), Mac, Android, iOS
Agile, continuous integration, Jenkins, zero-downtime software updates
Qualifications &
Experience:
Bachelor’s degree in Cybersecurity, IT or related field
5+ years of related experience
Certified Information Systems Security Professional (CISSP)
Proficient understanding of network infrastructure, firewalls and compliance frameworks
Experience in coordinating with IT teams
Compensation and Benefits:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: