Information Security Manager
π Role Overview & Responsibilities
Job Title: Information Security ManagerLocation: Santa Clara CA, 95054 (Hybrid)Duration: 8 months
Description:We need a Security technical lead / Manager with the experience in Zscaler, Qualys, Threat Hunting experience.At least 5-8 years of Cyber Security Knowledge with relevant experience in Tools like Qualys, Zscaler, Defender, Firewalls. Needs to have exposure to Security Standards & Regulations like NIST, GDPR, PCI DSS.Job Description:Work with one of Clientβs prized clients in the heart of Silicon Valley by ensuring security for critical infrastructure.We are looking for a talented hands-on security professional that has deep technical knowledge also likes contributing to the strategic direction.In this role you will get to work with the full array of security solutions as well as support the security provisions throughout the environmentβs infrastructure β networks, servers, desktops and applications.You will also contribute toward strategic planning based on risk assessments and analysis.
Required. Skills:Client engagement soft skills are requiredThe ability to present and explain security and risk information for business executives to understandThe ability to lead people of various levels and technical expertiseThe ability to prioritize and persuade in order to move the security program forward amongst competing initiativesExperienced with security solutions (e.g. firewall, VPN, SIEM, IPS, URL filtering, Endpoint protection, MFA, NAC)Strong understanding of NIST 800-53 & CSF, risk assessment and incident response standardsStrong understanding of Microsoft Active Directory, GPOs, Windows DACL/SACL, and LinuxStrong understanding of protocols, such as IPsec, ESP, GRE, SSL/TLS, 802.1x, RADIUS/TACACS, HSRP, GSLB and WCCPAbility to perform and analyze packet capturesAbility to analyze suspicious emails, URLs, and files to ascertain if they are maliciousKnowledge of hacking techniques, vulnerability disclosures, and security analysis techniquesKnowledge of malware families, botnets, threats by sector, attack campaigns and attack methodsScripting language such as PowerShell or PERLFamiliarity with incident tracking, change management and project tracking systems like ServiceNow and Jira.
Description Ownership of day to day security events, perform incident response using NIST SP 800-61 standards, and determine root causesCreate and lead security initiatives that reduce risk as well as automate detection and protection mechanismsManage and update the cybersecurity plan in order to identify needs and implement comprehensive security controls using multi-layered security and defense in depthBe knowledgeable of customer information security policies, standards, and procedures, as well as the infrastructure equipment, versions and configurations.Collaborate with all operations teams to ensure security controls and configurations are implemented and incorporated in their ongoing operationsServer security through vulnerability management, system patching and secure configurationNetwork security through segmentation and firewall zoning and ACL policies, as well as secure configurations in firewalls, routers, switches, VPNs and load balancersEndpoint security management to prevent malware and insider threatsEmail security through Spam filtering and use of SPF & DMARCApplication security based on OWASP Top 10Monitor SIEM, IPS, event logs and reports for indicators of attack and indicators of compromiseProactive client involvement in solving client challenges and business opportunitiesContribute quarterly security advisories for the Security Awareness ProgramKeep security plans and documentation updated, such as the disaster recovery plans and security policies, and create internal operating procedures to support and enforce customer policies and procedures in order to ensure the availability, integrity, and confidentiality of customer assets and dataContinuously mature the GRC programGovernance: Collaborate with client stakeholders and steering committees to ensure plans and identified solutions meet business needs and expectations.Risk: Working with stakeholders to perform risk management and ongoing assessments, and then selecting mitigating and corrective controls based on Pareto analysisRisk: Reviewing SOWs and RFP responses to assess risksRisk: Collect, analyze, and validate open source intelligenceCompliance: Ensure regulatory compliance with PCI-DSS, CJIS, and California Consumer Privacy Act of 2018 (AB-375)Communicate with Client team on a regular basis to provide timely and informative reports and related analysis and recommendations to maintain and improve service deliveryProvide up-to-date information to clients in response to specific inquiries and meet all commitments ahead of due datesMonthly presentations to executives on current state of risks, status of security controls, and remediation timelinesMonthly reports on security operations that provide current states of security controls
Frequently Asked Questions
How do I apply for the Information Security Manager position at Select Source International? βΌ
Click the “Apply for this Position” button on this page to submit your application directly to Select Source International without recruitment intermediary fees.
Is this position eligible for remote work or visa sponsorship? βΌ
This position is located in Santa Clara, CA with potential relocation and sponsorship assistance depending on candidate qualifications.
Are there any candidate fees on Hirely? βΌ
No. Hirely is completely free for candidates. We never charge registration fees or placement fees.
Legitimate employers will never ask you to transfer funds, purchase equipment from unauthorized vendors, or pay application/visa fees. Hirely rigorously monitors listings, but always verify communication is from official corporate email domains.
Learn how to protect yourself against employment fraud →