Information Security & Compliance Manager
Pittsburgh, Pennsylvania, United States
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Orbital Engineering
Information Security & Compliance Manager
Working with our business partners to create, improve and sustain industry and infrastructure. Orbital Engineering Inc. (Orbital) has been driven by this core purpose for more than 50 years - energizing Orbital team members and helping our clients solve challenging and complex problems with innovative engineering, inspection, and construction solutions. Orbital team members are guided by the fundamental beliefs of building trusted relationships, personal accountability, innovation, and excellence in everything we do. Orbital is looking for others to join our team to continue activating our purpose and embrace our values.
Orbital Engineering is seeking a hands-on Information Security & Compliance Manager to lead the development and execution of our cybersecurity and compliance program. This role will serve as the single point of accountability for security compliance and risk mitigation across the enterprise, with a primary focus on achieving and maintaining SOC 2 Type I and Type II certification. This is a fully remote position and candidates must live in the United States.
As Orbital expands its proprietary software offerings and scales operations across high-risk industries, this role is both strategically and operationally critical. The ideal candidate is a proactive, mid-senior level leader capable of balancing day-to-day security operations with long-term compliance strategy.
Essential Duties and Responsibilities
Position duties include, but are not limited to, the following:
- Lead SOC 2 Compliance Program:
Manage and execute the SOC 2 Type I and II certification process, including gap analysis, control implementation, policy development, evidence collection, and coordination with external auditors. - Security Governance and Risk Management:
Develop, maintain, and enforce cybersecurity policies, procedures, asset inventories, access controls, and risk registers. Monitor and manage company-wide adherence to regulatory and industry standards. - Security Operations Oversight:
Own the execution of vulnerability management, patch tracking, access reviews, incident response coordination, and employee security training. - Software Security Compliance:
Partner with software development and product teams to implement secure development lifecycle (SDLC) practices and ensure compliance across all Orbital-developed platforms. - Third-Party Security Management:
Respond to client and vendor security reviews, including questionnaires, due diligence packages, and third-party audit coordination. - Cross-Departmental Collaboration:
Work with IT, software, legal, HR, and business operations teams to integrate security and compliance into daily practices and ongoing projects.
Qualifications
Required:
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or related field; equivalent experience considered.
- 5+ years of hands-on information security experience, with at least 2 years in a lead or management capacity.
- Demonstrated experience driving SOC 2 Type II certification (or similar frameworks such as ISO 27001, NIST).
- Strong understanding of cybersecurity best practices, threat modeling, risk assessments, and secure development practices.
- Experience responding to client/vendor security assessments and managing third-party risk.
- Familiarity with cloud environments, SaaS platforms, and security tools (SIEM, EDR, vulnerability scanners, etc.).
- Excellent communication, documentation, and cross-functional leadership skills.
- Relevant certifications such as CISSP, CISM, or CCSP.
Preferred:
- Experience supporting secure software development environments or product security programs.
- Prior experience in engineering, industrial, or technology services industries.
Orbital has provided worldwide professional engineering and consulting services since 1969. Our commitment to quality, responsiveness, and attention to detail has earned us the reputation as a leading provider of engineering and design services.
A commitment to excellence and hard work will be rewarded with a competitive salary, career advancement opportunities, and an excellent benefits package including medical, dental, vision, prescription drug, 401(k), and supplemental insurance.
Orbital is an Equal Opportunity Employer, EEO/AA/M-F-V-D. Orbital seeks diversity among its employees. Reasonable accommodations may be made to enable individuals to perform the essential job functions.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CCSP CISM CISSP Cloud Compliance Computer Science EDR Governance Incident response Industrial ISO 27001 NIST Product security Risk assessment Risk management SaaS SDLC Security assessment SIEM SOC SOC 2 Strategy Vulnerability management
Perks/benefits: Career development Competitive pay Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.