Jobs · Information Technology · California

Senior Information Security Manager

Fortinet · Sunnyvale, CA · 1 wk ago
HybridInformation Technology$167k–$204k/yrFull-time

About the role

Fortinet is seeking a Senior Information Security Manager to lead the information security team in the U.S., focusing on information security compliance projects. This role oversees the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS), coordinates security compliance initiatives across the organization, and serves as the primary liaison with external auditors and regulatory bodies. The position requires a strong understanding of ISO/IEC 27001 and NIST security frameworks, cloud security, risk management, governance, and security operations. The successful candidate must be a U.S. citizen and work onsite at Fortinet's headquarters in Sunnyvale, California.

Responsibilities

  • Manage the information security team, lead the design, implementation, operation, and continual improvement of the Information Security Management System (ISMS).
  • Perform gap analysis based on NIST SP800-53 and other compliance frameworks, create mitigation/action plans.
  • Determine the applicability and apply information security and privacy requirements to ISMS policies.
  • Prepare required documents for supporting various compliance frameworks such as FedRAMP and GovRAMP.
  • Develop related KPI metrics for performance measurement to ensure continued compliance and improvement.
  • Create compliance project plans and manage their implementation.
  • Conduct risk and privacy impact assessments on business and operational processes, prepare finding reports, and create and implement risk treatment plans.
  • Collaborate with operations teams to ensure appropriate controls are implemented and operated properly.
  • Participate in and lead daily security operations, oversee the handling of security alerts and incidents.
  • Lead vulnerability management activities, monitor remediation progress, and work closely with operations teams to ensure timely patching of identified vulnerabilities.
  • Manage internal and external audits, develop audit plans, and respond to various audits and review requests.

Requirements

  • 7+ years of experience in information security, with people and project management experience.
  • Subject matter expert in NIST SP800-53, ISO/IEC 27000, and SOC2 related standards, regulations, and guidelines.
  • Experience managing FedRAMP or GovRAMP implementation and compliance is highly preferred.
  • Knowledge and experience working with various information security frameworks (ISO/IEC 27001, NIST 800-53, NIST SP800-161, GovRAMP, FedRAMP, PCI DSS) and regulatory frameworks (SOX, PCI-DSS, HIPAA, GDPR, SOC, etc.).
  • Strong knowledge of and experience in privacy frameworks and regulatory compliance requirements (e.g., GDPR, CCPA).
  • Strong network security knowledge and thorough understanding of current and emergent trends in information security.
  • Working knowledge of information security control technologies including access control, cryptography, vulnerability management, SIEM/log management, ID/IPS, and penetration testing.
  • Working knowledge and hardening skills on information technologies including Linux, Windows, VMWare, MySQL, MSSQL, etc.
  • Working knowledge of cloud platforms, cloud security (AWS, Azure, GCP), and network security.
  • Experience and knowledge of Fortinet products and services are preferred.
  • Strong verbal and written communication skills, with the ability to work with team members, cross-functional teams, and external parties.
  • Ability to work independently in a fast-paced, dynamic environment, establish priorities, and meet deadlines.
  • Strong analytical mindset with the ability to gather and report data in a meaningful format.
  • Passionate about policies, processes, and documentation, with the ability to translate general standards into practical guidelines suitable for business operations.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Certifications in one or more of the following are desirable: CISSP, CISA, CISM, ISO 27001 Lead-Auditor, VCP, CCSP, CRISC, NIST SP800-53 related training program, or GovRAMP/FedRAMP related training program.

About Our Team

Join our collaborative team, working seamlessly with global customers, internal engineering teams, and product development groups. Our team culture emphasizes continuous learning, innovation, and a strong commitment to customer satisfaction. We embrace Fortinet’s core values of openness, teamwork, and innovation, fostering an environment where team members support each other, share knowledge, and leverage AI to solve complex technical challenges. Our inclusive and dynamic team thrives on collaboration and is driven by the shared goal of maintaining Fortinet’s high standards of excellence in cybersecurity solutions.

Pay

The U.S. base salary range for this full-time position is $166,500–$203,500. Exact salary offers will be determined by factors such as the candidate's subject knowledge, skill level, qualifications, experience, and geographic location. All roles are eligible to participate in the Fortinet equity program. Bonus eligibility is reviewed at the time of hire and annually at the Company’s discretion.

Benefits

  • Medical, dental, vision, life, and disability insurance.
  • 401(k) retirement plan.
  • 11 paid holidays.
  • Vacation time and sick time.
  • Comprehensive leave program.

About Us

Fortinet (NASDAQ: FTNT) secures the largest enterprise, service provider, and government organizations around the world. We empower our customers with intelligent, seamless protection across the expanding attack surface and the power to take on ever-increasing performance requirements of the borderless network—today and into the future. Only the Fortinet Security Fabric architecture can deliver security without compromise to address the most critical security challenges, whether in networked, application, cloud, or mobile environments. Fortinet ranks number one in the most security appliances shipped worldwide, and more than 500,000 customers trust Fortinet to protect their businesses.

Similar jobs