远程工作雷达

全球IT经理,安全与合规

Global IT Manager, Security & Compliance

开发工程全球可投
公司serverfarm
薪资未公开
工作地点Remote, GA
地域资格全球可投
时区要求无特别要求
用工类型Full-Time
发布时间未知
数据来源Lever
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

Serverfarm 是一家领先的数据中心开发商和运营商,在 750 多个地点运营,并在 45 个国家建立了关键客户关系。我们正在重塑北美、西欧和以色列的数据中心运营方式,为全球领先的科技和超大规模公司提供服务。随着 2023 年 Manulife Investment Management 的收购以及我们获奖的 InCommand 平台,随着人工智能采用和云迁移推动对数据中心容量前所未有的需求,我们正处于爆发式增长的有利位置。

在 Serverfarm 职业生涯意味着站在数字基础设施创新的最前沿,你的工作将直接影响全球数据的管理和安全。随着我们未来四年实现四倍增长的目标,你将有机会迎接新的挑战,掌握尖端技能,并在我们不断扩展的全球业务中发展自己的职业生涯。

加入我们的创新团队,帮助塑造可持续数据中心的未来,同时打造无边界的事业。

Serverfarm 致力于提供平等的就业机会,提供带薪休假、带薪假期、401k 和全额覆盖的医疗、牙科和视力保险。我们的薪酬理念是奖励员工在实现与公司目标和战略举措一致的价值和成果方面取得的成就。

该职位的薪资范围是基于竞争性就业市场的估算。最终薪酬将根据您的个人技能、经验和所在地区确定。

上述陈述旨在描述该职位的一般性质和工作水平。它们并非旨在作为所有可能职责和职责的详尽列表。即使您的经验与职位描述不完全匹配,我们也鼓励您申请。

关键职责

合规与风险

  • 负责涵盖 ISO 27001:2022、SOC 1、SOC 2、PCI DSS 和 HIPAA 的 IT 证据计划,适用于约十三个运营站点的组合。
  • 作为 IT 部门与外部认证机构和审计师的对应方——准备审计、展示并辩护控制证据,并负责 IT 发现问题的整改直至关闭。
  • 管理 IT 的第三方和供应商风险管理:供应商安全评估,维护供应商登记册并进行定期重新评估。
  • 负责面向客户的网络安全尽职调查——问卷、审计和评估。
  • 维护 IT 风险登记册和改进机会
查看英文原文

Serverfarm is a leading developer and operator of data centers with over 750+ locations and key customer relationships in 45 countries. We're revolutionizing how data centers operate across North America, Western Europe, and Israel, serving the world's leading technology and hyperscale companies. With Manulife Investment Management's acquisition in 2023 and our award-winning InCommand platform we're positioned for explosive growth as AI adoption and cloud migration drive unprecedented demand for data center capacity.

A career at Serverfarm means being at the forefront of digital infrastructure innovation, where your work directly impacts how the world's data is managed and secured. As we target 4x growth over the next four years, you'll have unprecedented opportunities to take on new challenges, develop cutting-edge skills, and grow your career across our expanding global operations.

Join our team of innovators and help shape the future of sustainable data centers while building a career without boundaries.
Serverfarm is committed to providing an equal opportunity workplace and offers paid time off, paid holidays, 401k and FULL coverage medical, dental and vision. Our compensation philosophy rewards employees for achieving the values and objectives aligned with the company’s goals and strategic initiatives.

The listed salary range for this position is an estimate based on the competitive job market. Final compensation will be based on your own individual skills, experience, and location.

The above statements are intended to describe the general nature and level of work being performed in this role. They are not intended to serve as an exhaustive list of all possible responsibilities and duties. We encourage you to apply even if your experience isn't an exact match to the job description.

Key Accountabilities

Compliance and Risk

  • Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for a portfolio of approximately thirteen operating sites.
  • Act as IT's counterpart to external certification bodies and auditors — prepare for audits, present and defend control evidence, and own remediation of IT findings through to closure.
  • Manage third-party and vendor risk management for IT: vendor security assessments, a maintained vendor register with periodic reassessment.
  • Own customer-facing security due diligence — questionnaires, audits and assessments.
  • Maintain the IT risk register and opportunities-for-improvement log, and drive items to closure rather than allowing them to age.
  • Coordinate IT participation in business continuity and disaster recovery testing, and ensure results are documented.

Security Operations

  • Manage vulnerability management end to end — scanning coverage, triage, remediation ownership, escalation of anything aging, and periodic reporting to leadership.
  • Work along side counterparts to oversee endpoint detection and response and the security alerting pipeline; ensure alerts reach an owner and that investigations are recorded and closed.
  • Lead security incident response — containment, investigation, root cause, customer-facing incident reporting, and post-incident hardening.
  • Manage email security, including domain authentication posture and secure email gateway configuration.
  • Run the security awareness program — monthly phishing simulation, results analysis, and targeted follow-up.

Identity and Access

  • Contribute to identity governance across a hybrid estate spanning cloud and on-premises IdP
  • Oversee access review cadence, privileged access controls, and the joiner-mover-leaver process from an IT control standpoint, including third-party and contractor access.

Required Qualifications

  • Eight or more years in information security, IT compliance, or IT risk, with meaningful time spent in both compliance and technical security work.
  • Demonstrated ownership of an ISO 27001 program, including direct experience preparing for and defending findings with an external certification body.
  • Hands-on experience with at least two of: SOC 2, PCI DSS, HIPAA, NIS2, or DORA.
  • Genuine technical depth — you should be comfortable reading firewall and authentication logs, assessing a vulnerability scan, evaluating an OAuth consent request, and challenging an engineer's proposed remediation on its merits.
  • Experience with vulnerability management platforms, endpoint detection and response tooling, and enterprise identity platforms.
  • Experience leading security incident response through to a customer-facing or executive-facing conclusion.
  • Ability to communicate risk credibly to both engineers and executives, and to hold vendors and internal stakeholders accountable without formal authority over them.
  • Willingness to travel to sites periodically for audit, assessment, and control validation.
本页面信息整理自 Lever,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位