For Employers

Serverfarm

Global IT Manager, Security & Compliance

Posted an hour ago
$135K - $145K per year
5-10 years experience
Apply Now

Please mention DailyRemote when applying

Not sure your resume will pass? Check your ATS score free

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

The Global IT Manager will oversee the IT evidence program for compliance frameworks like ISO 27001 and SOC 2 while managing vendor risk and customer-facing security due diligence. Additionally, the role involves leading vulnerability management, security incident response, and identity governance across a hybrid cloud and on-premises environment.

Serverfarm is a leading developer and operator of data centers with over 750+ locations and key customer relationships in 45 countries. We're revolutionizing how data centers operate across North America, Western Europe, and Israel, serving the world's leading technology and hyperscale companies. With Manulife Investment Management's acquisition in 2023 and our award-winning InCommand platform we're positioned for explosive growth as AI adoption and cloud migration drive unprecedented demand for data center capacity. A career at Serverfarm means being at the forefront of digital infrastructure innovation, where your work directly impacts how the world's data is managed and secured. As we target 4x growth over the next four years, you'll have unprecedented opportunities to take on new challenges, develop cutting-edge skills, and grow your career across our expanding global operations. Join our team of innovators and help shape the future of sustainable data centers while building a career without boundaries. \n


Key Accountabilities

Compliance and Risk

  • Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for a portfolio of approximately thirteen operating sites.

  • Act as IT's counterpart to external certification bodies and auditors — prepare for audits, present and defend control evidence, and own remediation of IT findings through to closure.

  • Manage third-party and vendor risk management for IT: vendor security assessments, a maintained vendor register with periodic reassessment.

  • Own customer-facing security due diligence — questionnaires, audits and assessments.

  • Maintain the IT risk register and opportunities-for-improvement log, and drive items to closure rather than allowing them to age.

  • Coordinate IT participation in business continuity and disaster recovery testing, and ensure results are documented.

Security Operations

  • Manage vulnerability management end to end — scanning coverage, triage, remediation ownership, escalation of anything aging, and periodic reporting to leadership.

  • Work along side counterparts to oversee endpoint detection and response and the security alerting pipeline; ensure alerts reach an owner and that investigations are recorded and closed.

  • Lead security incident response — containment, investigation, root cause, customer-facing incident reporting, and post-incident hardening.

  • Manage email security, including domain authentication posture and secure email gateway configuration.

  • Run the security awareness program — monthly phishing simulation, results analysis, and targeted follow-up.

Identity and Access

  • Contribute to identity governance across a hybrid estate spanning cloud and on-premises IdP

  • Oversee access review cadence, privileged access controls, and the joiner-mover-leaver process from an IT control standpoint, including third-party and contractor access.


Required Qualifications
  • Eight or more years in information security, IT compliance, or IT risk, with meaningful time spent in both compliance and technical security work.

  • Demonstrated ownership of an ISO 27001 program, including direct experience preparing for and defending findings with an external certification body.

  • Hands-on experience with at least two of: SOC 2, PCI DSS, HIPAA, NIS2, or DORA.

  • Genuine technical depth — you should be comfortable reading firewall and authentication logs, assessing a vulnerability scan, evaluating an OAuth consent request, and challenging an engineer's proposed remediation on its merits.

  • Experience with vulnerability management platforms, endpoint detection and response tooling, and enterprise identity platforms.

  • Experience leading security incident response through to a customer-facing or executive-facing conclusion.

  • Ability to communicate risk credibly to both engineers and executives, and to hold vendors and internal stakeholders accountable without formal authority over them.

  • Willingness to travel to sites periodically for audit, assessment, and control validation.


\n
$135,000 - $145,000 a year
\n

Serverfarm is committed to providing an equal opportunity workplace and offers paid time off, paid holidays, 401k and FULL coverage medical, dental and vision. Our compensation philosophy rewards employees for achieving the values and objectives aligned with the company’s goals and strategic initiatives.

 

The listed salary range for this position is an estimate based on the competitive job market. Final compensation will be based on your own individual skills, experience, and location.

 

The above statements are intended to describe the general nature and level of work being performed in this role. They are not intended to serve as an exhaustive list of all possible responsibilities and duties. We encourage you to apply even if your experience isn't an exact match to the job description.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Legal jobs →

Attorney

Full Time United States Legal

Sr. Dir, Product Offering, MedTech Quality, Regulatory, Safety & Compliance

Full Time United States $134K - $374K per year Legal

Director of Compliance, Employee Benefits-Insurance Advisory Solutions

Full Time United States $185K per year Legal

Sr Regulatory Affairs Specialist - Remote US

Full Time United States Legal

Clinical Regulatory Affairs Specialist II - Remote US

Full Time United States Legal

Sr. Staff Clinical Regulatory Scientist

Full Time United States $130K - $140K per year Legal
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in IT Manager

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified