SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 150,000 - 180,000 / annual
Synack operates a Penetration Testing as a Service (PTaaS) platform that helps organizations discover assets, identify critical vulnerabilities, and understand security risks. The company has uncovered over 71,000 exploitable vulnerabilities and serves Global 2000 customers and U.S. federal agencies in a FedRAMP Moderate Authorized environment.
As Manager of Information Security, you will lead compliance and security control efforts across the organization. Your responsibilities include automating the generation of System Security Plans (SSP), Security Concept of Operations, Risk Management Matrices, and Security Control Traceability Matrices. You'll conduct Security Impact Analysis on major system changes and develop automated Plans of Action and Milestones (POAMs).
A key focus area is managing AI and agentic systems used across Synack. You will own the inventory and risk assessments of these systems, ensuring alignment with NIST AI Risk Management Framework and ISO 42001 standards. This includes oversight of data handling, model and agent change control, and non-human identity and credential scoping.
You will build automated evidence collection processes and monitor control drift across security controls. You'll codify security controls into Infrastructure as Code (IaC) guardrails, Cloud Native Application Protection Platform (CNAPP) policies, and CI/CD checks to prevent risks at commit and deploy time. Regular stakeholder communication on security compliance issues, aligned to CIS and NIST standards, is essential, along with tracking mitigation tasks and generating reports.
You'll work collaboratively with Project Managers, Software Engineers, and field teams to respond to vendor security assessments and conduct third-party risk assessments. The role emphasizes a DevSecOps approach and enabling (non-obstructive) security practices.
Required qualifications include 8+ years in IT Security Strategy, Risk Management, IT Audit, and Compliance, preferably with a Cloud Service Provider. You need hands-on experience with Python, Terraform, and CI/CD pipelines, plus comfort integrating tools with AI. Familiarity with Enterprise GRC tools, event monitoring platforms (Datadog, Stackdriver, Azure Sentinel), SOAR platforms, CNAPP, and detection engineering is expected. You should have working knowledge of ISO 27000, ISO 42001, OWASP, SOC2, GDPR, CMMC, FedRAMP, and NIST frameworks. Excellent communication skills for both technical and non-technical audiences are critical.
Note: U.S. citizenship is required due to federal government contract requirements.