WPS - Educational and Psychological Assessments ยท 4 days ago
Information Security & Compliance Manager
WPS is an organization focused on educational and psychological assessments, and they are seeking a Manager for Information Security & Compliance. This role leads all security engineering and compliance operations, ensuring the confidentiality, integrity, and availability of systems and data while overseeing the compliance program and security governance.
Education
Responsibilities
Own vulnerability management, SIEM tuning and monitoring, incident response, and threat investigation
Maintain secure baseline configurations (CIS, hardening standards)
Oversee AWS security controls, including IAM governance, cloud logging, encryption standards, network security boundaries, and enforcement of cloud security guardrails
Design and approve security controls for new systems, infrastructure changes, and applications
Govern identity security, privileged access, MFA enforcement, and periodic access reviews
Provide security oversight for DevOps pipelines and cloud deployments
Own all security policies, standards, procedures, and security awareness training
Lead annual risk assessments, security reviews, and third-party/vendor risk management
Own the Disaster Recovery (DR) governance program, including planning, documentation, tabletop exercises, and driving remediation, while partnering with Infrastructure on technical DR execution
Manage data protection and data classification practices
Track and report security KPIs, risks, and initiatives to the ISO
Run regular security governance meetings and guide cross-functional alignment
Lead the Compliance Engineer and review all work for accuracy and completeness
Approve technical controls, evidence, and audit documentation
Ensure IT systems meet required technical controls across SOC 2, HIPAA, GDPR, CCPA, and other applicable regulatory or customer-driven frameworks
Act as the technical owner during internal/external audits
Define evidence required from IT and non-IT WPS teams
Manage corrective actions, POAMs, and remediation plans
Review customer security questionnaires with the Compliance Engineer
Security defines security requirements and works closely with Infrastructure to implement the necessary configurations, remediations, and technical controls
Partner with the Infrastructure team to ensure DR plans, runbooks, and technical recovery processes are implemented and tested effectively
Security reviews and approves changes that impact security posture
Advance detection engineering, automation, and threat visibility
Implement stronger security controls to support company and platform growth
Lay groundwork for future expansion of the security/compliance function
Qualification
Required
Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or equivalent experience preferred
5+ years of hands-on IT security engineering or cybersecurity engineering experience
Experience leading security or compliance functions
Strong technical experience in SIEM, AWS security, vulnerability management, identity security, incident response, and disaster recovery
Strong proficiency with AWS security architecture, IAM, cloud logging, and security guardrails
Working knowledge of SOC 2, HIPAA, GDPR, and CCPA compliance frameworks
Strong understanding of security architecture, secure configurations, and cloud security
Excellent judgment and risk evaluation skills
Ability to translate regulatory requirements into executable technical controls
Strong communication skills for cross-functional work and audit interactions
Ability to mentor and develop team members
Strong analytical and troubleshooting skills
Company
WPS - Educational and Psychological Assessments
A family business since 1948, WPS publishes psychological and educational assessments that practitioners trust.