{"id":1539376,"url":"https://alion.io/job/bright-defense-information-security-manager-secops","title":"Information Security Manager – SecOps","company":{"id":1850073,"name":"Bright Defense","domain":"brightdefense.com","url":"https://alion.io/company/brightdefense","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":{"grade":"B","score":75,"open_postings":4,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":75000,"max_usd":161000,"period":"year","method":"global_role_seniority_cell","sample_n":414},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Asana","optional":false},{"name":"Google Workspace","optional":false},{"name":"HIPAA","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST CSF","optional":false},{"name":"PCI DSS","optional":false},{"name":"Slack","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"SOC 2","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"GCP","optional":true}],"status":"live","first_seen_at":"2026-04-12T17:27:58Z","employer_posted_date":"2026-04-12","last_verified_at":"2026-10-01T07:17:58Z","board_verified":true,"closed_at":null,"days_open":172,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":171},"description":"Bright Defense · SecOps Team · Now Hiring\nInformation Security Manager\nSecOps - Continuous Monitoring & Client Risk Management\nFull-TimeRemoteSecOpsCompliance & Risk Focus\nYou’ll be the person clients trust to keep their security program on track between audits. This role lives at the intersection of technical rigor and clear communication - translating control monitoring, risk findings, and compliance gaps into actionable guidance that customers can act on.\nAbout the role\nAs an Information Security Manager on the Bright Defense SecOps Team, you’ll manage a portfolio of customer security programs through asynchronous collaboration, lead continuous control monitoring, assess maturity, and develop risk management strategies that strengthen client security postures. You’ll work closely with Security Consultants, Offensive Security, and other SecOps functions - and serve as the primary written voice keeping customers informed on findings, progress, and next steps.\nKey responsibilities\nPortfolio management\nManage a portfolio of customer security programs with continuous oversight via async channels\nServe as the primary point of accountability for program health, milestone tracking, and escalation\nCoordinate with assigned Security Consultants to align monitoring with each client’s overall strategy\nParticipate in internal syncs and contribute to broader SecOps objectives\nControl monitoring & risk\nLead ongoing assessments of security controls against ISO 27001, SOC 2, NIST CSF, and other applicable frameworks\nMonitor and evaluate control effectiveness, maturity levels, and residual risk exposure\nIdentify, track, and support remediation of control weaknesses and compliance gaps\nMaintain current records of risk assessments, audit findings, and corrective action plans\nAudit & compliance readiness\nReview evidence and documentation to validate compliance posture across multiple frameworks\nSupport audit readiness for SOC 2, HIPAA, ISO 27001, PCI DSS, CMMC, and related engagements\nPerform Third Party Risk Management assessments for new and existing vendors\nRespond to security questionnaires on behalf of clients within a 5-business-day SLA\nReporting & communication\nPrepare accurate, professional, and actionable written reports and customer updates\nDeliver data-driven insights and recommendations with clarity and specificity\nEnsure transparency across all customer-facing communications regarding monitoring, findings, and remediation status\nContinuously improve reporting standards, evidence management, and monitoring methodologies\nCross-functional collaboration\nSecurity Consulting\nOffensive Security\nSecOps Functions\nClient Stakeholders\nWhat we’re looking for\nSecurity & compliance (required)\n3-6 years in information security, GRC, or compliance-adjacent roles\nHands-on experience with SOC 2, ISO 27001, NIST CSF, HIPAA, PCI DSS, or CMMC\nDemonstrated ability to assess control effectiveness and document residual risk\nExperience conducting or supporting security audits and evidence reviews\nRisk management\nPractical experience building or maintaining risk registers and treatment plans\nFamiliarity with Third Party Risk Management (TPRM) processes and vendor assessments\nAbility to prioritize risk findings and translate them into business-level recommendations\nExperience completing security questionnaires (RFP, SIG, CAIQ, custom)\nCommunication & async work\nExceptional written communication - client-facing reports, findings summaries, executive updates\nComfortable managing multiple engagements through async channels (Slack, email, project tools)\nAble to communicate technical findings clearly to non-technical stakeholders\nTools & platforms\nGRC platforms - Drata, Vanta, Thoropass, or equivalent\nAsana or similar PM tools for task and program tracking\nSafeBase or equivalent for security questionnaire management\nGoogle Workspace or Microsoft 365 proficiency\nNice to have\nCISA, CISM, CISSP, or CRISC certification\nMSSP or consulting firm background\nExperience supporting CMMC Level 2 or ITAR-adjacent programs\nFamiliarity with NYDFS 23 NYCRR Part 500 or other state-level frameworks\nExposure to cloud security environments (AWS, Azure, GCP)\nBackground in healthcare, defense, or fintech regulated industries\nPerformance benchmarks\n5 days\nSLA for security questionnaire responses\nMonthly\nwritten updates delivered to every active client\n0 gaps\nuntracked audit findings at any point in time\nCurrent\nrisk registers and corrective action logs maintained\nAligned\ncontrol monitoring mapped to each client’s framework scope\n100%\nTPRM assessments completed before vendor onboarding\nCompensation & perks\nCompetitive base salary - range shared during screening\nRemote-first with flexible working hours\nCertification reimbursement (CISA, CISM, CISSP, CRISC, and others)\nDirect collaboration with Bright Defense co-founders\nBroad client exposure across defense, healthcare, and fintech verticals\nClear growth path toward Senior ISM or vCISO functions\nBright Defense is an equal opportunity employer. We build diverse, high-trust teams.","description_format":"text","description_chars":5060,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Certification reimbursement","Flexible schedule"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Security Compliance"],"lifecycle":[{"event":"open","at":"2026-09-30T20:25:24Z"}],"liveness":{"score":10,"band":"cold","label":"Long shot","p_open":1,"p_active":0.364,"p_room":0.28,"age_days":171,"expected_fill_days":7,"reasons":["conf:9","win:tail","crowd:"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/bright-defense-information-security-manager-secops","json_url":"https://alion.io/job/bright-defense-information-security-manager-secops.json","meta":{"generated_at":"2026-10-01T20:02:15Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2756,"day_limit":5000,"remaining_today":2244,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}