The short version: An Information Security Manager resume wins on the security program you owned and the risk you measurably reduced — roadmap delivered, audits and certifications passed (SOC 2, ISO 27001, PCI DSS), team and budget managed, incidents handled, and findings closed — each backed by the frameworks you run. Recruiters and applicant tracking systems scan for security program management, GRC, risk management, NIST CSF, ISO 27001, SOC 2, and incident response in the top third of the page, plus CISSP or CISM. Below is a complete sample you can adapt, the keyword bank that gets you found, the salary range, and the mistakes that quietly get security-leadership resumes cut.
What an Information Security Manager actually does
An Information Security Manager owns an organization's security program — the strategy, the controls, the people, and the budget that protect its systems, data, and reputation. This is a leadership and governance role, not a hands-on-keyboard one: where an analyst triages alerts, the manager decides which risks the business will accept, sets policy, runs the audits, leads the team that does the triage, and translates security into language the executive team and the board will fund. Hiring managers are not buying a tool operator; they are buying lower organizational risk, a program that survives an audit, and a leader who can make security a business enabler rather than a blocker.
Day to day and quarter to quarter, the core responsibilities look like this:
- Own the security program and roadmap — defining the multi-year security strategy, maturing the program against a framework (NIST CSF, ISO 27001, CIS Controls), and reporting progress to executives and the board.
- Run governance, risk, and compliance (GRC) — maintaining the risk register, leading risk assessments, writing and enforcing security policies and standards, and steering the company through audits and certifications (SOC 2 Type II, ISO 27001, PCI DSS, HIPAA).
- Lead the security team — hiring, mentoring, and managing security engineers and SOC analysts, setting OKRs, running the on-call and escalation model, and owning the security operating budget.
- Direct incident response — owning the incident-response plan and tabletop exercises, serving as incident commander during major events, and presenting post-incident reviews to leadership.
- Manage third-party and vendor risk — running the vendor security review process, assessing SaaS and supply-chain risk, and embedding security requirements into procurement and contracts.
- Oversee identity, vulnerability, and operations programs — setting direction for IAM, vulnerability management, endpoint and cloud security, and security awareness training, then holding the team and IT to SLAs.
- Be the business partner for security — advising engineering and product on secure design, supporting sales with security questionnaires and trust reviews, and making the risk trade-offs that let the business move fast safely.
The role overlaps with titles like Security Manager, Cybersecurity Manager, IT Security Manager, GRC Manager, and Security Operations Manager, and it sits on the path between senior analyst/engineer roles and Director of Security or CISO. Because postings use these labels and emphasize different mixes of governance, operations, and leadership, a strong Information Security Manager resume mirrors the exact title and the program scope named in the job it targets.
What hiring managers and ATS look for in an Information Security Manager resume
Security leadership is keyword-dense and credential-sensitive, so the applicant tracking system filters hard on frameworks, certifications, and program language. But the hiring manager — often a CISO, VP of Engineering, or CIO — is reading for something the parser can't grade: can you own a program, lead people, pass an audit, and brief the board without melting down? The resumes that earn the interview do four things:
- Lead with program outcomes, not tasks. "Built and matured the security program from ad-hoc to a NIST CSF Tier 3 posture and passed first SOC 2 Type II with zero exceptions" beats "Responsible for information security." The program-level result is the headline; the framework is the proof.
- Quantify leadership scope. Team size managed, budget owned, number of audits passed, risk reduced, MTTR improvement, vendor reviews completed, and policy coverage are the numbers security leaders are measured on. Scope signals altitude — managing 8 people and a $2M budget reads very differently from "worked on security."
- Name the frameworks and the audit outcomes. NIST CSF, ISO 27001, SOC 2, PCI DSS, HIPAA, and CIS Controls tell the reader you govern with structure — and stating that you passed (or led the company to) a specific certification is the single most credible line on the page.
