
Senior Manager, Information Security & IT
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Genea is looking for a hands-on Senior Manager, Information Security & IT to lead and continuously improve our cybersecurity and corporate IT programs.
Reporting to the CTO, this role will lead Genea’s cybersecurity and IT programs across compliance, cloud and application security, incident response, identity and access management, and corporate IT.
Genea is already SOC 2 Type 2 compliant. This role will be responsible for continuously maintaining and maturing that program while helping drive additional cybersecurity and compliance initiatives, including ISO 27001 and other relevant frameworks as the business evolves.
We are looking for a cybersecurity leader who embraces AI, understands the evolving risks introduced by AI and agentic technologies, and can help Genea adopt AI securely while leveraging AI and automation to strengthen cybersecurity operations.
This is a hands-on leadership role for someone who can set direction, build scalable programs, lead the IT team and build out the cybersecurity function as needed, work closely with Engineering and other business teams, and remain involved in execution where needed.
Duties and Responsibilities
Cybersecurity Compliance & Programs
- Own and continuously mature Genea’s cybersecurity compliance program, including SOC 2 Type 2, policies, controls, audit readiness, evidence management, risk assessments, cybersecurity awareness, and readiness for ISO 27001 and other relevant frameworks.
- Establish practical governance and guardrails for secure enterprise adoption of AI, including approved AI technologies, data protection, third-party AI risk, responsible usage, and emerging AI cybersecurity requirements.
- Establish measurable cybersecurity KPIs, KRIs, risk reporting, and provide regular program updates to the executive team.
Cloud & Application Security
- Drive Genea’s cloud and application security program in close partnership with Engineering, DevOps, Platform, and Product teams, including secure-by-design practices for traditional applications as well as AI and GenAI capabilities.
- Strengthen cybersecurity across AWS and Azure, including IAM roles and permissions, least privilege, network controls, secrets management, encryption, logging, secure configurations, infrastructure hardening, and secure access to AI models, agents, APIs, and data.
- Mature secure SDLC and DevSecOps practices, including threat modeling, architecture reviews, SAST/DAST, dependency and container scanning, software supply-chain security, and controls for emerging AI risks such as prompt injection and excessive agent permissions.
- Own vulnerability management and coordinate internal and external penetration testing, prioritizing findings and driving remediation with Engineering.
Incident Response & Cybersecurity Operations
- Own cybersecurity monitoring, detection, investigation, and incident response across cloud, applications, endpoints, corporate systems, and AI-enabled services.
- Lead incident response from triage and containment through recovery, post-incident review, and corrective actions, while maintaining playbooks and tabletop exercises.
- Leverage AI and automation to improve threat detection, investigation, alert triage, and response, while monitoring emerging AI-enabled threats and attack techniques.
Identity, Access Management & Corporate IT
- Own corporate IT operations, including employee endpoints, MDM, SaaS applications, device lifecycle management, onboarding/offboarding, hardware and software provisioning, and employee IT support.
- Manage identity and access across corporate and approved AI systems, including SSO, MFA, privileged access, least privilege, IAM policies, access reviews, API credentials, and joiner/mover/leaver processes.
- Drive automation, standardization, patching, secure configuration, endpoint cybersecurity, access governance, and appropriate controls for enterprise AI tools and data usage.
Team Leadership & Development
- Lead and develop the IT team, establishing clear ownership, operational standards, and accountability across corporate technology and cybersecurity responsibilities.
- Build the cybersecurity team as the organization grows, identifying capability gaps and hiring or developing the right talent across areas such as cybersecurity engineering, operations, compliance, and risk.
Customer, Vendor & Cybersecurity Risk
- Own customer cybersecurity questionnaires, RFP responses, customer security reviews, third-party assessments, and vendor cybersecurity risk, including material AI-related vendor and platform risks.
- Represent Genea’s cybersecurity program in customer and partner discussions and clearly communicate Genea’s cybersecurity posture and controls.
- Identify and track material cybersecurity risks, drive remediation, and ensure appropriate executive visibility.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Genea

Genea
View Company ProfileGenea is a cutting-edge technology company that specializes in innovative software solutions. With a strong focus on research and development, Genea is committed to providing high-quality products that cater to the evolving needs of various industries. The company's expertise lies in creating intelligent and intuitive systems that enhance operational efficiency, productivity, and customer experience. Genea's vision is to empower businesses and individuals by providing them with the tools and expertise necessary to succeed in today's fast-paced digital landscape. With a team of highly skilled professionals and a passion for innovation, Genea is poised to make a significant impact in the tech industry. The company's commitment to excellence, customer satisfaction, and continuous improvement has earned it a reputation as a trusted and reliable partner for businesses seeking to leverage technology to achieve their goals.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
