Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Infosec Manager image - Rise Careers
Job details

Infosec Manager

About the Company:

Ouro is a global, vertically-integrated financial services and technology company dedicated to the delivery of innovative financial empowerment solutions to consumers worldwide. Ouro’s financial products and services span prepaid, debit, cross-border payments, and loyalty solutions for consumers and enterprise partners.

Ouro's flagship product Netspend provides prepaid and debit account solutions that connect customers with secure, convenient access to global payment networks so they can manage their money and make everyday purchases. With a nationwide U.S. retail network, customers can purchase and reload Netspend products at 130,000 reload points and over 100,000 distributing locations.

Since Ouro's founding in 1999 by industry pioneers Roy and Bertrand Sosa, Ouro products have processed billions of dollars in transaction volume and served millions of customers worldwide. The company is headquartered in Austin, Texas with regional offices around the world. Learn more at www.ouro.com.

About the Role

The Information Security Manager is responsible for leading the development, implementation, and oversight of the organization’s information security strategy, with a strong focus on application security. This role ensures the protection of critical business systems, data, and infrastructure through proactive risk management, secure software development practices, and cross-functional collaboration. The ideal candidate brings 10+ years of progressive experience in cybersecurity and application security, with strong leadership and hands-on technical capabilities.

Key Responsibilities:

1. Security Strategy, Governance & Compliance

  • Develop, implement, and maintain enterprise-wide security policies and procedures, covering access control, incident response, data privacy, and user awareness.

  • Conduct regular risk assessments and security audits to identify vulnerabilities and compliance gaps.

  • Ensure compliance with industry standards and regulations such as PCI DSS, GDPR, HIPAA, ISO 27001, NIST, etc.

  • Manage third-party/vendor security risk assessments and enforce relevant security controls.

  • Lead internal and external security audits, and oversee remediation efforts.

2. Application Security (AppSec)

  • Define and execute a robust Application Security strategy, ensuring security is embedded throughout the SDLC.

  • Collaborate with development teams to integrate static (SAST), dynamic (DAST), and software composition analysis (SCA) tools into CI/CD pipelines (e.g., GitLab, Jenkins).

  • Conduct code reviews, threat modeling, and secure architecture reviews for critical applications.

  • Provide actionable remediation guidance for vulnerabilities such as SQL Injection, XSS, CSRF, RCE, etc.

  • Promote and enforce secure coding practices, leveraging frameworks such as OWASP ASVS and Top 10.

  • Stay updated on emerging application threats and security trends, incorporating them into internal processes and controls.

3. Security Operations & Incident Management

  • Oversee day-to-day security operations including monitoring, detection, investigation, and incident response.

  • Lead response efforts for security incidents—containment, analysis, resolution, and root cause documentation.

  • Manage and maintain key security tools including SIEM, EDR, IDS/IPS, firewalls, and cloud-native security tools.

  • Coordinate vulnerability management activities using tools like Qualys, Tenable, OpenVAS, and ensure timely remediation.

4. DevSecOps Integration

  • Drive security automation by integrating tools into CI/CD pipelines, ensuring early detection of vulnerabilities.

  • Promote a DevSecOps culture by working closely with engineering and DevOps teams to embed security across development and deployment lifecycles.

  • Evaluate and implement security tooling for containerized and cloud-native applications (e.g., Docker, Kubernetes, AWS, Azure).

5. Leadership, Training & Stakeholder Engagement

  • Lead and mentor a team of security analysts and engineers, providing strategic and tactical guidance.

  • Define security KPIs, report on program effectiveness, and present risks to executive leadership.

  • Conduct internal training, awareness programs, and regular knowledge sharing to foster a security-first mindset.

  • Manage the security budget and ensure resource allocation aligns with organizational risk priorities.

  • Engage with external stakeholders such as auditors, regulators, vendors, and law enforcement when required.

Key Skills & Qualifications:

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.

  • 10+ years of experience in cybersecurity, including 5+ years in application security and security architecture roles.

  • Strong experience in secure software development, DevSecOps, and vulnerability management.

  • Deep understanding of web application and API security, threat modeling, and risk assessment.

  • Hands-on expertise with security tools (e.g., SAST, DAST, SCA, SIEM, IDS/IPS, EDR).

  • Proficient in scripting (e.g., Python, Bash) for automation and tool integration.

  • Familiar with cloud and container security best practices for AWS, Azure, Docker, Kubernetes.

  • Excellent interpersonal and communication skills, with the ability to influence both technical and non-technical stakeholders.

  • Preferred certifications: CISSP, CISM, OSCP, CEH, GWAPT, or similar.

