Granicus - Information Security Manager (CJIS)
About Granicus:
Granicus provides comprehensive cloud-based solutions for government communications, website design, meeting management, and digital services to over 5,500 federal, state, and local government agencies worldwide.
Role Overview:
Information Security Manager will oversee the CJIS compliance program and manage a complex information security framework including multiple compliance standards. The role involves managing internal and external audits, developing security policies, and leading cross-functional security initiatives across government-focused SaaS products.
Location:
Remote position.
Key Responsibilities:
- Manage CJIS program including policies, procedures, and audits
- Serve as CJIS subject matter expert for product and roadmap decisions
- Perform internal CJIS compliance audits and manage external audits
- Oversee compliance programs for TxRAMP, StateRAMP, ISO 27001, SOC 2, PCI, HIPAA, and FISMA
- Lead security program initiatives and maintain audit runbooks
- Manage third-party risk management program and vendor assessments
- Collaborate with cross-functional teams on security control implementation
- Develop customer security resources and answer libraries
- Support incident response, disaster recovery, and business continuity reviews
Qualifications:
- 7+ years in information security with 3+ years managing security teams
- 5+ years managing CJIS compliance programs and audits
- Expert knowledge of CJIS policies, procedures, and compliance requirements
- Experience with multiple compliance frameworks (FedRAMP, StateRAMP, SOC 2, ISO 27001, PCI, HIPAA)
- Experience managing third-party audits and developing audit runbooks
- Strong understanding of cloud security controls and AWS/Azure/GCP environments
- Familiarity with SIEM, firewalls, IDS/IPS, encryption, and endpoint protection
- Security certifications preferred (CISSP, CISM, CISA, Security+)
Compensation & Benefits:
$160,000 - $180,000 annually
Comprehensive health benefits, 401(k) with matching, flexible time off, and remote-first work environment.