- Surface the keywords and the certifications in the top third. A leadership summary, a certifications line (CISSP, CISM), and a skills block must carry the framework, audit, and GRC language from the posting, because that is exactly what recruiters paste into search. Clearance, if you hold one, goes near the top.
A full Information Security Manager resume example
Here is a complete, realistic sample for a mid-to-senior Information Security Manager on the path toward Director of Security. Adapt the names, companies, and numbers to your own record — and keep every metric honest.
Information Security Manager with 9+ years in security and 4+ years leading teams, building and maturing security programs for regulated and high-growth SaaS environments. Owns the full GRC lifecycle — risk management, policy, audits, and vendor risk — and leads SecOps and incident response. Took two organizations through first-time SOC 2 Type II and ISO 27001 certification, reduced enterprise risk, and built security teams from the ground up. Operates to NIST CSF and ISO 27001; CISSP and CISM certified.
- Program & Strategy
- Security program management, roadmap, security maturity (NIST CSF, CIS Controls)
- GRC
- Risk management, risk register, policy development, security awareness, audit management
- Compliance
- SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, NIST 800-53, GDPR readiness
- Leadership
- Team building & mentoring, budget ownership, board/executive reporting, OKRs
- Operations
- Incident response (incident commander), SecOps/SOC oversight, vulnerability management
- Identity & Cloud
- IAM, SSO/MFA, AWS & Azure security, cloud posture management, Zero Trust
- Vendor & 3rd-party
- Vendor risk management, security questionnaires, contract/DPA review
- Built and matured the company's security program from ad-hoc to a NIST CSF Tier 3 posture, defining the 3-year roadmap and reporting quarterly to the board's audit committee.
- Led the company's first SOC 2 Type II and ISO 27001 certifications to completion with zero major nonconformities, unblocking $14M in enterprise pipeline gated on security review.
- Hired and now lead a 7-person security team (SecOps, GRC, and security engineering) and own a $2.4M annual security budget, cutting tooling spend 18% through vendor consolidation.
- Stood up the enterprise risk register and quarterly risk-assessment cadence, driving residual high risks down 41% in 18 months and securing executive sign-off on the risk-acceptance process.
- Served as incident commander on 5 major incidents, rebuilt the IR plan and ran quarterly tabletops, cutting mean time to respond (MTTR) from 6 hours to under 90 minutes.
- Launched the vendor-risk program (350+ vendors assessed) and embedded security requirements into procurement, reducing average sales-security-questionnaire turnaround from 9 days to 2.
- Promoted to lead a 3-person team after owning the company's PCI DSS program, passing two consecutive annual assessments with no compensating-control findings.
- Designed and rolled out the IAM and least-privilege program (SSO, MFA, quarterly access reviews) across 1,100 employees, closing all prior identity-related audit findings.
- Built the vulnerability-management SLA framework and drove remediation of 2,000+ critical/high findings to a 95% 30-day SLA across engineering and IT.
- Authored 20+ security policies and standards mapped to NIST 800-53, establishing the governance baseline the program still runs on.
- Ran SOC monitoring and incident response, then moved into GRC — leading HIPAA risk assessments and building the evidence library that passed the org's first external security audit.
- Tuned detection and reporting that cut false positives 50% and gave leadership its first monthly security-posture dashboard.
CISSP (ISC2) · CISM (ISACA) · CRISC (ISACA) · AWS Certified Security – Specialty · (in progress) CCSP
B.S. in Management Information Systems — The University of Texas at Austin
Key hard skills, soft skills, and ATS keywords
Use these as a checklist against the posting you are targeting. Include the ones you genuinely have, in the exact phrasing the job description uses, and prove the important ones in a bullet.
