×
Register Here to Apply for Jobs or Post Jobs. X

Senior Information Security Manager

Job in Sunnyvale, Santa Clara County, California, 94087, USA
Listing for: Zoomcar
Full Time position
Listed on 2026-09-25
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 167000 - 204000 USD Yearly USD 167000.00 204000.00 YEAR
Job Description & How to Apply Below

Job Responsibilities:

  • Manage information security team, lead the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS).
  • Perform gap analysis based on NIST SP800-53 and other compliance framework, create mitigation/action plans.
  • Determine the applicability and apply the information security and privacy requirements to ISMS policies.
  • Prepare required documents for supporting various compliance frameworks such as FedRAMP and GovRAMP.
  • Develop related KPI metrics for performance measurement, and for ensuring continued compliance and improvement.
  • Create compliance project plans. Manage the implementation.
  • Conduct risk and privacy impact assessments on business and operation processes. Prepare finding reports. Create and implement risk treatment plans.
  • Collaborate with operation teams to ensure that appropriate controls are implemented and operated properly.
  • Participate in and lead the daily security operation, oversee the handling of security alerts and incidents.
  • Lead vulnerability management activities, monitor remediation progress, and work closely with operations teams to ensure timely patching of identified vulnerabilities.
  • Manage internal and external audits. Develop audit plans, respond to various audits and review requests.
Skills and

Qualifications:
  • 7+ years of experience in information security area, with people and project management experience.
  • Subject matter expert of NIST SP800-53, ISO/IEC 27000 and SOC2 related standards, regulations and guidelines.
  • Experience of managing FedRAMP or GovRAMP implementation and compliance is highly preferred.
  • Knowledge and experience working with various information security frameworks (ISO/IEC 27001, NIST 800-53, NIST SP800-161, GovRAMP, FedRAMP, PCI DSS) and regulatory frameworks (SOX, PCI-DSS, HIPAA, GDPR, SOC, etc.).
  • Strong knowledge of and experience in privacy framework and regulatory compliance requirements (e.g., GDPR, CCPA).
  • Strong network security knowledge. Thorough understanding of current and emergent trends in information security.
  • Working knowledge of information security control technologies including access control, cryptography, vulnerability management, SIEM/log management, /IPS, and penetration test.
  • Working knowledge and hardening skills on information technologies including Linux, Windows, VMWare, MySQL, MSSQL, etc.
  • Working knowledge of Cloud platforms, Cloud security (AWS, Azure, GCP) and network security.
  • Experience and knowledge of Fortinet products and services are preferred.
  • Strong verbal and written communication skills. Demonstrate ability to work with team members, cross functional and external parties.
  • Ability to work independently in a fast-paced, dynamic environment. Able to establish priorities and meet deadlines.
  • Ability to provide continual attention to details. Strong analytical mindset. Able to gather and report data in meaningful format.
  • Passionate about policies, processes and documentation. Able to translate general standards to practical guidelines suitable for business operations.
Educational & Certification Requirements:
  • Bachelor’s degree in computer science, Information Security or related field;
  • A certification in one or more of the following desirable:
    • CISSP
    • CISA, CISM
    • ISO 27001 Lead-Auditor
    • VCP
    • CCSP
    • CRISC
  • NIST SP800-53 related training program.
  • GovRAMP/FedRAMP related training program.

About Our Team:

Join our team, known for its collaborative ethos, working seamlessly with global customers, internal engineering teams and product development groups. Our team culture emphasizes continuous learning, innovation, and a strong commitment to customer satisfaction. We embrace Fortinet’s core values of openness, teamwork and innovation, fostering an environment where team members…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary