Skip to main content
Cambium Learning® Group

Technical Security Manager

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior security manager to run and mature an information security/GRC program for an education‑tech SaaS company. Requires 5+ years hands‑on security experience, strong knowledge of ISO/GovRAMP/FedRAMP/NIST/SOC frameworks, privacy laws (GDPR, COPPA, FERPA) and GRC tooling. Remote role supporting audits, risk assessments, security awareness, and vendor/software security reviews.

Core skills

GRC toolingISO/GovRAMP/FedRAMP compliance

Required skills

ISO 27001ISO 27018ISO 42001ISO 9001GovRAMPFedRAMPNIST 800SOCCIS ControlsGRC toolsrisk assessmentssecurity awareness programsprivacy frameworks (GDPR)COPPAFERPA

Optional skills

CISSPGIACISACA certificationsAWS Security certificationPMPAI Governance experience (NIST, ISO42001)

What you'll do

  • Maintain, mature, and take ownership of the information security program to ensure conformance to security standards (ISO 27001, ISO 27018, ISO 42001, ISO 9001, GovRAMP, FedRAMP, NIST 800, SOC, CIS Top Controls).
  • Facilitate annual independent audits by third‑party security and privacy experts, create audit plans, coordinate stakeholders, review reports, and remediate audit findings.
  • Plan and manage multiple security improvement projects from requirements through deployment/implementation.
  • Manage document and record control processes and procedures, maintain accurate inventories and records of compliance/conformance artifacts.
  • Own Security Awareness and related training programs; maintain and improve processes, platforms and systems supporting training campaigns; create, monitor and report on campaigns.
  • Support business development by responding to security and privacy information requests included in proposals.
  • Perform security risk assessments of software acquisitions, technical services, business systems and new technologies.
  • Own and administer a GRC tool to track security controls and conformance status; ensure relevant security artifacts are recorded and updated.
  • Conduct enterprise risk assessment reviews and report to senior management on security issues and metrics.
  • Assist continual improvement by examining security posture, identifying risks/gaps, and recommending programs to address them.
  • Manage privacy risks including exposures from cookies and APIs; maintain privacy policies and ensure compliance.

What they require

  • Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Engineering, Information Systems or related technical field.
  • Minimum 5 years hands‑on experience in the information security field.
  • Extensive knowledge of security and privacy frameworks, standards, and industry best practices.
  • Knowledge of privacy laws and principles such as GDPR, COPPA, and FERPA.
  • Extensive knowledge of tools and techniques to protect against cybersecurity attacks and respond to incidents.
  • Information Security certifications such as CISSP, GIAC, ISACA, AWS Security (preferred).
  • Experience with GRC tools.
  • Exceptional verbal and written communication skills for technical and executive audiences.
  • Demonstrated experience with security and privacy standards such as ISO, GovRAMP, FedRAMP and other frameworks.
  • Experience writing, developing, and maintaining security and privacy records and documentation.
  • Experience reducing organizational risk via risk assessments, gap analysis, improvement plans and tracking corrective actions/POAMs to closure.
  • Experience developing and executing project management plans for technical projects.
  • Experience coordinating with senior business leaders, subject matter experts, technical leaders and third‑party consultants.
  • Experience or desirable experience in AI Governance and frameworks such as NIST and ISO42001.

Benefits

  • Not specified beyond standard application instructions and Equal Opportunity Employer statement.

Cambium Learning® Group is an award-winning educational technology solutions leader... (full company blurb in source)

🇺🇸 United StatesEdTechEnterprise
Salary not disclosed