Resume example · Technology & Security

Information Security Manager Resume Example

A full, ATS-ready Information Security Manager resume — with the security program you own, the audits and frameworks recruiters search for, and quantified leadership bullets that prove you can reduce organizational risk, lead a team, and pass the audit. Build yours free, then hand the search to a real strategist.

Resume examples → Technology & Security → Information Security Manager · Updated June 2026

The short version: An Information Security Manager resume wins on the security program you owned and the risk you measurably reduced — roadmap delivered, audits and certifications passed (SOC 2, ISO 27001, PCI DSS), team and budget managed, incidents handled, and findings closed — each backed by the frameworks you run. Recruiters and applicant tracking systems scan for security program management, GRC, risk management, NIST CSF, ISO 27001, SOC 2, and incident response in the top third of the page, plus CISSP or CISM. Below is a complete sample you can adapt, the keyword bank that gets you found, the salary range, and the mistakes that quietly get security-leadership resumes cut.

What an Information Security Manager actually does

An Information Security Manager owns an organization's security program — the strategy, the controls, the people, and the budget that protect its systems, data, and reputation. This is a leadership and governance role, not a hands-on-keyboard one: where an analyst triages alerts, the manager decides which risks the business will accept, sets policy, runs the audits, leads the team that does the triage, and translates security into language the executive team and the board will fund. Hiring managers are not buying a tool operator; they are buying lower organizational risk, a program that survives an audit, and a leader who can make security a business enabler rather than a blocker.

Day to day and quarter to quarter, the core responsibilities look like this:

  • Own the security program and roadmap — defining the multi-year security strategy, maturing the program against a framework (NIST CSF, ISO 27001, CIS Controls), and reporting progress to executives and the board.
  • Run governance, risk, and compliance (GRC) — maintaining the risk register, leading risk assessments, writing and enforcing security policies and standards, and steering the company through audits and certifications (SOC 2 Type II, ISO 27001, PCI DSS, HIPAA).
  • Lead the security team — hiring, mentoring, and managing security engineers and SOC analysts, setting OKRs, running the on-call and escalation model, and owning the security operating budget.
  • Direct incident response — owning the incident-response plan and tabletop exercises, serving as incident commander during major events, and presenting post-incident reviews to leadership.
  • Manage third-party and vendor risk — running the vendor security review process, assessing SaaS and supply-chain risk, and embedding security requirements into procurement and contracts.
  • Oversee identity, vulnerability, and operations programs — setting direction for IAM, vulnerability management, endpoint and cloud security, and security awareness training, then holding the team and IT to SLAs.
  • Be the business partner for security — advising engineering and product on secure design, supporting sales with security questionnaires and trust reviews, and making the risk trade-offs that let the business move fast safely.

The role overlaps with titles like Security Manager, Cybersecurity Manager, IT Security Manager, GRC Manager, and Security Operations Manager, and it sits on the path between senior analyst/engineer roles and Director of Security or CISO. Because postings use these labels and emphasize different mixes of governance, operations, and leadership, a strong Information Security Manager resume mirrors the exact title and the program scope named in the job it targets.

What hiring managers and ATS look for in an Information Security Manager resume

Security leadership is keyword-dense and credential-sensitive, so the applicant tracking system filters hard on frameworks, certifications, and program language. But the hiring manager — often a CISO, VP of Engineering, or CIO — is reading for something the parser can't grade: can you own a program, lead people, pass an audit, and brief the board without melting down? The resumes that earn the interview do four things:

  • Lead with program outcomes, not tasks. "Built and matured the security program from ad-hoc to a NIST CSF Tier 3 posture and passed first SOC 2 Type II with zero exceptions" beats "Responsible for information security." The program-level result is the headline; the framework is the proof.
  • Quantify leadership scope. Team size managed, budget owned, number of audits passed, risk reduced, MTTR improvement, vendor reviews completed, and policy coverage are the numbers security leaders are measured on. Scope signals altitude — managing 8 people and a $2M budget reads very differently from "worked on security."
  • Name the frameworks and the audit outcomes. NIST CSF, ISO 27001, SOC 2, PCI DSS, HIPAA, and CIS Controls tell the reader you govern with structure — and stating that you passed (or led the company to) a specific certification is the single most credible line on the page.
  • Surface the keywords and the certifications in the top third. A leadership summary, a certifications line (CISSP, CISM), and a skills block must carry the framework, audit, and GRC language from the posting, because that is exactly what recruiters paste into search. Clearance, if you hold one, goes near the top.
Rule of thumb: for a management resume, every line should answer "what did your program achieve, at what scope?" A framework or tool that appears only in a skills list — with no audit passed, no risk reduced, no team led behind it — reads as a course you took, not a program you ran.

A full Information Security Manager resume example

Here is a complete, realistic sample for a mid-to-senior Information Security Manager on the path toward Director of Security. Adapt the names, companies, and numbers to your own record — and keep every metric honest.

