Neumo Logo

Neumo

Manager, Information Security (Remote)

Posted One Month Ago
In-Office or Remote
6 Locations
Senior level
In-Office or Remote
6 Locations
Senior level
Leads security operations and engineering strategy, manages a 2–3-person team, and remains hands-on with WAF, DLP, AI security, automation, vulnerability management, incident response, cloud security, purple teaming, SIEM, and detection engineering. Partners with executives and cross-functional leaders, oversees vendors and tooling, reports risk metrics, and develops team capabilities and security roadmaps.
The summary above was generated by AI

Job Summary:

We are seeking a Manager, Information Security to lead the execution of our Security Operations and Engineering program. This is a hands-on, player-coach role: you will manage a small, high-caliber team of 2–3 direct reports while also personally rolling up your sleeves on engineering, triage, and incident response when needed. You will own the roadmap and day-to-day execution across Web Application Firewall (WAF), Data Loss Prevention (DLP), AI Security and Security Automation, Vulnerability Management, Incident Management, Cloud Security, Purple Team, and broader Security Engineering across our infrastructure.

Duties and Responsibilities: 

  • Execute the Security Operations and Engineering strategy, aligning priorities with overall business and security goals.
  • Operate as a player-coach: manage, mentor, and grow 2–3 direct reports while remaining hands-on with engineering and operational work.
  • Partner with the CISO and cross-functional leaders (Engineering, IT, Compliance, HR, Legal) to align security initiatives with business needs.
  • Manage team capacity, priorities, and career development; conduct performance reviews and coaching.
  • Own vendor and tooling deployments.
  • Report on program metrics, risk posture, and roadmap progress to Senior leaders
  • Web Application Firewall (WAF): Own configuration, tuning, and lifecycle management of WAF policies to protect production applications from evolving threats.
  • Data Loss Prevention (DLP): Design, implement, and continuously improve DLP controls across endpoints, cloud, and email to protect sensitive data.
  • AI Security / Automation: Evaluate and secure AI tools and workflows used across the business; build automation (including AI-assisted) to scale detection, triage, and response.
  • Vulnerability Management: Own the end-to-end vulnerability management lifecycle: scanning, prioritization, remediation tracking, and reporting — across infrastructure and applications.
  • Incident Management: Lead incident response efforts, from detection through containment, eradication, and post-incident review; maintain and improve incident response playbooks.
  • Cloud Security: Set and enforce cloud security architecture, configuration standards, and controls across our cloud environments.
  • Purple Team: Run and mature purple team exercises, partnering offense and defense to validate detection and response capabilities and close gaps.
  • Security Engineering: Design, build, and maintain security tooling and infrastructure (detection engineering, logging/SIEM, automation pipelines) across the environment.
  • Perform other duties as assigned.


 Education and Experience:

  • 7+ years of experience in information security, with at least 2–3 years in a people management or team lead capacity.
  • Demonstrated player-coach experience: comfortable managing a team while remaining technically hands-on.
  • Hands-on experience with WAF platforms, DLP tooling, vulnerability management platforms, and cloud security controls (AWS, Azure, and/or GCP).
  • Experience leading or participating in incident response, including root cause analysis and post-incident reporting.
  • Experience building or deploying automation to scale security operations; exposure to AI/LLM tooling and its security implications is a strong plus.
  • Relevant certifications (e.g., CISSP, CISM, GCIH, OSCP, or cloud security certifications) are a plus but not required.


Knowledge, Skills and Abilities: 

  • Familiarity with purple team methodologies and how offensive testing informs defensive engineering.
  • Strong scripting/automation skills (e.g., Python, Terraform or similar) for tooling and detection engineering.
  • Excellent communication skills, with the ability to translate technical risk for executive and non-technical audiences.
  • Proven ability to context-switch across strategic, operational, and tactical work without losing focus or quality.


Work Environment:

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.


Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.

Similar Jobs

One Month Ago
In-Office or Remote
6 Locations
Senior level
Senior level
Information Technology • Software
Own and mature Neumo’s Governance, Risk, and Compliance program, including SOC 1, SOC 2, and PCI DSS audits, risk registers, data governance, control automation, vendor assessments, and exception processes. Manage 1–2 direct reports, coordinate remediation, leverage AI/LLM tools, participate in incident management, and communicate compliance posture and risk trends to executives and the board.
Top Skills: Ai/Llm ToolingArcherDrataIso 27001JIRANist CsfOnetrustPci DssServicenow GrcSoc 1Soc 2Vanta
2 Hours Ago
Remote or Hybrid
45K-85K Annually
Junior
45K-85K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handle inbound calls and warm leads, consult customers on insurance needs, recommend appropriate Property and Casualty coverage, and convert leads into policyholders. The role includes paid licensing and training, customer-focused sales, commission opportunities, and remote work. Employees must complete a weekday and weekend schedule, maintain a dedicated home workspace with wired high-speed internet, and remain in their resident state for at least one year.
Top Skills: Cable InternetDsl InternetFiber InternetPcWired High-Speed Internet
7 Hours Ago
In-Office or Remote
140K-170K Annually
Senior level
140K-170K Annually
Senior level
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Manages multiple global regulatory and licensing programs from market-entry planning through approval. Builds plans, sequences dependencies, assigns owners, tracks risks, coordinates Legal, Compliance, Finance, Product, Engineering, and other teams, and prepares executive steering updates. Establishes scalable program standards, reporting metrics, and AI-enabled workflows while supporting policy activities and procurement. Requires regulatory or compliance experience in financial services, fintech, or another regulated industry, strong communication, discretion, and the ability to lead through influence.
Top Skills: AIApple MacosBlockchainChatgptClaudeGeminiGoogle SuiteSlackVibebox

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account