| Detail | For this role |
|---|---|
| Department | Information Technology |
| Level | Manager |
| Reports to | Chief Information Security Officer |
| Direct reports | Security Analyst, SOC Analyst, Cyber Security Engineer, Firewall Engineer |
| Experience | 8 to 12 years in IT security, with 3 or more years leading a security operations or compliance team |
IT Security Manager job description template
Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.
Job title: IT Security Manager
Department: Information Technology
Reports to: Chief Information Security Officer
Location: [City], [office, branch or site]
About the role
An IT Security Manager runs a company's day-to-day security programme: vulnerability management, access reviews, security monitoring, incident response, awareness training and audit readiness. They manage security analysts and engineers, push IT and engineering teams to close findings, and keep policies aligned with ISO 27001 and client or regulator requirements. In Indian IT firms, banks, NBFCs, hospitals and BPOs the role reports to the CISO or IT Head. A good IT Security Manager keeps findings closing faster than they open and handles incidents without panic.
Key responsibilities
- Run the vulnerability management cycle: monthly scans, risk rating, assignment to IT owners and follow-up until closure.
- Oversee security monitoring by the SOC or a managed security provider, and review alert quality and missed detections.
- Lead incident response for phishing, malware, data leaks and account compromise, covering containment, evidence and reporting to management.
- Run quarterly user access reviews for critical systems with application owners, and remove access that is no longer needed.
- Keep security policies and procedures aligned with ISO 27001, and get them reviewed and approved every year.
- Plan security awareness training and phishing simulations for all staff, including every batch of new joiners.
- Prepare for internal, ISO 27001, client and regulator audits, collect evidence and track findings to closure.
- Manage security tools and vendors, such as endpoint protection, email security, SIEM and firewall support contracts.
- Report security metrics and the top risks to the CISO or IT head every month.
- Guide security analysts and engineers, plan monitoring shift cover and build their skills.
Requirements
- B.E., B.Tech, B.Sc IT or MCA
- CISM, CISSP or ISO 27001 Lead Implementer certification
- CEH or CompTIA Security+ is an advantage
- 8 to 12 years in IT security, with 3 or more years leading a security operations or compliance team
KRAs and KPIs for a IT Security Manager
Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.
| Key result area | How to measure it |
|---|---|
| Vulnerability closure | Critical vulnerabilities closed within 15 days and high ones within 30 days of detection |
| Incident response | Security incidents contained within 4 hours of detection, with a written report within 3 working days |
| Access reviews | Quarterly access review completed for every critical system, with removals done within 5 working days |
| Security awareness | Phishing simulation click rate lower each quarter, and every employee trained once a year |
| Audit results | No major non-conformity in ISO 27001 or client security audits |
| Endpoint coverage | Endpoint protection active on at least 98 percent of company devices |
Skills and tools
Tools used day to day: Splunk, QRadar or Microsoft Sentinel, Qualys, Nessus or Rapid7, CrowdStrike or Microsoft Defender, Microsoft 365 security portal, KnowBe4 or another phishing simulation tool, GRC tool or Excel risk register.
Reporting line and career path
Next roles: Chief Information Security Officer, Security Architect, IT Head
Interview questions for a IT Security Manager
- An employee's mailbox is sending phishing emails to clients. Walk me through your first hour.
- How do you get IT teams to close vulnerabilities when they say there is no downtime window?
- What evidence do you prepare for an ISO 27001 surveillance audit?
- Your phishing simulation click rate has stopped improving. What would you change?
- Which alerts should the SOC escalate to you at night, and which can wait?
- Tell me about a security incident you handled and what you changed afterwards.
Managing a IT Security Manager in ZeniaHR
Hire and manage your information technology team in one place
Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What does an IT security manager do?
An IT security manager runs a company's everyday security work. They manage vulnerability scanning and fixes, oversee monitoring and incident response, run access reviews and awareness training, maintain security policies and prepare for ISO 27001 and client audits. They lead the security analysts and engineers and report risks to the CISO or IT head.
What is the difference between an IT security manager and a CISO?
The CISO sets security strategy, owns security risk at leadership level and reports to the CEO or board. The IT security manager runs the programme day to day: scans, incidents, access reviews, training and audits. In mid-sized companies without a CISO, the IT security manager often reports to the IT head and covers both jobs.
Which certifications are best for an IT security manager?
CISM suits the management side of the role and CISSP covers broad security knowledge, and both are widely recognized in India. ISO 27001 Lead Implementer or Lead Auditor helps where audits are frequent. Hands-on certifications such as CEH or Security+ are useful earlier in the career.