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Infosec Manager, Ouro

At Ouro, we're on a mission to redefine financial services and empower consumers around the globe with innovative solutions. As an Infosec Manager based in Noida, you will play a critical role in safeguarding our digital environment. You'll be at the forefront of our information security strategy, focused on crafting and implementing robust policies designed to protect our sensitive data and infrastructure. This isn't just a job; it's a chance to lead the charge in advancing application security practices. With your extensive experience—10+ years in cybersecurity and application security—you'll collaborate across departments, ensuring security is integrated into our software development lifecycle. Your leadership will also involve mentoring a talented team of security analysts, conducting risk assessments, and integrating cutting-edge security tools into our CI/CD processes. Every day brings new challenges as you drive our commitment to secure coding practices and compliance with industry standards. If you're ready to make a tangible impact in a supportive and dynamic work environment, this is the opportunity for you. Join us at Ouro, where your expertise will help empower consumers and enterprises worldwide.

Frequently Asked Questions (FAQs) for Infosec Manager Role at Ouro
What are the key responsibilities of the Infosec Manager at Ouro?

The Infosec Manager at Ouro is tasked with developing and overseeing the information security strategy, focusing on application security. Key responsibilities include implementing security policies, conducting risk assessments, ensuring compliance with industry standards like PCI DSS and GDPR, and managing security operations. The role also involves leading a team of security analysts, integrating security within the software development lifecycle, and driving security automation.

Join Rise to see the full answer
What qualifications are needed to be an Infosec Manager at Ouro?

To qualify for the Infosec Manager position at Ouro, candidates should hold a Bachelor's degree in Computer Science, Cybersecurity, or a related field, along with 10+ years of experience in cybersecurity. A minimum of 5 years should be in application security and security architecture roles. Certifications such as CISSP, CISM, or OSCP are preferred, alongside hands-on expertise with security tools like SIEM, DAST, and SAST.

Join Rise to see the full answer
How does Ouro approach application security in the Infosec Manager role?

At Ouro, application security is a cornerstone of our Infosec strategy. The Infosec Manager will define and execute a security strategy that ensures comprehensive protection throughout the software development lifecycle. This includes collaborating with development teams to incorporate security tools into CI/CD pipelines, conducting threat modeling and code reviews, and enforcing secure coding practices aligned with frameworks like OWASP.

Join Rise to see the full answer
What tools and technologies are utilized by the Infosec Manager at Ouro?

The Infosec Manager at Ouro will have access to an array of security tools essential for maintaining robust security postures. These include SIEM, EDR, IDS/IPS, and tools for vulnerability management like Qualys and Tenable. Additionally, proficiency in scripting languages such as Python or Bash is crucial for automation and tool integration, especially in a DevSecOps environment.

Join Rise to see the full answer
What is the work culture like for the Infosec Manager at Ouro?

The work culture at Ouro is dynamic and collaborative. As an Infosec Manager, you will work alongside various departments, fostering a security-first mindset throughout the organization. Leadership is not just about management; it also involves mentoring and engaging with your team and stakeholders to drive our mission of bringing innovative financial solutions to life securely.

Join Rise to see the full answer
Common Interview Questions for Infosec Manager
What experience do you have in developing security policies and procedures for an organization?

When answering this question, it's beneficial to describe specific instances where you developed, implemented, or maintained security policies. Highlight your approach to aligning these policies with compliance standards and how you involved various stakeholders in the process to ensure buy-in and effectiveness.

Join Rise to see the full answer
How do you conduct risk assessments and manage vulnerabilities?

Upon discussing your experience with risk assessments, illustrate your methodology for identifying vulnerabilities, prioritizing risks, and creating remediation plans. Provide an example of how you've contributed to risk mitigation in a past role, and emphasize the tools you used for vulnerability management.

Join Rise to see the full answer
Can you describe your experience with application security and secure coding practices?

This is a chance to showcase your familiarity with secure coding frameworks like OWASP. Talk about the specific techniques you've employed to identify and mitigate security weaknesses in applications, as well as your experience integrating security measures into the software development lifecycle.

Join Rise to see the full answer
What steps do you take when responding to a security incident?

Outline your structured approach to incident response, emphasizing the importance of containment, analysis, and resolution. Provide an example of a past incident and discuss how your response led to improvements in security posture following the incident.

Join Rise to see the full answer
How do you stay updated on emerging security threats and trends?

Highlight your commitment to continuous learning through methods such as attending industry conferences, subscribing to cybersecurity journals, and participating in relevant training. Discuss how you apply this knowledge to enhance security practices within an organization.

Join Rise to see the full answer
What is your experience with third-party/vendor security assessments?

When discussing your experience with third-party security assessments, mention how you've evaluated vendors’ compliance with security standards and facilitated risk assessments. Provide examples of how these assessments have influenced vendor selection or security requirements.

