← All jobs
PN

Senior Manager of Information Security

Plume NetworkUnited States
Type
Full-time
Work setup
On-site
Experience
Senior
Posted
6 days ago
🛂 Visa sponsorship
$179k - $190k
midpoint below market median

What security roles in crypto pay

64 salaries · our own data
this role$145kmedian$268k

This role pays $179k-$190k, below the $202k median for security roles in crypto on this board.

As Senior Manager of Information Security at Plume, you lead and mature the company's security program at a critical inflection point. With ISO 27001 and SOC 2 Type 1 certifications already in place, you'll formalize policies and procedures, build a high-functioning security team, and protect infrastructure, networks, cloud environments, and applications-all while enabling, not blocking, the engineers and developers who build the products.

What you'll do

  • Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
  • Author, formalize, and maintain policies, standards, and procedures to close remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor and third-party risk, change management, business continuity, etc.).
  • Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
  • Manage relationships with external auditors, penetration testers, and compliance partners.
  • Own the security of infrastructure, networks, cloud environments (AWS and GCP), and applications end to end.
  • Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging and monitoring, and incident response.
  • Establish and continuously improve secure SDLC practices: threat modeling, secure code review, dependency and supply-chain security, and CI/CD pipeline security.
  • Build and run the incident response plan, run tabletop exercises, and lead response when needed.
  • Lead, coach, and develop the security team, establishing clear roles, workflows, and a sense of ownership.
  • Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
  • Define how the team engages with Engineering and Product through embedded reviews, self-service tooling, and clear SLAs to minimize friction and rework.
  • Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership.
  • Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no."
  • Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage.

What you bring

  • A Bachelor's degree in Information Security, Computer Science, Computer Engineering, or a related field, or equivalent work experience.
  • 6-8+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
  • Direct experience operating within ISO 27001 and SOC 2 frameworks-you know what "audit-ready" looks like day to day, not just at renewal time.
  • Strong technical depth in cloud security (AWS and GCP), network security, and modern application security (SDLC, AppSec tooling, container and Kubernetes security).
  • Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment.
  • A track record leading security teams that engineers actually like working with-you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates.
  • Experience managing external auditors, penetration testers, and compliance vendors.
  • Excellent communication skills: able to flex between a whiteboard session with engineers and a risk briefing with the board.

Nice to have

  • CISSP, CISM, or similar certification.
  • Experience implementing or operating under ISO 27701 (privacy extension to ISO 27001) and the NIST Cybersecurity Framework (CSF).
  • Experience at a company of similar size and stage (post-certification, scaling team).

What we offer

  • Base compensation range of $179,000-$190,000, plus up to 15% bonus and equity.
  • Benefits include a 401k plan with company match, basic life insurance, and health, dental, vision, and other benefits and perks.
  • Visa sponsorship is not available at this time.

About Plume

Plume is the creator of the only open, hardware-independent, cloud-controlled experience platform for ISPs and their subscribers. The company's software-defined network serves over 60 million locations globally and has managed over 3 billion devices on its platform. Plume partners with over 400 ISP customers, including Charter, Liberty Global, and J:COM, and maintains OpenSync, the most widely supported open-source, silicon-to-cloud framework for smart spaces.

Senior Manager of Information Security | CryptoJobsHQ