Global IT Manager, Security & Compliance (Remote)
Global IT Manager, Security & Compliance (Remote)
ServerFarmStraight from ServerFarm’s careers page. Apply on the company site — no recruiter, no middleman.
Global IT Manager, Security & Compliance
Team: Information Technology
Location: Remote, GA
Commitment: Full-Time
Workplace Type: remote
Serverfarm is a leading developer and operator of data centers with over 750+ locations and key customer relationships in 45 countries. Were revolutionizing how data centers operate across North America, Western Europe, and Israel, serving the worlds leading technology and hyperscale companies. With Manulife Investment Managements acquisition in 2023 and our award-winning InCommand platform were positioned for explosive growth as AI adoption and cloud migration drive unprecedented demand for data center capacity. A career at Serverfarm means being at the forefront of digital infrastructure innovation, where your work directly impacts how the worlds data is managed and secured. As we target 4x growth over the next four years, youll have unprecedented opportunities to take on new challenges, develop cutting-edge skills, and grow your career across our expanding global operations. Join our team of innovators and help shape the future of sustainable data centers while building a career without boundaries.Key Accountabilities
-
Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for a portfolio of approximately thirteen operating sites.
-
Act as ITs counterpart to external certification bodies and auditors — prepare for audits, present and defend control evidence, and own remediation of IT findings through to closure.
-
Manage third-party and vendor risk management for IT: vendor security assessments, a maintained vendor register with periodic reassessment.
-
Own customer-facing security due diligence — questionnaires, audits and assessments.
-
Maintain the IT risk register and opportunities-for-improvement log, and drive items to closure rather than allowing them to age.
-
Coordinate IT participation in business continuity and disaster recovery testing, and ensure results are documented.
-
Manage vulnerability management end to end — scanning coverage, triage, remediation ownership, escalation of anything aging, and periodic reporting to leadership.
-
Work along side counterparts to oversee endpoint detection and response and the security alerting pipeline; ensure alerts reach an owner and that investigations are recorded and closed.
-
Lead security incident response — containment, investigation, root cause, customer-facing incident reporting, and post-incident hardening.
-
Manage email security, including domain authentication posture and secure email gateway configuration.
-
Run the security awareness program — monthly phishing simulation, results analysis, and targeted follow-up.
-
Contribute to identity governance across a hybrid estate spanning cloud and on-premises IdP
-
Oversee access review cadence, privileged access controls, and the joiner-mover-leaver process from an IT control standpoint, including third-party and contractor access.
Compliance and Risk
Security Operations
Identity and Access
Required Qualifications
-
Eight or more years in information security, IT compliance, or IT risk, with meaningful time spent in both compliance and technical security work.
-
Demonstrated ownership of an ISO 27001 program, including direct experience preparing for and defending findings with an external certification body.
-
Hands-on experience with at least two of: SOC 2, PCI DSS, HIPAA, NIS2, or DORA.
-
Genuine technical depth — you should be comfortable reading firewall and authentication logs, assessing a vulnerability scan, evaluating an OAuth consent request, and challenging an engineers proposed remediation on its merits.
-
Experience with vulnerability management platforms, endpoint detection and response tooling, and enterprise identity platforms.
-
Experience leading security incident response through to a customer-facing or executive-facing conclusion.
-
Ability to communicate risk credibly to both engineers and executives, and to hold vendors and internal stakeholders accountable without formal authority over them.
-
Willingness to travel to sites periodically for audit, assessment, and control validation.
Similar remote jobs
All IT Manager jobs →
Jasper
Senior Governance, Risk, and Compliance Lead

Relativity
Senior Security Engineer, Identity and Access Management


Discover More than 100,000 Hidden Remote Jobs Before Everyone Else
Unlock All Remote Jobs Today
Simple pricing. Big savings on Quarterly and Yearly.
Monthly Access
- Instant access to fresh remote jobs from 500+ companies
- New opportunities added hourly, often 3-7 days before anywhere else
- Advanced filtering by role type, stack, pay, and location
- Priority customer support
Yearly Access
- Everything in Monthly
- Save $169 (~74%) vs paying monthly
- Average job search takes ~6 months - get covered for the whole journey
- Less than the cost of one lunch per month for competitive advantage
- Equivalent to just ~$4.92/month