994,162open jobs
59,296companies
165,357added this week
Browse all
Salary
≈ $75k – $161k per year (Estimated)
Location
Remote (United States)
Seniority
Middle · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Apr 12, 2026. Bright Defense scores B on the Alion truth index.

Overview
Company
Impact
Profile match
We provide managed SOC 2, ISO 27001, HIPAA, and CMMC compliance services for small and mid-size businesses through CISSP certified experts.

Bright Defense · SecOps Team · Now Hiring

Information Security Manager

SecOps - Continuous Monitoring & Client Risk Management

Full-TimeRemoteSecOpsCompliance & Risk Focus

You’ll be the person clients trust to keep their security program on track between audits. This role lives at the intersection of technical rigor and clear communication - translating control monitoring, risk findings, and compliance gaps into actionable guidance that customers can act on.

About the role

As an Information Security Manager on the Bright Defense SecOps Team, you’ll manage a portfolio of customer security programs through asynchronous collaboration, lead continuous control monitoring, assess maturity, and develop risk management strategies that strengthen client security postures. You’ll work closely with Security Consultants, Offensive Security, and other SecOps functions - and serve as the primary written voice keeping customers informed on findings, progress, and next steps.

Key responsibilities

Portfolio management

  • Manage a portfolio of customer security programs with continuous oversight via async channels
  • Serve as the primary point of accountability for program health, milestone tracking, and escalation
  • Coordinate with assigned Security Consultants to align monitoring with each client’s overall strategy
  • Participate in internal syncs and contribute to broader SecOps objectives

Control monitoring & risk

  • Lead ongoing assessments of security controls against ISO 27001, SOC 2, NIST CSF, and other applicable frameworks
  • Monitor and evaluate control effectiveness, maturity levels, and residual risk exposure
  • Identify, track, and support remediation of control weaknesses and compliance gaps
  • Maintain current records of risk assessments, audit findings, and corrective action plans

Audit & compliance readiness

  • Review evidence and documentation to validate compliance posture across multiple frameworks
  • Support audit readiness for SOC 2, HIPAA, ISO 27001, PCI DSS, CMMC, and related engagements
  • Perform Third Party Risk Management assessments for new and existing vendors
  • Respond to security questionnaires on behalf of clients within a 5-business-day SLA

Reporting & communication

  • Prepare accurate, professional, and actionable written reports and customer updates
  • Deliver data-driven insights and recommendations with clarity and specificity
  • Ensure transparency across all customer-facing communications regarding monitoring, findings, and remediation status
  • Continuously improve reporting standards, evidence management, and monitoring methodologies

Cross-functional collaboration

Security Consulting

Offensive Security

SecOps Functions

Client Stakeholders

What we’re looking for

Security & compliance (required)

  • 3-6 years in information security, GRC, or compliance-adjacent roles
  • Hands-on experience with SOC 2, ISO 27001, NIST CSF, HIPAA, PCI DSS, or CMMC
  • Demonstrated ability to assess control effectiveness and document residual risk
  • Experience conducting or supporting security audits and evidence reviews

Risk management

  • Practical experience building or maintaining risk registers and treatment plans
  • Familiarity with Third Party Risk Management (TPRM) processes and vendor assessments
  • Ability to prioritize risk findings and translate them into business-level recommendations
  • Experience completing security questionnaires (RFP, SIG, CAIQ, custom)

Communication & async work

  • Exceptional written communication - client-facing reports, findings summaries, executive updates
  • Comfortable managing multiple engagements through async channels (Slack, email, project tools)
  • Able to communicate technical findings clearly to non-technical stakeholders

Tools & platforms

  • GRC platforms - Drata, Vanta, Thoropass, or equivalent
  • Asana or similar PM tools for task and program tracking
  • SafeBase or equivalent for security questionnaire management
  • Google Workspace or Microsoft 365 proficiency

Nice to have

  • CISA, CISM, CISSP, or CRISC certification
  • MSSP or consulting firm background
  • Experience supporting CMMC Level 2 or ITAR-adjacent programs
  • Familiarity with NYDFS 23 NYCRR Part 500 or other state-level frameworks
  • Exposure to cloud security environments (AWS, Azure, GCP)
  • Background in healthcare, defense, or fintech regulated industries

