Information Security Manager
Jobgether · United States · Yesterday
RemoteRemoteInformation TechnologyFull-time
Accountabilities
- Operating, enhancing, and maintaining enterprise security programs that protect sensitive information and support compliance with industry regulations.
- Managing security operations, identity governance, audit readiness, data protection initiatives, and vendor security processes while serving as a key partner across technology and business teams.
- Administering and enhancing identity and access management processes, including Microsoft Entra ID, Active Directory, user lifecycle management, conditional access, MFA, SSO integrations, and role-based access controls.
- Conducting regular access reviews, account audits, and remediation activities to maintain least-privilege access and strengthen security controls.
- Operating and optimizing security monitoring capabilities, including SIEM platforms, security alerts, endpoint visibility, and threat detection processes.
- Investigating and responding to security incidents by supporting identification, containment, recovery, documentation, and continuous improvement efforts.
- Maintaining and improving security controls aligned with defense-in-depth strategies and organizational risk objectives.
- Supporting compliance programs including SOC 2, URAC, HIPAA, and HITRUST CSF initiatives through evidence collection, control mapping, audit preparation, and remediation tracking.
- Leading security certification readiness activities, including gap assessments, control implementation, and coordination with internal and external stakeholders.
- Providing security oversight for applications, integrations, data flows, and system configurations to ensure secure design and operation.
- Managing data governance activities, including Microsoft Purview administration, data classification, loss prevention controls, retention policies, eDiscovery, and legal hold support.
- Evaluating and managing security tools, vendors, and third-party risk processes, including product assessments, renewals, configuration oversight, and security reviews.
- Developing and maintaining security documentation, including policies, procedures, standards, technical baselines, and operational runbooks.
- Responding to security-related requests and support teams with timely, well-documented solutions.
- Communicating security risks, recommendations, and technical concepts effectively to both technical and non-technical audiences.
Requirements
- Strong information security experience, technical knowledge of Microsoft security technologies, and familiarity with compliance requirements in regulated industries.
- Hands-on experience with Microsoft security technologies, including Entra ID, Active Directory, Microsoft 365, and Azure.
- Experience supporting compliance frameworks such as SOC 2, HITRUST, URAC, and HIPAA.
- Proven experience with identity and access management, SSO, SIEM operations, and data governance solutions.
- Experience conducting vendor security assessments and managing third-party security risks.
- Knowledge of healthcare, pharmacy benefits management, or other highly regulated environments preferred.
- Familiarity with security certifications such as CISSP, CISM, CompTIA Security+, SC-200, SC-300, AZ-500, or HITRUST CCSFP preferred.
- Strong technical understanding with the ability to translate security concepts for diverse audiences.
- Excellent written and verbal communication skills.
- Strong problem-solving mindset with the ability to work independently and manage multiple priorities.
- Able to maintain a reliable remote work environment with strong availability and communication practices.
- Able to support occasional after-hours activities related to security incidents or audit deadlines.
- Able and willing to travel approximately 10-20%.
Benefits
- Competitive compensation package.
- Health, dental, vision, and additional employee benefits.
- Fully remote work environment.
- Opportunity to contribute to meaningful improvements in healthcare technology and data security.
- Opportunity to work in a collaborative culture focused on innovation, trust, and professional growth.
- Opportunity to influence security strategy and strengthen enterprise security capabilities.