Information Security Manager
Ciklum is looking for an Information Security Manager to join our team full-time in Bulgaria.
We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners, we engineer technology that redefines industries and shapes the way people live.
About the role:
As an Information Security Manager, you'll become a part of a cross-functional development team engineering experiences of tomorrow. You will play a key role in protecting the IT organisation, promoting a security-first culture, and ensuring that critical digital assets and services remain secure and resilient. You will work closely with technical and business stakeholders to identify and manage security risks, strengthen security practices, and support the effective implementation of the information security strategy.
Responsibilities:
- Promote and embed a security-first culture across the organisation
- Drive adoption of and compliance with security policies, standards, and controls, providing expert advice and guidance to relevant stakeholders
- Contribute to the delivery and continuous improvement of the information security strategy and security programme
- Identify, assess, communicate, and manage information security risks, ensuring appropriate mitigation and remediation actions
- Ensure effective security operations, including vulnerability management, vulnerability scanning, patching, security assurance, and testing
- Coordinate and support effective security incident management across cloud and on- premises environments, ensuring lessons learned and remediation actions are implemented
- Oversee remediation activities resulting from security assessments and external audit findings
- Protect the confidentiality, integrity, availability, authenticity, and non-repudiation of information and data at rest and in transit
- Track and report the effectiveness of security initiatives against defined KPIs, identifying opportunities for continuous improvement
- Collaborate with technical, product, and business stakeholders to embed secure ways of working and ensure security considerations are incorporated into decision-making
- Provide pragmatic, risk-based security guidance, balancing security requirements, business objectives, and commercial considerations
Requirements:
- Proven experience in Information Security, including responsibility for security capabilities within a large or complex organisation
- Strong experience implementing and/or operating an Information Security Management System (ISMS) in a large organisation
- Good understanding of information security within AWS cloud environments
- Strong understanding of security operations and security incident management across cloud and on-premises environments
- Technical background with previous experience in a hands-on technical security role or strong practical exposure to areas such as security analysis, vulnerability management/scanning, penetration testing, or security operations
- Solid knowledge of security standards and frameworks such as ISO 27001, NIST, PCI DSS, OWASP, and ITIL
- Good understanding of the international regulatory environment, particularly data privacy requirements
- Strong stakeholder management and communication skills, with the ability to influence both technical and non-technical stakeholders and gain commitment to security objectives
- Strong planning and organisational skills, with the ability to prioritise security activities and maintain focus on agreed objectives and deliverables
- Strong analytical and problem-solving skills, with a logical and pragmatic approach to complex security and business challenges
- Ability to understand business needs, technical constraints, organisational structures, and stakeholder dependencies, and to identify relevant decision-makers and influencers
- Good commercial awareness, with the ability to balance security risks, business priorities, and practical considerations when making recommendations or supporting decisions
- Collaborative mindset and ability to work effectively within cross-functional and internationally distributed teams
Desirable:
- AWS Cloud Fundamental or Practitioner certification
- Professional security certifications such as ISO 27001 Lead Implementer, CompTIA Security+, CISMP, CISSP, CISM, or CISA
What’s in it for you?
- Regular salary reviews based on performance
- Corporate events: webinars, offline parties, and meetups
- Internal Mobility Program
- Tailored education path (including full access to Udemy, certifications, etc.)
- 25 paid days off: 20 business days of vacation per calendar year + 5 undocumented sick leave days
- Additional health insurance
- 100% company-covered Multisport card, with discounts available for family members
About us:
At Ciklum, we are always exploring innovations, empowering each other to achieve more, and engineering solutions that matter. With us, you’ll work with cutting-edge technologies, contribute to impactful projects, and be part of a One Team culture that values collaboration and progress.
Since expanding to Bulgaria in 2022, we’ve been building a fast-growing team that thrives on learning, collaboration, and innovation. Join us on this exciting journey and help shape the future of our delivery center.
Explore, empower, engineer with Ciklum!
Interested already? We would love to get to know you! Submit your application. We can’t wait to see you at Ciklum.
#LI-MH1