
Information Security Manager
Aries.com · Remote, United States
About The Role
Aries is looking for an Information Security Manager to take ownership of the day-to-day operation, governance, and continued development of our information security program.
This is a hands-on leadership role for someone who can bring structure and accountability to a growing security function. You’ll manage our Information Security Analysts, work closely with our vCISO, Compliance, Engineering, IT, and executive leadership, and ensure that security policies, controls, incidents, risks, and regulatory obligations are actively managed and documented.
We’re looking for someone who is comfortable operating both strategically and tactically: building processes and reporting frameworks while also stepping in to coordinate incidents, review controls, manage remediation efforts, and keep the security program moving forward.
This role has significant room for growth and is expected to have a potential path into a Director of Information Security position as Aries and the security organization continue to scale.
WHAT YOU’LL OWN
INFORMATION SECURITY GOVERNANCE
- Own and continuously improve Aries’ information security governance framework.
- Maintain security policies, standards, procedures, control documentation, and associated review cycles.
- Establish clear ownership and accountability for security controls across the organization.
- Maintain security risk registers, exceptions, remediation plans, and related governance processes.
- Ensure documented security practices accurately reflect how the organization operates.
SECURITY PROGRAM MANAGEMENT
- Take day-to-day ownership of the information security program.
- Manage, mentor, and prioritize the work of Aries’ Information Security Analysts.
- Oversight of recurring security operating cadences, including reviews of incidents, vulnerabilities, risks, controls, and remediation efforts.
- Coordinate security initiatives across Engineering, IT, Compliance, and other teams.
- Track security findings through remediation and ensure identified issues do not remain unresolved.
INCIDENT RESPONSE
- Own the operational incident response process.
- Coordinate investigation, escalation, containment, remediation, and post-incident activities.
- Ensure incidents are properly documented and appropriate stakeholders are kept informed.
- Lead or coordinate post-incident reviews and ensure corrective actions are completed.
- Continuously improve incident response procedures, escalation paths, and readiness.
COMPLIANCE & REGULATORY SUPPORT
- Partner closely with Compliance to support regulatory and audit requirements.
- Produce recurring security reports, metrics, risk updates, and control-status reporting for Compliance and leadership.
- Coordinate evidence gathering and control testing activities.
- Support examinations, audits, security assessments, and regulatory inquiries as required.
- Experience working in environments regulated by FINRA, the SEC, or other financial-services regulators is a strong plus.
SECURITY CONTROLS & VANTA
- Own the administration and continued development of the Aries security compliance program within Vanta.
- Maintain control mappings, evidence, integrations, tests, ownership, and remediation workflows.
- Ensure compliance tooling reflects the actual security posture of the organization rather than functioning solely as an audit checklist.
- Identify control gaps and work with relevant teams to address them.
VCISO & EXECUTIVE COORDINATION
- Serve as the primary operational counterpart to Aries’ vCISO.
- Translate security strategy and recommendations into concrete initiatives, owners, and deliverables.
- Provide the vCISO and executive leadership with clear visibility into security risks, priorities, incidents, and program maturity.
- Help develop the longer-term security roadmap as Aries continues to grow.
WHAT WE’RE LOOKING FOR
- Several years of progressive experience in information security, cybersecurity governance, security operations, GRC, or related disciplines.
- Previous experience owning or materially contributing to an organizational information security program.
- Experience leading security professionals, projects, or cross-functional security initiatives.
- Strong understanding of security governance, risk management, incident response, and control frameworks.
- Experience working with security compliance platforms such as Vanta, Drata, Secureframe, or similar tools.
- Experience supporting security audits, assessments, compliance programs, or regulatory examinations.
- Ability to develop clear policies, procedures, reports, metrics, and executive-level security communications.
- Strong organizational skills and the ability to drive remediation work across teams that you may not directly manage.
- Comfortable operating in a growing organization where processes are still being built and improved.
- Strong judgment and the ability to distinguish meaningful security risk from compliance-box-checking.
- Experience with SOC 2, NIST CSF, CIS Controls, ISO 27001, or similar frameworks.
NICE TO HAVE
- Experience within a broker-dealer, fintech, financial institution, trading firm, or similarly regulated financial-services environment.
- Familiarity with FINRA and/or SEC cybersecurity expectations.
- Experience working with a vCISO or outsourced security advisory function.
- Experience participating in or coordinating tabletop exercises and incident response simulations.
- Security certifications such as CISSP, CISM, CRISC, GIAC, or similar credentials.
Certifications are valued, but practical experience building and operating security programs is more important to us than collecting acronyms.
COMPENSATION
$100,000–$130,000 USD annually, depending on experience and qualifications.
GROWTH
This role is intended to become an important part of Aries’ leadership structure. As the company and security function grow, the successful candidate will have the opportunity to expand their scope, build out the security organization, and potentially progress into a Director of Information Security role and beyond.
ABOUT ARIES
Aries is a financial technology company building modern infrastructure and products for active investors and traders.
We operate in an environment where security, reliability, regulatory compliance, and customer trust are fundamental to the business. As Aries continues to scale, we are investing in a security program that is practical, accountable, and deeply integrated into how the company operates.
We’re looking for someone who wants to help build that program — not simply inherit a checklist.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
