Role: Information Security Manager
Location: Pittsburgh, PA
Work Model: Hybrid – 3 days onsite / 2 days remote
About eNGINE
eNGINE builds Technical Teams. We are a Solutions and Placement firm shaped by decades of interaction with Technical professionals. Our inspiration is continuous learning and engagement with the markets we serve, the talent we represent, and the teams we build. Our Consulting Workforce is encouraged to enjoy career fulfillment in the form of challenging projects, schedule flexibility, and paid training/certifications. Successful outcomes start and finish with eNGINE.
Role Overview
eNGINE is seeking a Manager, Information Security to lead a technically strong security team while helping mature the organization's security operations, governance, risk, and compliance capabilities.
This role is designed for a security leader who has real operational experience and a strong technical foundation. You won't be expected to spend your days configuring firewalls or responding to every security ticket, but you need to understand the technology, speak the language of engineers, and have enough hands-on experience to challenge assumptions and make sound decisions.
The ideal candidate has roughly 10+ years in IT/security, including direct people-management experience, and has developed the leadership skills to manage highly technical security professionals in a high-expectation environment. You'll be responsible for setting priorities, providing meaningful feedback, managing risk, overseeing vendors and budgets, and ensuring security initiatives actually move forward.
This is a highly visible position that requires someone who can work effectively with technical teams, executives, business stakeholders, and demanding clients. Professional services or law firm experience is a plus, particularly for candidates who have experience navigating stakeholders who have strong opinions and high expectations.
The Three Pillars of the Role:
Security
Own and continuously improve security governance, risk, compliance, architecture, and operational capabilities across the organization.
You'll need to understand security controls in practice—not simply what a framework says should exist. The successful candidate can distinguish between a legitimate compensating control and a weak justification, evaluate whether a risk is genuinely acceptable, and explain practical alternatives when a proposed approach isn't the right answer.
Operations
Provide leadership and oversight across the organization's security technology and operational processes, including:
- Network security and Palo Alto firewall environments
- Privileged access management and CyberArk
- Vulnerability management and Tenable
- Endpoint security and CrowdStrike
- Email security and phishing analysis
- Identity and remote access controls
- Security monitoring and incident response
- Security-related cloud and infrastructure controls
- Physical security controls where applicable
You'll manage the team responsible for day-to-day operational tickets while also driving larger projects and a steady pipeline of process and administrative improvements.
Leadership
Lead and develop a team of experienced security professionals while establishing a culture of accountability, collaboration, and continuous improvement.
This includes setting expectations, prioritizing competing demands, delivering both positive and constructive feedback, supporting career development, managing performance, and ensuring the team understands what success looks like.
Duties & Responsibilities
- Lead and develop a team of security engineers and technical security professionals.
- Establish priorities for security operations, projects, risk activities, and continual improvement initiatives.
- Provide direction and escalation support for day-to-day security operations without becoming the team's primary hands-on engineer.
- Evaluate security risks based on practical business and technical realities rather than theoretical concerns alone.
- Partner with leadership and GRC stakeholders on risk assessment, mitigation strategies, and security decision-making.
- Manage security policies, standards, procedures, and operational processes.
- Oversee compliance activities associated with ISO 27001, ISO 27701, and PCI-DSS, including audits, evidence collection, remediation, and client assurance requests.
- Review security controls and determine where requirements are mandatory versus where legitimate compensating controls or alternative approaches may be appropriate.
- Provide technical and business context when communicating security risks to executives, attorneys, business leaders, and other non-technical stakeholders.
- Oversee vulnerability management, privileged access, endpoint protection, firewall security, email security, identity controls, monitoring, and related security technologies.
- Guide security architecture and design reviews involving network, infrastructure, applications, identity, collaboration platforms, and cloud environments.
- Coordinate security incident response, investigation, remediation, and recovery activities.
- Track security findings, audit issues, vulnerabilities, and remediation efforts through completion.
- Manage security vendors, managed security service providers, and other third-party relationships.
- Participate in third-party risk assessments and vendor security reviews.
- Manage the security budget and help determine where investments will provide the greatest reduction in organizational risk.
- Partner with Data Governance and IT teams to ensure security, privacy, and operational requirements are incorporated into broader technology processes.
- Improve security processes, workflows, documentation, and administrative practices across the organization.
- Help the security team balance operational demands with longer-term projects and strategic initiatives.
- Build strong working relationships with highly technical engineers while maintaining clear leadership and accountability.
- Provide guidance during difficult or high-pressure situations and make informed decisions when competing priorities arise.
- Support security awareness efforts and advise employees and leadership on emerging threats, policies, controls, and best practices.
Qualifications
- 10+ years of experience across information technology, information security, infrastructure, systems, networking, or related technical disciplines.
- Significant professional experience working directly with security and IT operations.
- Previous experience managing or supervising a team of technical security professionals.
- Strong understanding of network, systems, identity, endpoint, cloud, and infrastructure security.
- Demonstrated experience with security governance, risk management, and compliance.
- Hands-on familiarity with enterprise security technologies such as Palo Alto, CyberArk, Tenable, CrowdStrike, email security platforms, and related tools.
- Experience with ISO 27001 and ISO 27701, with an understanding of how security controls are implemented and evaluated in real environments.
- Working knowledge of PCI-DSS requirements.
- Ability to assess technical risks and translate them into business-level decisions and recommendations.
- Strong understanding of IT operational and engineering processes.
- Experience managing competing priorities across operational work, projects, compliance requirements, and continuous improvement.
- Strong communication and interpersonal skills with the ability to work effectively with technical and non-technical stakeholders.
- Demonstrated ability to provide candid, constructive feedback while maintaining trust and team cohesion.
- Ability to handle confidential information with a high degree of discretion.
- Bachelor's degree in a related field or equivalent combination of education and professional experience.
Preferred Experience
- Experience working in a law firm, professional services, financial services, or similarly high-expectation environment.
- Experience supporting environments where executives, attorneys, partners, or other demanding stakeholders require a high level of responsiveness and professionalism.
- Experience with GRC and formal risk management programs.
- Experience with third-party/vendor risk assessments.
- Familiarity with data governance and privacy programs.
- Experience managing security budgets and vendor relationships.
- Experience with security awareness, phishing analysis, and incident response.
- Experience evaluating compensating controls and documenting risk-based security decisions.
- Exposure to physical security controls and their relationship to broader security programs.
- CISSP, CISM, CEH, or CIPP certification is highly desirable; candidates actively pursuing one of these certifications will also be considered.
Next Steps
No C2C, relocation, referral, or sponsorship candidates for this role.
For finer details on how eNGINE can impact your career, apply today!
Pay: $160,000.00 - $180,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Health insurance
- Paid time off
- Vision insurance
Work Location: Hybrid remote in Pittsburgh, PA 15222