Information Security Manager Seattle, wa
Job in
Seattle, King County, Washington, 98127, USA
Listed on 2026-07-11
Listing for:
Triplenet Technologies
Full Time
position Listed on 2026-07-11
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
Overview
Roles involve guiding security policy, governance, risk management, ISMS development and maintenance, security training, incident response leadership, and collaboration with partners across agencies and vendors to enforce security best practices within payment systems.
Key Responsibilities- Guide security policy and participate in broader Information Security governance efforts.
- Develop and maintain the Information Security Management System (ISMS) in collaboration with regional information security SMEs and technical consultants.
- Oversee and manage the ISMS and recommend appropriate mitigating controls.
- Oversee Information Security Risk Management activities, including risk identification, assessment, and communication to relevant stakeholders.
- Provide expertise and leadership to governing executive leadership, including sharing metrics on regional security program performance and executive risk score reports.
- Facilitate a committee of Information Security SMEs across Agencies to ensure regional compliance and concurrence on information security matters, recommending solutions from a regional perspective.
- Collaborate with Systems Integrator, vendors, and partner Agencies to ensure security best practices, standards, and regulatory requirements are incorporated into core payment system design, implementation, and sustainment.
- Conduct regular security reviews of software and processes; review and create threat models and recommend security enhancements aligned with strategy and evolving threats.
- Support external IT security audits and assessments focusing on operation.
- Develop, update, implement, and conduct information security training programs to support ISMS objectives.
- Manage approvals for Identity and Access Management (IAM) and Access Control Administration.
- Act as Incident Commander for Security Incident Response activities and provide oversight when invoked by partners or vendors.
- Participate in information security incident investigations and response efforts; perform root-cause analysis and prepare incident reports.
- Evaluate change requests for potential impacts to Information Security and provide input to Change Management processes.
- Coach future Regional Operations Team (ROOT) information security personnel as the ISMS matures.
- Keep up to date on latest information security trends, best practices, threats, and countermeasures.
Skills and Qualifications
- Enterprise-level information security plans, policies, standards, guidelines, methods, and practices based on current industry standards and best practices.
- Information Security Management Systems and applicable industry standards (ISO 27001/2).
- Knowledge of federal, state, and local laws and regulations affecting information security for payment systems.
- Environments subject to PCI DSS compliance duties.
- Knowledge and understanding of information-security standards, audits, risk management, and policy compliance.
- Information Security Audit principles and practices.
- Knowledge of governance frameworks such as COBIT 5, ISO, NIST, or COSO.
- Strong ITIL-based service delivery understanding.
- Project facilitation, leadership, and team management skills.
- Technical knowledge in security engineering, system and network security, authentication, and cryptography.
- Understanding of security software threats and vulnerability mitigation techniques.
- Working knowledge of cloud platforms (Azure/AWS) and related security controls.
- Ability to build collaborative relationships with staff, management, vendors, and stakeholders.
- Ability to document and explain risks, recommendations, and incident data to technical stakeholders.
- Ability to interpret and administer information security policies and procedures.
- Experience leading or supporting an Information Security Management System.
- Experience generating metrics and preparing reports for security decision-making.
- Proficiency with office software for preparing spreadsheets and reports; strong written and oral communication skills.
- Ability to research, analyze, and evaluate new security processes, products, and techniques.
- Excellent time management, ability to work under pressure, and adjust to changing priorities.
- Experience documenting technical standards in English with clear communication.
- At least one of the following (valid):
- Certified Information Systems Security Professional (CISSP).
- Certified Information Security Manager (CISM).
- Certified Information Security Auditor (CISA).
- Other relevant certifications in information security, project management, auditing, and/or risk management (e.g., CRISC).
Skills and Qualifications
- Knowledge of Governance, Risk, and Compliance (GRC) tools.
- Leadership, supervision, training, and performance evaluation skills.
- Extensive knowledge of risk-based methodologies and frameworks such as ISO 27001/2:2017, 27005:2011, 31000; PCI-DSS; or NIST 800-53.
Duration: 11/07/2025 to 2/28/2026
Location:
Downtown Seattle (Hybrid)
Schedule:
Mon-Fri, 8:00 AM to 5:00 PM.…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×