Join Rise to see the full answer
Can you provide an example of how you've integrated security in a DevSecOps environment?

Detail your experience in embedding security practices throughout the development and deployment process. Mention specific tools and automation strategies you've implemented to ensure security is a continuous consideration rather than an afterthought.

Join Rise to see the full answer
How do you manage and mentor a team of security professionals?

Discuss your leadership style and how you've fostered growth and learning among security team members. Provide examples of mentoring experiences, training sessions, or knowledge-sharing initiatives that you've led to strengthen your team's overall skill set.

Join Rise to see the full answer
What security metrics do you track to measure the effectiveness of your security programs?

Discuss the key performance indicators (KPIs) you have defined for security initiatives, emphasizing their relevance to organizational goals. Describe how you use these metrics to report on program effectiveness and influence security strategy.

Join Rise to see the full answer
Why do you believe information security is crucial for a financial services company like Ouro?

This question allows you to reflect on the vital role security plays in the financial services industry. Highlight the importance of protecting sensitive customer information and the repercussions of data breaches, while also mentioning how security fosters trust and innovation in financial services.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 2 days ago

Join i360technologies as an Azure Synapse Architect/Manager, where you will lead reporting projects and contribute to technology implementation.

Photo of the Rise User
Posted 13 days ago

Become a vital contributor at Boeing as an Entry Level Programmer Analyst, focusing on innovation in business operations.

Photo of the Rise User

Join GDIT as a HITS-U III Information Systems Security Officer Lead to manage the cybersecurity of the NAVY DoD Supercomputing Resource Center.

Photo of the Rise User
Posted 6 days ago

Guidehouse is looking for a Lead IT Security Engineer to enhance security operations and incident management processes in Atlanta, GA.

Photo of the Rise User
Posted 12 days ago

Join EOS IT Solutions as a Data Center Technician and be a part of a team delivering top-notch IT support services.

Photo of the Rise User
Posted 11 days ago
Dental Insurance
Paid Holidays

Mattermost is looking for a skilled Senior Security Engineer to safeguard our platforms and infrastructure in a remote-first environment.

Photo of the Rise User
Posted 5 days ago

Join Capgemini as a Semi Senior Application Support Analyst and contribute to advancing applications for one of the largest insurance carriers in the U.S.

Netspend & Rêv come together to be the most innovative & accessible company in financial services, focused on helping consumers around the world manage and get more value for their money.

36 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 15, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cincinnati just viewed M365 Technical Advisor at Upwork
Photo of the Rise User
Someone from OH, Cincinnati just viewed Sr. Client Care Support at Visa
Photo of the Rise User
Someone from OH, Cincinnati just viewed Level 1 Support Technician at Pico
Photo of the Rise User
83 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
10 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Steubenville just viewed Digital Marketing Content Intern at Sanction Scanner
Photo of the Rise User
Someone from OH, Cleveland just viewed Data Labeling Associate - 6 Month Contract at Citylitics
Photo of the Rise User
Someone from OH, Dublin just viewed Trainee Database Engineer - IN ( Oracle ) at Rackspace
Photo of the Rise User
13 people applied to ITSM Specialist at Datacom
C
Someone from OH, Lorain just viewed RN Ambulatory - Dermatology at CCF
Photo of the Rise User
Someone from OH, New Albany just viewed Jr Data Scientist (Hybrid) at NielsenIQ
Photo of the Rise User
7 people applied to Cybersecurity Intern at Terumo
Photo of the Rise User
Someone from OH, Lewis Center just viewed Banking Sector | PL/SQL Developer (Hybrid) at Devoteam
Photo of the Rise User
Someone from OH, Loveland just viewed Director, Change Management at Visa
Photo of the Rise User
14 people applied to IT Intern - Seasonal at Carowinds
Photo of the Rise User
Someone from OH, Columbus just viewed Manager, People Partner (Remote, US) at Renew Home
Photo of the Rise User
Someone from OH, Pleasant Hill just viewed Manager, Strategic Partnerships at Lindenwood University
Photo of the Rise User
Someone from OH, Columbus just viewed Associate Director, US HCP Marketing at Sobi
C
Someone from OH, Cincinnati just viewed Injection Molding Machine Operator at Clarios
Photo of the Rise User
Someone from OH, Columbus just viewed Senior XM Advisor - Customer Experience at Qualtrics
Photo of the Rise User
Someone from OH, Columbus just viewed Dynamics 365 Senior Functional Consultant at ARO
Photo of the Rise User
Someone from OH, Canton just viewed Consultant- Natural Resources at Esri
Photo of the Rise User
Someone from OH, Strongsville just viewed Digital Operations Specialist at Riverside Insights
Photo of the Rise User
Someone from OH, Delaware just viewed Casting: 'Séance At The Museum' at Backstage