Information Security Manager
Basys ProcessingAbout the role
Grow with a team that leads with service and builds with purpose.
At Basys, we believe success is built on relationships, not transactions. We collaborate, solve challenges head-on and raise the bar for ourselves and each other every day. If you’re energized by meaningful work and motivated to make a real impact, you’ll feel right at home here.
We personalize payments and elevate service so our clients can grow with confidence. And we’re building a company where innovation, care and accountability shape how we work: together.
Summary
The Information Security Manager is responsible for leading and executing the organization’s information security program, balancing governance, compliance, and hands-on technical security responsibilities. This role provides leadership to a team of security associates while partnering closely with IT, Engineering, and business stakeholders to identify, manage, and reduce security risk. The Information Security Manager ensures compliance with regulatory and customer security requirements, supports secure operations across systems and platforms, and contributes to a strong culture of security awareness and accountability across the organization.
Employees in this role are expected to perform their duties in accordance with The Way We Work, helping to create a company where innovation and care drive meaningful connections.
Duties & Responsibilities
Essential Functions
- Develop, implement, and maintain the company’s information security program, including security policies, standards, and control objectives.
- Provide leadership and day-to-day management for an assigned team of security associates, including work direction, coaching, performance feedback, and support of professional development.
- Conduct and lead information security risk assessments across applications, infrastructure, and third parties; maintain a risk management framework to identify, assess, document, prioritize, and track remediation of security risks.
- Oversee and perform (as needed) threat detection, vulnerability management, and incident response activities, including investigation coordination, root cause analysis, remediation tracking, and post-incident reviews.
- Own and manage the PCI DSS compliance lifecycle, including control implementation and validation, assessment coordination, evidence collection, and remediation of findings.
- Lead SOC 2 readiness, audits, and ongoing compliance by maintaining control documentation and mappings, coordinating evidence collection with cross-functional teams, and serving as the primary liaison to external auditors and assessors.
- Assess, monitor, and report third-party and vendor security risk, including due diligence reviews, security requirement input, and ongoing risk monitoring as applicable.
- Provide hands-on security support for cloud and networked environments (e.g., Azure and application networking), including reviewing configurations, recommending or implementing security controls, and partnering with IT and Engineering to remediate identified issues.
- Partner with Engineering to implement and validate application security requirements (e.g., OWASP-aligned controls), support secure development practices, identify security gaps, and track remediation to closure.
Additional Responsibilities
- Manage security awareness and training to support required policies, acceptable use practices, and security responsibilities across the organization.
- Support initiatives that enhance the security of associates, partners, systems, and integrations through collaboration, adherence to security practices, and continuous improvement.
- Work collaboratively with internal departments to support secure operations and a high standard of service for
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s