Infovisa, Inc.
Information Security Officer
United States · Posted today
Opens infovisa.applytojob.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- Not specified
- Source
- Jazzhr (employer's hiring system)
Skills mentioned
SOC 2, Incident Response, AWS, Cybersecurity, SIEM, Cloud Security
About the role
JOB DESCRIPTION
Position Title: Information Security OfficerDepartment: Information Security FLSA Status: Exempt
Reports To: Chief Operating Officer Hours: 8:00 – 5:00, ET (core)
Location: Cornelius, North Carolina or Lincoln, Nebraska Compensation: Salary + Bonus
Position SummaryThe Information Security (IS) Officer owns Infovisa’s information security program including designing, implementing, and monitoring the controls that protect the enterprise while enabling the business to operate and thrive. As the company’s designated security leader, this person is accountable not only for identifying risk but for closing it. Working closely with company management and the IT team, the IS Officer sets security standards and policy, personally operates the company’s core security tooling, and provides independent oversight of the security-related work carried out by IT.
The role operates under GLBA and SOC 2 obligations and has primary responsibility for the company’s information security program.
The person in this position works across the following areas and technologies: Network Security; Enterprise Firewalls (Check Point, Check Point Harmony VPN); AWS cloud security; Endpoint Detection and Response (CrowdStrike); Security Information and Event Management (Sophos); Vulnerability Management; Identity and Access Management (Entra ID); Windows Server, Hyper-V, and IIS; TLS certificate management and PKI; DNS; and the application infrastructure of the enterprise network.
Essential Functions- Program ownership: own the information security program including strategy, policies, standards, and their day-to-day execution; accountable for closing findings.
- Executive reporting: serve as the company’s designated security owner under GLBA; report the state of security risk and remediation directly to executive management in terms of threat level and associated risk.
- Security monitoring & detection: operate and maintain the enterprise security monitoring and log-management capability; define data inputs and alerting, monitor for threats, and respond to events.
- Endpoint & threat protection: manage endpoint detection and response and related malware protection across the environment.
- Vulnerability, patch & hardening: own the vulnerability management lifecycle from identification through verified remediation, and set patch-management and system-hardening standards for servers and databases, monitoring compliance.
- Firewall policy & oversight: define and maintain the firewall change policy and security configuration standards; oversee execution through formal change control; review higher-risk and datacenter firewall changes prior to implementation.
- Identity & access: set identity and access-management standards and own periodic access reviews, including timely removal of access for separated associates.
- Incident response: lead security incident response through detection, containment, remediation, and post-incident review.
- Policy, documentation & compliance: develop, maintain, and enforce security policies and procedures; own the written information security program required under GLBA and the control evidence required for SOC 2; coordinate SOC 2 readiness and act as the primary internal owner for security control evidence.
- Audits, examinations & testing: participate in external audits, third-party vulnerability scans and penetration tests, and regulatory examinations including gathering artifacts and attending interviews.
- Vendor risk: conduct third-party/vendor security reviews and manage security vendor relationships.
- Awareness training: manage cybersecurity awareness training for all associates.
- Team leadership: hire, train, mentor, and manage associate(s) on the security team; provide security direction to IT staff who execute security-related changes.
- Industry engagement: act as liaison to FS-ISAC / IT-ISAC, InfraGard, and other industry groups; share information as appropriate.
- Budget: assist in developing the annual security budget and tracking expenses.
- Availability: participate in an after-hours on-call rotation and work evenings and weekends as needed to support security operations, incident response, and change windows.
- Maintain up-to-date knowledge of applicable technologies and equipment; assist with escalated support when necessary.
- Understand and adhere to all company policies, laws, and regulations applicable to the role; report compliance issues in accordance with company policy.
- Perform other job-related duties or special projects as assigned.
- 10 years of information security experience required.
- Three years of management experience.
- Hands-on expertise across firewalls and network security (Check Point preferred), SIEM operations, EDR, vulnerability management, and AWS security.
- Working knowledge of GLBA (Safeguards Rule) and SOC 2 control frameworks; demonstrated experience supporting audits and regulatory examinations.
- Strong policy and procedure-writing skills and a track record of detailed technical documentation.
- Valid driver’s license.
- Four-year degree in information technology / systems, or computer and information science or equivalent experience.
- Preferred: Check Point certification and one or more applicable security certifications (e.g., CISSP, CISM, or equivalent).
- Analytical and detailed.
- Effective communicator, including with executive leadership and in the board room.
- Organized.
- Independent with good judgment.
- Proven ability to multitask and prioritize projects.
- Self-directed and takes initiative.
- Participates in an after-hours on-call rotation; evening and weekend work is required as needed.
- Mostly indoor work with occasional exposure to outdoor elements or hazards.
- Medium workload; lifting and/or carrying up to 20 pounds frequently and exerting up to 75 pounds of force occasionally.
- Some travel required.
This is an in-office position in Cornelius, NC or Lincoln, NE. Successful candidates will live within commuting distance of one of these offices or be willing to relocate.
About Infovisa
Infovisa is a leading provider of financial technology solutions delivered to forward-thinking trust, wealth management, and retirement professionals. Infovisa’s solutions empower its clients to acquire new customers, invest assets effectively, manage trust and investment portfolios efficiently, and flexibly report results to customers. For more information about Infovisa, visit www.infovisa.com. Follow us on LinkedIn.
We are interested in every qualified candidate who is lawfully eligible to work in the United States.
We are unable to sponsor visas.
Infovisa, Inc. is an Equal Opportunity Employer.
Job ID jz-infovisa-20261007141910_vlpey4bfzu5ubhav · Original posting ↗
Similar jobs
Information Security Officer 3 (Security Architect, Application and Product Security)3dGovernment of AlbertaEdmonton, Alberta
- Chief Information Security Officer, Global3dVantage Data Centers Management Company LLCDenver, Colorado · On-site
- Information Security Officer - AVP3dCharles River Systems Inc MAQuincy, Massachusetts · On-site
- Chief Information Security Officer8dSlash FinancialSan Francisco, California · On-site
- Chief Information Security Officer12dUniversity of AlbertaEdmonton, Alberta · On-site