Marcus T. Delacroix
Information Security Manager · GRC, SecOps & Risk
Austin, TX · marcus.delacroix@email.com · (512) 555-0147 · linkedin.com/in/mdelacroix-sec
Leadership Summary

Information Security Manager with 9+ years in security and 4+ years leading teams, building and maturing security programs for regulated and high-growth SaaS environments. Owns the full GRC lifecycle — risk management, policy, audits, and vendor risk — and leads SecOps and incident response. Took two organizations through first-time SOC 2 Type II and ISO 27001 certification, reduced enterprise risk, and built security teams from the ground up. Operates to NIST CSF and ISO 27001; CISSP and CISM certified.

Core Competencies
Program & Strategy
Security program management, roadmap, security maturity (NIST CSF, CIS Controls)
GRC
Risk management, risk register, policy development, security awareness, audit management
Compliance
SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, NIST 800-53, GDPR readiness
Leadership
Team building & mentoring, budget ownership, board/executive reporting, OKRs
Operations
Incident response (incident commander), SecOps/SOC oversight, vulnerability management
Identity & Cloud
IAM, SSO/MFA, AWS & Azure security, cloud posture management, Zero Trust
Vendor & 3rd-party
Vendor risk management, security questionnaires, contract/DPA review
Professional Experience
Information Security Manager2022 – Present
Northwind Cloud (Series C B2B SaaS, ~900 employees) · Austin, TX
  • Built and matured the company's security program from ad-hoc to a NIST CSF Tier 3 posture, defining the 3-year roadmap and reporting quarterly to the board's audit committee.
  • Led the company's first SOC 2 Type II and ISO 27001 certifications to completion with zero major nonconformities, unblocking $14M in enterprise pipeline gated on security review.
  • Hired and now lead a 7-person security team (SecOps, GRC, and security engineering) and own a $2.4M annual security budget, cutting tooling spend 18% through vendor consolidation.
  • Stood up the enterprise risk register and quarterly risk-assessment cadence, driving residual high risks down 41% in 18 months and securing executive sign-off on the risk-acceptance process.
  • Served as incident commander on 5 major incidents, rebuilt the IR plan and ran quarterly tabletops, cutting mean time to respond (MTTR) from 6 hours to under 90 minutes.
  • Launched the vendor-risk program (350+ vendors assessed) and embedded security requirements into procurement, reducing average sales-security-questionnaire turnaround from 9 days to 2.
Security Team Lead / Senior Security Engineer2019 – 2022
Lattice Financial (fintech / PCI-regulated) · Austin, TX
  • Promoted to lead a 3-person team after owning the company's PCI DSS program, passing two consecutive annual assessments with no compensating-control findings.
  • Designed and rolled out the IAM and least-privilege program (SSO, MFA, quarterly access reviews) across 1,100 employees, closing all prior identity-related audit findings.
  • Built the vulnerability-management SLA framework and drove remediation of 2,000+ critical/high findings to a 95% 30-day SLA across engineering and IT.
  • Authored 20+ security policies and standards mapped to NIST 800-53, establishing the governance baseline the program still runs on.
Information Security Analyst → Senior Analyst2016 – 2019
Cardinal Health Partners (regional healthcare, HIPAA) · Dallas, TX
  • Ran SOC monitoring and incident response, then moved into GRC — leading HIPAA risk assessments and building the evidence library that passed the org's first external security audit.
  • Tuned detection and reporting that cut false positives 50% and gave leadership its first monthly security-posture dashboard.
Certifications

CISSP (ISC2) · CISM (ISACA) · CRISC (ISACA) · AWS Certified Security – Specialty · (in progress) CCSP

Education

B.S. in Management Information Systems — The University of Texas at Austin

Why this works: every bullet leads with a program-level outcome and a number, leadership scope is explicit (team size, budget, board reporting), and the audit results — SOC 2 Type II, ISO 27001, PCI DSS — are stated as passed, not just "supported." The frameworks (NIST CSF, NIST 800-53) and certifications (CISSP, CISM) appear inside proven results, not only in a list.

Key hard skills, soft skills, and ATS keywords

Use these as a checklist against the posting you are targeting. Include the ones you genuinely have, in the exact phrasing the job description uses, and prove the important ones in a bullet.

Hard skills & domains (the ATS keyword bank)

security program managementGRCrisk managementrisk assessmentrisk registerpolicy developmentNIST CSFNIST 800-53ISO 27001SOC 2PCI DSSHIPAAGDPRCIS Controlsaudit managementincident responsesecurity operations (SOC)vulnerability managementvendor / third-party riskIAMSSO / MFAZero Trustcloud security (AWS/Azure)security awarenessdata privacybusiness continuity / DRSIEMEDRDLPsecurity architecturebudget managementteam leadershipboard reportingKPIs / metrics

Soft skills that matter for security management

A manager is hired as much for judgment and leadership as for technical depth, so the human skills carry decisive weight. The ones hiring managers probe in interviews — and that belong, demonstrated, in your bullets — are executive communication and influence (translating risk into business language the board will fund), leadership and people management (hiring, mentoring, retaining a team), risk-based decision-making (knowing which risks to accept, mitigate, or escalate), cross-functional collaboration with engineering, legal, and procurement, and calm command during a live incident. Show them through outcomes ("briefed the board," "built a 7-person team," "drove sign-off on risk acceptance") rather than asserting them as adjectives.

