Jobs and Careers
MA
Manager, Security Trust and Assurance
MalwarebytesUnited States, United Statesfull_timeVerifiedPosted 31 Jul 2024
About the role
Malwarebytes believes that when people and organizations are free from threats, they are free to thrive. Founded in 2008, CEO Marcin Kleczynski had one mission: to rid the world of malware. Today, Malwarebytes has grown beyond malware remediation to ensuring cyber-protection for everyone, providing device protection, privacy, and prevention solutions in the home, on-the-go, at work, or on campus. With threat hunters and innovators across the world, we want great people, like YOU, to join our team! Malwarebytes is looking for... An experienced Trust and Assurance Manager as part of our Security Team who is excited to grow our GRC, Business Continuity, Incident Management and External Assurance programs. As the Trust and Assurance Manager, you will ensure that our internal customers have the best possible experience as consumers of security services within Malwarebytes. You will define and automate processes, to ensure our Trust and Assurance service is the best in class. You will be working closely with Sales, Sales Engineers, Product, Engineering, IT, Legal, Customer Success, and third-party vendors to help mature our Security, Trust and Assurances practices over time. You will design and implement security controls, documentation, and lead the compliance programs and certifications, such as SOC 2, ISO 27001, HIPPA and PCI. Collaborate with cross-functional stakeholders, system and business owners and external auditors to ensure risk, security and privacy audits are operating effectively and efficiently. Ability to work autonomously and keep peers and leadership teams informed about progress. What You’ll Do: Inspire and lead a successful security program with a track record of delivery.GovernanceDirectly responsible for policies, procedures, security awareness activities, and controls to assure compliance with good business practices, as well as applicable regulatory, legal and audit requirements.Risk ManagementImplement processes that are sustainable for identifying risk, perform risk assessment based on risk management framework, recommend and consult on risk mitigation plans, monitor and report on remediation status.Audit and ComplianceStrengthen Audit and Compliance program, and oversee compliance monitoring, audit and controls for certifications and frameworks, including SOC 2, ISO 27001, GDPR, HIPAA, PCI and more.Security Sales EnablementCollaborate with Sales, Account Management and Customer Success teams to help close deals through customer questionnaires, questions, etc., and working with Engineering, Product, Legal and IT on security best practices integration and documentation.Business Continuity/Disaster RecoveryOversee the organization’s programs to address and maintain business continuity and resilience risks, disaster recovery to ensure program’s robustness and effectiveness in the protecting systems in preparation for an event and for independent assessments against regulatory and compliance frameworks. Drive table top exercises with key stakeholders across the organization.Incident ManagementKeep updated incident response plan and other pertinent documentation. Partner with security, engineering operations, customer success, global communications teams, to update incident communication templates for stakeholder updates, on real or business impacting events.Third-Party RiskOversee third-party risk security risk assessment program. Align practical risk mitigation with business objectives and foster a risk-conscious corporate culture.Training and EvangelismTrain Malwarebytes employees on security best practices at onboarding and ongoing. ReportingProduct monthly presentations for the Security Steering Committee and leadership teams on risk and key security metrics Skills You’ll Need to Have:
- Minimum of five (5) years of experience focused on information security and compliance
- BS/MS degree in Computer Information Systems or related field
- Thorough knowledge of information security and compliance concepts
- Strong knowledge of and experience in security requirements, standards and practices to include NIST CSF, NIST 800-53, SOC 2, ISO 27001, GDPR, COBIT, PCI DSS, HIPAA, OWASP Top 10, etc.
- Business acumen, communication skills and process-oriented
- Detail-oriented with the ability to see the “big picture”
- Strong analytical and problem-solving skills
- Experience in supporting and driving security compliance programs
- Strong understanding of information security and privacy standards and best practices related to data confidentiality (CCPA/CPRA, GDPR)
- Practical experience in developi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s