- Location
- Bingen, WA, United States of America
- Type
- Full-time
- Department
- Security
- Seniority
- Manager
- Source
- Workday
Description
Are you passionate about protecting critical assets and enabling innovation? Join our team and be the driving force behind a secure and resilient enterprise. We’re seeking a strategic and hands-on Manager of Information Security to advance our information security posture, deliver resilience, and steer cyber risk management across the organization. You’ll lead cross-functional teams, build relationships, and champion a culture that values security while seamlessly integrating business needs.
Insitu, located in Bingen, WA, has pioneered the design, manufacturing and operation of high-performance Uncrewed Aircraft Systems (UAS) with superior payload capabilities. We are on a mission to be the world’s most trusted partner; developing and integrating world-class solutions that support customer success in the most challenging environments.
What you’ll do:
- Develop and implement an enterprise-wide information security and cyber strategy aligned with business objectives.
- Identify, assess, and mitigate security risks while ensuring compliance with regulatory and industry standards.
- Oversee information security operations, including threat intelligence, vulnerability management, and incident response.
- Maintain and enforce security frameworks, policies, and industry regulations such as “NIST Cybersecurity Framework, Risk Management Framework (RMF), CMMC".
- Guide the selection, deployment, and ongoing management of security technologies, including firewalls, intrusion detection/prevention, endpoint protection, SIEM, identity and access management, and encryption solutions.
- Translate complex regulatory requirements into technical and operational architectures; collaborate effectively with legal, IT, engineering, and executive leadership.
- Lead and coordinate vulnerability management initiatives: scanning, penetration testing, risk-based remediation, and patch management oversight.
- Oversee third-party cybersecurity risk management, including vendor assessments, SOC report analysis, cloud security evaluations, ongoing monitoring, and remediation tracking.
- Maintain organizational security resilience: support business continuity and disaster recovery plans, incident response procedures, and tabletop exercises.
- Lead information security and cyber security audits, exams, and regulatory readiness efforts.
- Supervise, mentor, and develop the Information Security and Cyber team; drive accountability, performance, and professional growth.
- Provide regular status reporting and actionable recommendations to leadership; foster a culture committed to continuous maturity and measurable improvement.
Education & Experience:
- Bachelor’s degree in information security, cybersecurity, computer science, information systems, or related discipline.
- 3–5 years of progressive information security, cybersecurity, IT governance, or risk management experience.
- Demonstrated hands-on expertise with common security technologies (e.g., Firewalls, SIEM, Intrusion Detection/Prevention Systems, VPNs, NACs, EDR tools, DNS, DLP, IAM).
- Deep knowledge of IT infrastructure (on-premises and cloud), networking, and emerging technologies.
- Strong interpersonal communication skills and the ability to maintain effective working relationships
- Strong knowledge of IT infrastructure, networking, and cloud environments.
- Experience in highly regulated industries such as defense, aerospace, or government.
- Proficiency in information security operations, vulnerability management, threat intelligence, penetration testing, and third-party cybersecurity risk management programs.
- Ability to review and advise on technical architectures (cloud, network, application, and endpoint) for security risks.
- Experience supporting business continuity, disaster recovery, ransomware preparedness, and cyber resilience initiatives.
- Exceptional written, verbal, and presentation skills; able to communicate technical concepts to all audiences.
- Knowledge of security governance best practices.
Preferred Education & Experience:
- Experience leading people or teams
- Professional certifications such as CISSP, CISM, CISA, GIAC, or equivalent.
- Familiarity with security frameworks such as CMMC and RMF
- Experience with security audits, regulatory reviews, and incident management.
In-Office Requirement Statement: (Hybrid) This position is eligible for hybrid work. It is our strong preference that this position is on-site 3 days per week to allow for maximum collaboration and connection to the team and product. However, depending on the candidate’s location, experience, and qualifications, we may have some flexibility in the frequency of on-site days.
Visit our Careers - Insitu page to learn more about our benefits, 9/80 work schedule and flexible work model.
At Insitu, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
Insitu also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability programs and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire.
Please note that the salary information show below is a general guideline only. Salaries are based upon candidate experience, qualifications and work location.
Insitu is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.