Certifications worth listing

CertificationWhy it helps
CISM (ISACA)The management-focused credential; signals security governance, risk, and program-leadership maturity. Frequently named in manager postings.
CISSP (ISC2)The broad senior-security standard; an extremely common gate for security-leadership roles and often required.
CRISC / CISA (ISACA)Validates enterprise risk management (CRISC) and audit (CISA) depth — directly aligned to the GRC half of the role.
CCSP / AWS or Azure SecurityProves cloud-security leadership, increasingly expected as programs move to the cloud.

What Information Security Managers earn

In the United States, Information Security Managers typically earn a base salary between roughly $130,000 and $200,000, with a median commonly in the $150,000–$170,000 range. The U.S. Bureau of Labor Statistics places security managers within Computer and Information Systems Managers, which reports a median near $170,000 per year. Newer managers and those at smaller companies start closer to $120,000–$140,000; senior managers and those leading larger teams in high-cost metros or in finance, technology, and healthcare push past $200,000 before bonus and equity, and the step up to Director of Security or CISO opens a meaningfully higher band. Security management is among the fastest-growing leadership tracks in tech, with BLS projecting employment for the broader category to grow much faster than average. Pay rises fastest with team and budget scope, demonstrated audit and certification ownership, regulated-industry and cloud-security depth, and stacked credentials (CISSP, CISM).

Salary figures are general US ranges grounded in public labor-market data (BLS Occupational Employment Statistics for Computer and Information Systems Managers and Information Security Analysts); your number will vary by location, company size, industry, team scope, and seniority. Use the free Salary Analyzer to pressure-test an offer.

Common Information Security Manager resume mistakes

1. Reading like a senior analyst, not a manager. The most common error is a resume full of hands-on triage bullets with no program, no team, and no scope. Promote yourself: lead with the program you owned, the team and budget you managed, and the audits you passed.
2. No audit or certification outcomes. If your resume never names a SOC 2, ISO 27001, PCI DSS, or HIPAA result, the reader can't gauge your governance level. "Led the company to its first SOC 2 Type II with zero exceptions" is the single most credible manager line you can write.
3. Hiding leadership scope. Team size, budget owned, and board/executive reporting are what separate a manager from an individual contributor. Leaving them off makes a real leadership role read like a senior IC one.
4. A tool dump instead of a risk story. Listing 25 security products signals an operator, not a leader. A manager's resume is about risk reduced, frameworks operationalized, and outcomes — tools are supporting evidence, not the headline.
5. "Responsible for" passive bullets. Duties describe a seat; verbs and numbers describe a leader. Start every bullet with an action verb (built, led, matured, passed, reduced, briefed) and end it with a measurable result.
6. Burying CISSP/CISM or the GRC keywords. For management roles these certs and the governance language are often hard ATS gates. Put them in a leadership summary, a certifications line, and a skills block near the top — not at the bottom where the knockout filter may miss them.

Information Security Manager resume FAQ

What should an Information Security Manager resume focus on?

The security program you owned and the risk you measurably reduced — roadmap delivered, audits and certifications passed (SOC 2, ISO 27001, PCI DSS), team and budget managed, incidents led, and findings closed — each backed by the frameworks you run. Hiring managers are buying governance, leadership, and lower organizational risk, with frameworks and metrics as the proof.

What are the most important keywords on an Information Security Manager resume?

Security program management, GRC, risk management, NIST CSF, ISO 27001, SOC 2, PCI DSS, incident response, vendor/third-party risk, IAM, vulnerability management, and security operations, plus leadership terms (team management, budget ownership, board reporting) and certifications (CISSP, CISM). Mirror the exact phrasing in the posting.

How much do Information Security Managers make?

Base salary typically runs roughly $130,000–$200,000, with a median commonly around $150,000–$170,000; the BLS median for the broader Computer and Information Systems Managers category is near $170,000. Senior managers and those in high-cost metros or regulated industries exceed $200,000 before bonus and equity.

Do I need certifications on an Information Security Manager resume?

They carry real weight and many postings require CISSP or CISM. CISM signals security-management and governance maturity; CISSP signals broad senior depth; CRISC and cloud-security credentials differentiate further. Pair them with demonstrated program ownership and audit outcomes — leadership evidence outranks any single credential.

How long should an Information Security Manager resume be?

Two pages is standard for a manager with a real leadership track record; one page is fine only under roughly eight years of experience. Keep it dense with program-level outcomes — audits passed, risk reduced, team and budget scope — and put certifications and a leadership summary near the top.

Build it free — then put a human on the search

Start your Information Security Manager resume free in Backstage, Marqee's self-serve builder. It keeps your formatting parser-clean, suggests the right frameworks, GRC language, and certifications from the job description, and tells you what's missing before you submit. When you want the search actually working — not just the document polished — a real Marqee strategist takes over: tailoring and submitting applications on your behalf, running recruiter outreach, and surfacing referrals so you get top billing with the CISOs and VPs who hire security leaders, instead of getting lost in the pile.