Hard skills & domains (the ATS keyword bank)
Soft skills that matter for security management
A manager is hired as much for judgment and leadership as for technical depth, so the human skills carry decisive weight. The ones hiring managers probe in interviews — and that belong, demonstrated, in your bullets — are executive communication and influence (translating risk into business language the board will fund), leadership and people management (hiring, mentoring, retaining a team), risk-based decision-making (knowing which risks to accept, mitigate, or escalate), cross-functional collaboration with engineering, legal, and procurement, and calm command during a live incident. Show them through outcomes ("briefed the board," "built a 7-person team," "drove sign-off on risk acceptance") rather than asserting them as adjectives.
Certifications worth listing
| Certification | Why it helps |
|---|---|
| CISM (ISACA) | The management-focused credential; signals security governance, risk, and program-leadership maturity. Frequently named in manager postings. |
| CISSP (ISC2) | The broad senior-security standard; an extremely common gate for security-leadership roles and often required. |
| CRISC / CISA (ISACA) | Validates enterprise risk management (CRISC) and audit (CISA) depth — directly aligned to the GRC half of the role. |
| CCSP / AWS or Azure Security | Proves cloud-security leadership, increasingly expected as programs move to the cloud. |
What Information Security Managers earn
In the United States, Information Security Managers typically earn a base salary between roughly $130,000 and $200,000, with a median commonly in the $150,000–$170,000 range. The U.S. Bureau of Labor Statistics places security managers within Computer and Information Systems Managers, which reports a median near $170,000 per year. Newer managers and those at smaller companies start closer to $120,000–$140,000; senior managers and those leading larger teams in high-cost metros or in finance, technology, and healthcare push past $200,000 before bonus and equity, and the step up to Director of Security or CISO opens a meaningfully higher band. Security management is among the fastest-growing leadership tracks in tech, with BLS projecting employment for the broader category to grow much faster than average. Pay rises fastest with team and budget scope, demonstrated audit and certification ownership, regulated-industry and cloud-security depth, and stacked credentials (CISSP, CISM).
Common Information Security Manager resume mistakes
Information Security Manager resume FAQ
What should an Information Security Manager resume focus on?
The security program you owned and the risk you measurably reduced — roadmap delivered, audits and certifications passed (SOC 2, ISO 27001, PCI DSS), team and budget managed, incidents led, and findings closed — each backed by the frameworks you run. Hiring managers are buying governance, leadership, and lower organizational risk, with frameworks and metrics as the proof.
What are the most important keywords on an Information Security Manager resume?
Security program management, GRC, risk management, NIST CSF, ISO 27001, SOC 2, PCI DSS, incident response, vendor/third-party risk, IAM, vulnerability management, and security operations, plus leadership terms (team management, budget ownership, board reporting) and certifications (CISSP, CISM). Mirror the exact phrasing in the posting.
How much do Information Security Managers make?
Base salary typically runs roughly $130,000–$200,000, with a median commonly around $150,000–$170,000; the BLS median for the broader Computer and Information Systems Managers category is near $170,000. Senior managers and those in high-cost metros or regulated industries exceed $200,000 before bonus and equity.
Do I need certifications on an Information Security Manager resume?
They carry real weight and many postings require CISSP or CISM. CISM signals security-management and governance maturity; CISSP signals broad senior depth; CRISC and cloud-security credentials differentiate further. Pair them with demonstrated program ownership and audit outcomes — leadership evidence outranks any single credential.
How long should an Information Security Manager resume be?
Two pages is standard for a manager with a real leadership track record; one page is fine only under roughly eight years of experience. Keep it dense with program-level outcomes — audits passed, risk reduced, team and budget scope — and put certifications and a leadership summary near the top.
Build it free — then put a human on the search
Start your Information Security Manager resume free in Backstage, Marqee's self-serve builder. It keeps your formatting parser-clean, suggests the right frameworks, GRC language, and certifications from the job description, and tells you what's missing before you submit. When you want the search actually working — not just the document polished — a real Marqee strategist takes over: tailoring and submitting applications on your behalf, running recruiter outreach, and surfacing referrals so you get top billing with the CISOs and VPs who hire security leaders, instead of getting lost in the pile.