Information Security Manager | Corporate Technology

Red VenturesCharlotte, NC
Hybrid

About The Position

Red Ventures is hiring an Information Security Manager to lead technical risk reduction across our organization. This is a player-coach role where you will own the program and stay close to the work. This leader will drive cybersecurity risk management across vulnerability management, architecture review, and cloud security standards across multiple lines of business, while also ensuring compliance obligations are met with rigor. This role includes direct people management responsibility, with a team that grows in scope over time.

Requirements

  • Proven track record identifying, prioritizing, and driving remediation of technical risk across cloud and code environments, not just tracking it in a spreadsheet.
  • Understand secure design principles, can read and evaluate cloud configurations and IAM policies, and can lead engineers through design reviews and risk mitigation work.
  • Hands-on experience with AWS at scale (GCP a plus); has actually assessed risk in these environments, not just read about them.
  • Track record of eliminating manual security or GRC work through tooling, scripting, or AI-assisted workflows.
  • Translates technical risk into business impact for non-technical leaders across diverse business units.
  • Actively grows the team toward greater scope and ownership.
  • Understands the incident lifecycle and detection practices well enough to partner credibly with the engineers who own them day to day; this role does not carry primary IR ownership.
  • Working knowledge of PCI, SOC 2, ISO 27001, or NYDFS and how each maps to technical controls, gained through partnership with a compliance program, not necessarily as its sole owner.
  • 7+ years of experience in security engineering, cybersecurity, or technology risk, with demonstrated ownership of a vulnerability management or technical risk-reduction program, not just contribution to one.
  • Hands-on cloud security experience in AWS at scale.
  • Experience leading technical teams, including architecture or design reviews with engineering teams.
  • Working knowledge of risk and control frameworks (NIST, ISO 27001).
  • Working familiarity with incident response and detection engineering.
  • Strong stakeholder influence skills, with the ability to lead without authority.

Nice To Haves

  • AWS Security Specialty certification, or equivalent hands-on cloud security credential.
  • CISSP, GCFA, GIAC, CISA, or CRISC a plus.
  • Multi-business-unit or holding-company experience, with familiarity operating in federated environments where risk priorities and technology stacks vary by business unit.
  • Experience in regulated environments (SOC 2, PCI, NYDFS), gained through partnership with a compliance function rather than sole ownership.
  • Scripting or light automation skills (Python, PowerShell, or similar) to prototype automation before handing off to engineering.

Responsibilities

  • Lead vulnerability management and risk reduction across cloud and code environments, partnering directly with engineering teams to prioritize and close the highest-impact findings.
  • Own architecture review for new systems and major changes: read cloud configurations and IAM policies, identify risk before it ships, and guide engineers through remediation, not just flag issues and hand them off.
  • Set and enforce security architecture practices across our AWS environment, evaluating design decisions and identifying where technical controls fall short of what they claim to do.
  • Translate technical risk into terms BU leaders, Engineering, Finance, and Legal will act on, building trusted relationships across the portfolio rather than operating as a gate.
  • Maintain working familiarity with incident response and detection engineering practices, partnering closely with the engineers who own day-to-day detection and response.
  • Leverage automation and AI tooling to reduce manual security and compliance workflows, targeting meaningful burden reduction within the first year.
  • Oversee compliance programs across PCI, SOC 2, ISO 27001, and NYDFS; own the policy exception program and oversee vendor/third-party risk management.

Benefits

  • Health Insurance Coverage (medical, dental, and vision)
  • Life Insurance
  • Short and Long-Term Disability Insurance
  • Flexible Spending Accounts
  • Holiday Pay
  • 401(k) with match
  • Employee Assistance Program
  • Paid Parental Bonding Benefit Program
  • Flexible Paid Time Off (PTO): 20 days of PTO for a full calendar year annually, with an increase to 25 days after five years of service.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service