Performance benchmarks

5 days

SLA for security questionnaire responses

Monthly

written updates delivered to every active client

0 gaps

untracked audit findings at any point in time

Current

risk registers and corrective action logs maintained

Aligned

control monitoring mapped to each client’s framework scope

100%

TPRM assessments completed before vendor onboarding

Compensation & perks

  • Competitive base salary - range shared during screening
  • Remote-first with flexible working hours
  • Certification reimbursement (CISA, CISM, CISSP, CRISC, and others)
  • Direct collaboration with Bright Defense co-founders
  • Broad client exposure across defense, healthcare, and fintech verticals
  • Clear growth path toward Senior ISM or vCISO functions

Bright Defense is an equal opportunity employer. We build diverse, high-trust teams.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
994,162 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $48k – $91k per year (Estimated) • Remote (EU) • Full-Time • Warsaw
SQL
PowerShell
C#
C#
.NET
DevOps
Rest API
Azure
IAM
SOAP
Cybersecurity
Microsoft Entra ID
Active Directory
LDAP
Apply
$175k – $205k per year • Equity • Remote (United States) • TS/SCI • Full-Time • 8+ years exp • Bachelor's Degree • El Segundo
C
C
U-Boot
DevOps
Terraform
Puppet
Ansible
Docker Compose
NixOS
OpenTofu
Rancher
Chef
K3s
Azure
CI/CD
AWS
Docker
Kubernetes
Ubuntu
SaltStack
Configuration Management
SOPS
Linux
Cybersecurity
HashiCorp Vault
FedRAMP
Threat Modeling
PKI
Apply
≈ $118k – $214k per year (Estimated) • Remote (United States) • Full-Time
Python
PowerShell
AI/ML
Red Teaming
Cybersecurity
Burp Suite
Cobalt Strike
Sliver
Havoc
MITRE ATT&CK
OWASP Top 10
CVSS
Active Directory
SIEM
OWASP
Apply
≈ $89k – $167k per year (Estimated) • Remote (United States) • Full-Time
Python
PowerShell
Bash
DevOps
GCP
Azure
AWS
Docker
Kubernetes
IAM
Windows
Cybersecurity
Nmap
Nessus
OpenVAS
SIEM
DLP
Apply
≈ $15k – $31k per year (Estimated) • Remote (EAEU) • 1+ year exp • Moscow
DevOps
Linux
Cybersecurity
SIEM
DLP
Apply
$50k – $59k per year • In office • Full-Time • Bachelor's Degree • Lisbon
Cybersecurity
ISO 27001
NIST CSF
Apply
≈ $27k – $71k per year (Estimated) • Hybrid • Bachelor's Degree • Sri Lanka
Management
Slack
Notion
Google Workspace
Apply
≈ $97k – $211k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Jakarta
AI/ML
Red Teaming
DevOps
GCP
CI/CD
AWS
IAM
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
Zero Trust
SIEM
Apply
≈ $65k – $175k per year (Estimated) • Equity • Remote (United States) • Full-Time • Bachelor's Degree • Austin
Cybersecurity
HIPAA
Management
Google Workspace
Apply
In office
DevOps
Incident Management
Cybersecurity
ISO 27001
Apply
Remote (location not specified, PT hours) • Full-Time
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Management
Asana
Google Workspace
Apply
GRC Analyst – SecOps 6 months ago
≈ $58k – $135k per year (Estimated) • Remote (location not specified, PT hours) • Full-Time • 2+ years exp
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Management
Asana
Google Workspace
Apply
≈ $76k – $165k per year (Estimated) • Remote (likely United States) • Full-Time • 5+ years exp • Bachelor's Degree
DevOps
IAM
Cybersecurity
ISO 27001
PCI DSS
SOC 2
HIPAA
NIST 800-53
NIST 800-171
Apply
≈ $74k – $164k per year (Estimated) • Remote (location not specified) • Full-Time • 5+ years exp
Python
PowerShell
AI/ML
LLM
Red Teaming
LLM Guardrails
Frontend
GraphQL
DevOps
Rest API
GCP
Azure
CI/CD
AWS
Cybersecurity
Burp Suite
Metasploit
Nmap
ISO 27001
OWASP Top 10
PCI DSS
SOC 2
HIPAA
Threat Modeling
MobSF
Frida
Objection
OWASP
Apply
See all jobs
This is one of many
994,162 more open roles from verified company boards, updated every day.