You manage the information-systems security function for a company or major business unit — owning the program that protects systems, applications, and data — vulnerability management, identity-and-access, incident response, security-architecture, and the IS-security policy work the function generates.
IS-security management threads across vulnerability programs, identity-and-access work, incident response, and executive briefings — running vulnerability-and-patch programs, supporting IAM and access-control work, leading incident-response when events surface, sitting in IT and risk-committee meetings on security posture. Vulnerability-closure rate, incident outcomes, and audit posture anchor the operating measures.
The harder part is often the breadth of IS-security scope — endpoint, cloud, application, identity, data, third-party, and increasingly OT-security all touch the function, and managers carry working depth across the breadth while leading specialized teams. Variance across employers is real: regulated industries run IS-security under formal regulatory frameworks; tech firms run with mature security programs; smaller corporates may have IS-security managers wearing many hats.
It fits people paranoid in a constructive way, comfortable with executive presence, and steady through after-hours incident response. CISSP, CISM, and CCSP credentials anchor advancement. The trade-off is the asymmetric visibility — successful IS-security stays invisible; incidents land publicly, and managers carry the weight regardless of how disciplined the program was.
Remember “your permanent record”?
This time it works for you.
Where this role sits in the broader career landscape — and where it can take you.
Your job belongs to your employer.
Your career belongs to you.
Roles like this one sit within a broader occupational category. The numbers below reflect that full landscape — helpful for context, but your specific experience will depend on level, specialty, and where you work.
Roles with similar work and overlapping career paths
View all Business Operations roles →You manage the information-systems security function for a company or major business unit — owning the program that protects systems, applications, and data — vulnerability management, identity-and-access, incident response, security-architecture, and the IS-security policy work the function generates.
Median pay for an IS Security Manager (Information Systems Security Manager) is about $105K nationally, with the field ranging roughly from $57K to $173K depending on experience, employer, and metro (BLS).
Core skills for this role include Critical Thinking, Reading Comprehension, Active Listening, Judgment and Decision Making, and Complex Problem Solving.
Most people in this role hold a bachelor's degree.
Employment in this field is projected to grow about 1.55% through 2034, with roughly 214,270 people working in it today (BLS).
Closely related roles include Security Director, Corporate Security Director, and Judicial Office Security Director.
Don't do Truest if you aren't ready
to invest in yourself and your career.