Information Security Manager | Corporate Technology

Red Ventures · Charlotte, NC · Engineering

Posted 2026-09-01

Apply for this role →

This role requires a hybrid schedule and will be based in our South Charlotte, NC Headquarters (Tuesday through Thursday) and work fully remotely on Mondays and Fridays each week.

Curious how Shared Services fits into Red Ventures? Click here.

Red Ventures is hiring an Information Security Manager to lead technical risk reduction across our organization; this is a player-coach role, you will own the program and stay close to the work. This leader will drive cybersecurity risk management across vulnerability management, architecture review, and cloud security standards across multiple lines of business, while also ensuring compliance obligations are met with rigor. This role includes direct people management responsibility, with a team that grows in scope over time.

What You’ll Do:

Lead vulnerability management and risk reduction across cloud and code environments, partnering directly with engineering teams to prioritize and close the highest-impact findings.

Own architecture review for new systems and major changes: read cloud configurations and IAM policies, identify risk before it ships, and guide engineers through remediation, not just flag issues and hand them off.

Set and enforce security architecture practices across our AWS environment, evaluating design decisions and identifying where technical controls fall short of what they claim to do.

Translate technical risk into terms BU leaders, Engineering, Finance, and Legal will act on, building trusted relationships across the portfolio rather than operating as a gate.

Maintain working familiarity with incident response and detection engineering practices, partnering closely with the engineers who own day-to-day detection and response.

Leverage automation and AI tooling to reduce manual security and compliance workflows, targeting meaningful burden reduction within the first year.

Oversee compliance programs across PCI, SOC 2, ISO 27001, and NYDFS; own the policy exception program and oversee vendor/third-party risk management.

What We’re Looking For:

Vulnerability management and risk reduction: a proven track record identifying, prioritizing, and driving remediation of technical risk across cloud and code environments, not just tracking it in a spreadsheet.

Security architecture fluency: understands secure design principles, can read and evaluate cloud configurations and IAM policies, and can lead engineers through design reviews and risk mitigation work.

Cloud fluency: hands-on experience with AWS at scale (GCP a plus); has actually assessed risk in these environments, not just read about them.

Automation-first mindset: track record of eliminating manual security or GRC work through tooling, scripting, or AI-assisted workflows.

Multi-stakeholder risk communication: translates technical risk into business impact for non-technical leaders across diverse business units.

People leader who develops talent: actively grows the team toward greater scope and ownership.

Working familiarity with incident response and detection engineering: understands the incident lifecycle and detection practices well enough to partner credibly with the engineers who own them day to day; this role does not carry primary IR ownership.

Compliance program exposure: working knowledge of PCI, SOC 2, ISO 27001, or NYDFS and how each maps to technical controls, gained through partnership with a compliance program, not necessarily as its sole owner.

Minimum Qualifications:

7+ years of experience in security engineering, cybersecurity, or technology risk, with demonstrated ownership of a vulnerability management or technical risk-reduction program, not just contribution to one.

Hands-on cloud security experience in AWS at scale.

Experience leading technical teams, including architecture or design reviews with engineering teams.

Working knowledge of risk and control frameworks (NIST, ISO 27001).

Working familiarity with incident response and detection engineering.

Strong stakeholder influence skills, with the ability to lead without authority.

Preferred Qualifications:

AWS Security Specialty certification, or equivalent hands-on cloud security credential. CISSP, GCFA, GIAC, CISA, or CRISC a plus.

Multi-business-unit or holding-company experience, with familiarity operating in federated environments where risk priorities and technology stacks vary by business unit.

Experience in regulated environments (SOC 2, PCI, NYDFS), gained through partnership with a compliance function rather than sole ownership.

Scripting or light automation skills (Python, PowerShell, or similar) to prototype automation before handing off to engineering.

Compensation:

Total Cash Compensation Range: $150,000 - $230,000 per year

Actual compensation varies based on location, experience, and qualifications.

Additionally, the following benefits are provided by Red Ventures, subject to eligibility requirements.

Health Insurance Coverage (medical, dental, and vision)

Life Insurance

Short and Long-Term Disability Insurance

Flexible Spending Accounts

Holiday Pay

401(k) with match

Employee Assistance Program

Paid Parental Bonding Benefit Program

Flexible Paid Time Off (PTO): We believe time to rest and recharge is essential.  That’s why we offer a generous and flexible PTO policy.  Full-time employees accrue 20 days of PTO for a full calendar year annually, with an increase to 25 days after five years of service.

Who We Are:

Red Ventures is a global portfolio of high-growth companies — spanning several U.S. businesses, a joint venture in the health services industry, and strategic investments in Europe. Their businesses include The Points Guy, Lonely Planet, Bankrate, the Allconnect Platform, RV Home Client Growth, RV Growth & Transformation, Sage Home Loans Corporation, and more. Across the portfolio, Red Ventures businesses deliver seamless digital experiences for consumers, help Fortune 100 clients solve large-scale digital growth challenges, and create world-class experiences and opportunities for employees. Learn more at redventures.com and follow @RedVentures on LinkedIn and Instagram.

At Red Ventures, we believe diverse, inclusive teams are better. To help you better understand our core values and beliefs, we encourage you to watch this brief YouTube video: Our Belief Statements. This will give you insight into the principles that guide our work and our commitment to fostering an inclusive environment.

Red Ventures is an equal opportunity employer that does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or any other basis protected by law. Employment at Red Ventures is based solely on a person's merit and qualifications.

We are committed to providing equal employment opportunities to qualified individuals with disabilities. This includes providing reasonable accommodation where appropriate. Should you require a reasonable accommodation to apply or participate in the job application or interview process, please contact accommodation@redventures.com.

If you are based in California, we encourage you to read this important information for California residents linked here.

#LI-LM2 #LI-HYBRID

At Red Ventures, we believe in real human connection. That’s why we do not hire someone through text, social media, or email only. As part of the hiring process, you should expect live conversations with RV teammates before any offer is made. Also, keep an eye on the sender: we only use official @redventures.com email addresses at the portfolio level or business specific email addresses (e.g., @thepointsguy.com), not ones like “redventurescareer.com.” We will never ask candidates to send money, buy equipment, or share financial account info during your journey with us. You can always find our open roles on redventures.com— if you receive a message that seems suspicious, please use redventures.com to verify the opportunity.

For more, the U.S. Federal Trade Commission has published helpful articles to help individuals learn more about protecting themselves from recruiter scams. If you think you’ve been targeted, feel free to report it to your local authorities. Stay safe out there!

Apply for this role →

← Back to all jobs