Senior Manager of Information Security
What security roles in crypto pay
64 salaries · our own dataThis role pays $179k-$190k, below the $202k median for security roles in crypto on this board.
As Senior Manager of Information Security at Plume, you lead and mature the company's security program at a critical inflection point. With ISO 27001 and SOC 2 Type 1 certifications already in place, you'll formalize policies and procedures, build a high-functioning security team, and protect infrastructure, networks, cloud environments, and applications-all while enabling, not blocking, the engineers and developers who build the products.
What you'll do
- Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
- Author, formalize, and maintain policies, standards, and procedures to close remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor and third-party risk, change management, business continuity, etc.).
- Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
- Manage relationships with external auditors, penetration testers, and compliance partners.
- Own the security of infrastructure, networks, cloud environments (AWS and GCP), and applications end to end.
- Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging and monitoring, and incident response.
- Establish and continuously improve secure SDLC practices: threat modeling, secure code review, dependency and supply-chain security, and CI/CD pipeline security.
- Build and run the incident response plan, run tabletop exercises, and lead response when needed.
- Lead, coach, and develop the security team, establishing clear roles, workflows, and a sense of ownership.
- Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
- Define how the team engages with Engineering and Product through embedded reviews, self-service tooling, and clear SLAs to minimize friction and rework.
- Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership.
- Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no."
- Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage.
What you bring
- A Bachelor's degree in Information Security, Computer Science, Computer Engineering, or a related field, or equivalent work experience.
- 6-8+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
- Direct experience operating within ISO 27001 and SOC 2 frameworks-you know what "audit-ready" looks like day to day, not just at renewal time.
- Strong technical depth in cloud security (AWS and GCP), network security, and modern application security (SDLC, AppSec tooling, container and Kubernetes security).
- Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment.
- A track record leading security teams that engineers actually like working with-you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates.
- Experience managing external auditors, penetration testers, and compliance vendors.
- Excellent communication skills: able to flex between a whiteboard session with engineers and a risk briefing with the board.
Nice to have
- CISSP, CISM, or similar certification.
- Experience implementing or operating under ISO 27701 (privacy extension to ISO 27001) and the NIST Cybersecurity Framework (CSF).
- Experience at a company of similar size and stage (post-certification, scaling team).
What we offer
- Base compensation range of $179,000-$190,000, plus up to 15% bonus and equity.
- Benefits include a 401k plan with company match, basic life insurance, and health, dental, vision, and other benefits and perks.
- Visa sponsorship is not available at this time.
About Plume
Plume is the creator of the only open, hardware-independent, cloud-controlled experience platform for ISPs and their subscribers. The company's software-defined network serves over 60 million locations globally and has managed over 3 billion devices on its platform. Plume partners with over 400 ISP customers, including Charter, Liberty Global, and J:COM, and maintains OpenSync, the most widely supported open-source, silicon-to-cloud framework for smart spaces.
