Senior Information Security Manager

Fortinet
Sunnyvale
Workplace: HybridFull timeUSD 166,500 - 203,500 annuallyFunction: CybersecurityExperience: 7+ yearsEducation: bachelorsSkills: ["Communication","Cross-functional collaboration","Independent work","Analytical mindset","Documentation"]

Lead the Information Security team and oversee the design, implementation, operation, and continual improvement of an Information Security Management System (ISMS). Own security compliance programs across the organization, conduct NIST/FedRAMP/GovRAMP gap analyses, and manage risk and privacy impact assessments. Serve as the primary liaison with external auditors and regulatory bodies while driving security operations, incident handling, vulnerability management, KPIs, and audit readiness.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Fortinet
Fortinet
2 days ago

Senior Information Security Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Lead the Information Security team and oversee the design, implementation, operation, and continual improvement of an Information Security Management System (ISMS). Own security compliance programs across the organization, conduct NIST/FedRAMP/GovRAMP gap analyses, and manage risk and privacy impact assessments. Serve as the primary liaison with external auditors and regulatory bodies while driving security operations, incident handling, vulnerability management, KPIs, and audit readiness.
Location: Sunnyvale
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Manage the information security team and lead the design, implementation, operation, and continual improvement of the ISMS.
  • •Perform NIST SP800-53-based gap analyses and create mitigation/action plans; determine and apply information security and privacy requirements to ISMS policies.
  • •Prepare documentation for compliance frameworks such as FedRAMP and GovRAMP; develop KPI metrics to measure performance and continuous compliance improvement.
  • •Conduct risk and privacy impact assessments, produce finding reports, and create and implement risk treatment plans.
  • •Lead internal and external audits, manage security operations (alerts and incidents), and oversee vulnerability management and remediation progress.

Pay and Benefits

Salary: USD 166,500 - 203,500 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401k

Key Requirements

  • •7+ years of information security experience with people and project management experience.
  • •Strong subject-matter expertise in NIST SP800-53, ISO/IEC 27000, and SOC 2-related standards and regulatory guidelines.
  • •Experience with managing FedRAMP or GovRAMP implementation and compliance is highly preferred.
  • •Working knowledge of information security frameworks and regulatory compliance requirements (e.g., ISO/IEC 27001, NIST 800-53, NIST SP800-161, GovRAMP, FedRAMP, PCI DSS; GDPR, CCPA).
  • •Strong knowledge of privacy frameworks and regulatory compliance requirements and experience with security control technologies.
Experience:7+ yearsInformation securityCybersecuritySecurity complianceCloud securityRisk management
Education:Bachelor's
Skills:CommunicationCross-functional collaborationIndependent workAnalytical mindsetDocumentation
Certifications:CISSPCISACISMISO 27001 Lead-AuditorVCPCCSPCRISCNIST SP800-53 trainingGovRAMP/FedRAMP training
Tech Stack:ISO/IEC 27001ISO/IEC 27000NIST SP800-53NIST SP800-161FedRAMPGovRAMPSOC 2SOCPCI DSSSOXGDPRCCPAAWSAzureGCPLinuxWindowsVMwareMySQLMSSQL

Eligibility

Nationality:US National
Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Fortinet
Provides enterprise cybersecurity solutions including data protection, cloud security, network security, and user and entity behavior analytics to help organizations prevent insider threats, secure cloud and on-premises environments, and enforce data loss prevention policies.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Austin, United States
Founded: 1994
WebsiteLinkedIn