Global IT Manager, Security & Compliance
Summary
Owns Serverfarm's IT security and compliance program across ~13 data center sites: audit evidence and certification defense for ISO 27001, SOC 1/2, PCI DSS and HIPAA, vendor and customer security due diligence, vulnerability management, incident response, and identity/access controls. A hands-on GRC-plus-technical-security role, remote with periodic site travel.
Key Accountabilities
Compliance and Risk
-
Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for a portfolio of approximately thirteen operating sites.
-
Act as IT's counterpart to external certification bodies and auditors — prepare for audits, present and defend control evidence, and own remediation of IT findings through to closure.
-
Manage third-party and vendor risk management for IT: vendor security assessments, a maintained vendor register with periodic reassessment.
-
Own customer-facing security due diligence — questionnaires, audits and assessments.
-
Maintain the IT risk register and opportunities-for-improvement log, and drive items to closure rather than allowing them to age.
-
Coordinate IT participation in business continuity and disaster recovery testing, and ensure results are documented.
Security Operations
-
Manage vulnerability management end to end — scanning coverage, triage, remediation ownership, escalation of anything aging, and periodic reporting to leadership.
-
Work along side counterparts to oversee endpoint detection and response and the security alerting pipeline; ensure alerts reach an owner and that investigations are recorded and closed.
-
Lead security incident response — containment, investigation, root cause, customer-facing incident reporting, and post-incident hardening.
-
Manage email security, including domain authentication posture and secure email gateway configuration.
-
Run the security awareness program — monthly phishing simulation, results analysis, and targeted follow-up.
Identity and Access
-
Contribute to identity governance across a hybrid estate spanning cloud and on-premises IdP
-
Oversee access review cadence, privileged access controls, and the joiner-mover-leaver process from an IT control standpoint, including third-party and contractor access.
Required Qualifications
-
Eight or more years in information security, IT compliance, or IT risk, with meaningful time spent in both compliance and technical security work.
-
Demonstrated ownership of an ISO 27001 program, including direct experience preparing for and defending findings with an external certification body.
-
Hands-on experience with at least two of: SOC 2, PCI DSS, HIPAA, NIS2, or DORA.
-
Genuine technical depth — you should be comfortable reading firewall and authentication logs, assessing a vulnerability scan, evaluating an OAuth consent request, and challenging an engineer's proposed remediation on its merits.
-
Experience with vulnerability management platforms, endpoint detection and response tooling, and enterprise identity platforms.
-
Experience leading security incident response through to a customer-facing or executive-facing conclusion.
-
Ability to communicate risk credibly to both engineers and executives, and to hold vendors and internal stakeholders accountable without formal authority over them.
-
Willingness to travel to sites periodically for audit, assessment, and control validation.
Skills
As published by lever
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL