Manager, Information Security - (Open to remote)
BertelsmannAbout the role
Penguin Random House is looking for an Information Security Manager to join the Corporate Information Security team. The Corporate Information Security team owns the Information Security Management System (ISMS) responsibilities for the company and delivers an information security foundation to achieve and maintain legal, regulatory, and contractual compliance.
The IS Manager will be focused on evaluating technology controls, supporting risk assessments, leading audit coordination, and executing control activities related to fraud, training, and policy management.
The ideal candidate will have the mindset of a Risk Manager and the organizational skills of a Project Manager who can communicate complex security issues and requirements with diverse audiences in a way that drives understanding, collaboration, and ownership.
Who you are:
- Deeply knowledgeable of Information Security standards and best practices.
- Confident and willing to ask questions and raise issues in a timely manner.
- Process oriented with strong project management skills to ensure accountability and high-quality results.
- Strong verbal and written communicator with the ability to quickly build rapport with internal and external stakeholders.
- Ability to adapt to change, including evolving business and technical environments, and manage multiple priorities while meeting deadlines in a challenging environment.
- Team player with a collaborative work style.
- Self-motivated and able to work efficiently with minimal oversight/direction.
What you’ll do:
Risk Management
- Assist in the assessment and implementation of the global Information Security Management System (ISMS) requirements, which include Risk Assessments, Control Gap Assessments, and Business Impact Analyses.
- Drive risk mitigation activities by owning the design, tracking, and progress of action plans across various processes, technologies, and business areas.
- Develop and execute an internal audit program that aligns with internal Information Security requirements, external regulations, and risk findings.
- Enhance the company's risk register by defining metrics and reporting on key risk indicators (KRIs) and key performance indicators (KPIs).
- Manage the Information Security compliance of a portfolio of standalone companies owned by Penguin Random House.
Fraud Management
- Monitor external threat intelligence information to identify potential fraud or other malicious activity and escalate when necessary.
- Liaise with the Legal Department and takedown services to address typo squatting, social media impersonations, and email fraud.
Policy Development
- Define and document Corporate Information Security policies and guidelines to align with regulations, industry best practices, and special topics.
- Manage and maintain the Information Security policy repository and support policy communications and distribution.
Training & Awareness
- Enhance cybersecurity awareness by promoting employee education, managing anti-phishing campaigns, and communicating best practices.
- Develop security awareness materials and quick reference guides to present to stakeholders across the organization, including senior management.
Project Management
- Operationalize Corporate Information Security projects through all implementation stages from defining requirements to training end users.
- Track Corporate Information Security program tasks and effectively communicate program health and effectiveness, key accomplishments, and risks to senior management both within Security and to other business stakeholders.
Must Have:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s