Sr. Manager - Info Security (Moscow, ID) - 1007
Lightcast
Moscow, ID, USA
Posted on Mar 14, 2026
The Senior Manager, Information Security, leads the organization’s cybersecurity strategy, governance, and operational security programs while ensuring compliance with legal and regulatory requirements. This role protects company systems, networks, and data by developing security policies, managing risk and compliance initiatives, overseeing security operations, and leading incident response efforts. The role works closely with Legal, IT, Engineering, DevOps, and executive leadership to embed strong security practices across the organization.
Major Responsibilities:
Develop and implement the organization’s information security strategy, policies, and governance frameworks aligned with business and legal requirements.
Lead risk assessments, vulnerability management, and enterprise security risk mitigation initiatives.
Ensure compliance with industry standards and regulatory frameworks such as SOC 2, ISO 27001, GDPR, NIST, and CIS.
Oversee day-to-day security operations, including threat monitoring, vulnerability management, detection, and incident response processes.
Ensure the security of cloud environments, networks, applications, and internal infrastructure, including controls such as firewalls, encryption, and identity management.
Partner with IT, engineering, DevOps, product, and legal teams to integrate security into systems and development processes.
Lead and mentor security engineers and analysts, promote security awareness, and report security posture and risks to executive leadership.
Education and Experience:
-
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a
related field (Master’s degree preferred).
5-8+ years of experience in cybersecurity or information security.
3–5+ years in leadership or management roles.
-
Experience with cloud security platforms (AWS, Azure, or GCP) and security
operations, including incident response and vulnerability management.
Experience leading audits, assessments, and remediation efforts.
Strong knowledge of security frameworks such as NIST, ISO 27001, and CIS
Preferred certifications: CISSP, CISM, CCSP, GIAC, or equivalent