Information Security Manager
Sotheby's · United States
About this role
**ABOUT SOTHEBY’S** Established in 1744, Sotheby’s promotes access and ownership of exceptional art and luxury objects through auctions, private sales, and retail. Our deep expertise across 70 selling categories is supported by a leading technology platform and a global network of specialists spanning 40 countries. **THE ROLE** As an **Information Security Manager**, you will execute major components of Sotheby’s information security strategy and help define it. Reporting directly to the **CISO**, you’ll drive key initiatives while partnering with managers across the globe to balance business objectives with risk management. You’ll be a “utility player,” moving between areas as needed—such as performing risk assessments and security reviews, procuring infosec tools, managing projects, drafting policies and processes, running risk management meetings, designing controls, overseeing auditors, and leading incident response. **RESPONSIBILITIES** - Work with IT and business unit managers to drive security initiatives to completion - Lead business continuity and disaster recovery planning and preparation projects - Lead internal and external security audits; act as the primary point of contact for auditors - Draft, update, and enforce information security policies, processes, and standards - Conduct third-party vendor risk assessments and internal security risk assessments - Maintain risk registers, compliance dashboards, and reports for senior leadership - Audit internal systems to verify compliance with mandatory security controls - Develop policies, processes, and risk assessments aligned to frameworks such as **CIS, NIST, ISO 27001, and SOC 2** - Crosswalk and harmonize controls across multiple compliance frameworks - Document security requirements, support control implementation, and track remediation progress - Build risk registers, support assessments, and monitor remediation progress - Plan, lead, and execute control validation and testing across domains (e.g., access management, vulnerability management, incident response, data protection) - Mentor junior analysts and engineers; foster a culture of accountability - Document control issues and collaborate with stakeholders on remediation recommendations - Develop and enhance control testing methodologies, procedures, and reporting mechanisms **REQUIRED QUALIFICATIONS** - At least **five years** of hands-on experience in information security roles - Bachelor’s or Master’s in computer science, engineering, or cybersecurity - Deep understanding of information security fundamentals - Proven ability to manage complex projects from conception to completion - Ability to explain complex technical risks in simple, business-friendly language - Ability to communicate clearly, precisely, and concisely **PREFERRED QUALIFICATIONS** - At least one active credential (e.g., **CISA, CRISC, CISM, or CISSP**) - Experience performing risk assessments across diverse systems including **SaaS and mobile** - Deep knowledge of frameworks and standards such as **CIS, ISO 27001, and NIST** - Experience leading incident response through a cyberattack or data breach **Candidate Privacy Notice** - US: https://www.sothebys.com/en/docs/pdf/candidate-privacy-notice.pdf - UK / Hong Kong / France / Switzerland: https://www.sothebys.com/en/docs/pdf/final-v1-sothebys-recruitment-privacy-notice-uk-hk-france-and-switzerland-31-january-2022.pdf?locale=en
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.