Talent.com
Senior Manager, Information Security
Senior Manager, Information SecurityOnto Innovation • Wilmington,MA (Jonspin)
Senior Manager, Information Security

Senior Manager, Information Security

Onto Innovation • Wilmington,MA (Jonspin)
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Onto Innovation is a leader in process control, combining global scale with an expanded portfolio of leading-edge technologies that include: 3D metrology spanning the chip from nanometer-scale transistors to micron-level die-interconnects; macro defect inspection of wafers and packages; metal interconnect composition; factory analytics; and lithography for advanced semiconductor packaging. Our breadth of offerings across the entire semiconductor value chain helps our customers solve their most difficult yield, device performance, quality, and reliability issues. Onto Innovation strives to optimize customers’ critical path of progress by making them smarter, faster and more efficient.

Job Summary & Responsibilities

The Senior Manager of Information Technology is responsible for IT governance, risk, compliance, and operational readiness across Onto Innovation’s global environment. Reporting to the Senior Director of IT and Security, this role leads regulatory compliance initiatives, cybersecurity posture management, incident response readiness, business continuity and disaster recovery programs, vulnerability management, vendor and partner risk management, and contributes to Onto’s multi-year IT and security strategy.

Key Responsibilities

Compliance & Governance

  • Lead IT compliance programs aligned to ISO/IEC 27001, CMMC Level 2, SEMI E187, and SOX IT controls.
  • Translate regulatory requirements into actionable policies, standards, procedures, and audit evidence.
  • Drive audit readiness, internal assessments, remediation activities, and continuous compliance improvement.
  • Partner with Legal, HR, Compliance, Finance, Facilities, Operations, Service, and Engineering teams on enterprise risk initiatives.

Cybersecurity Posture & Vulnerability Management

  • Own and mature cybersecurity posture management practices across infrastructure, endpoints, and cloud services.
  • Oversee vulnerability management programs, including risk-based prioritization, remediation tracking, and executive reporting.
  • Partner with Infrastructure, Security Operations, and Engineering teams to reduce attack surface and improve resilience.
  • Drive our IT Security program forward with a defense in depth and continuous improvement mindset.
  • Continuously assess and validate security controls effectiveness and drive improvements based on threat intelligence and risk trends.

Incident Response & Readiness

  • Own incident response planning and execution for IT and cybersecurity incidents.
  • Design and lead tabletop exercises, purple team drills, and post-incident reviews.
  • Maintain incident response playbooks, escalation paths, and executive communications.
  • Drive continuous improvement through lessons learned and after-action reviews.

Business Continuity & Disaster Recovery

  • Own and mature Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP).
  • Define and validate RTO/RPO objectives across hybrid on-prem and cloud environments.
  • Lead and coordinate DR testing, recovery exercises, and continuous improvement efforts.

Vendor, Partner & Supply-Chain Risk Management

  • Lead vendor, partner, and supply-chain IT and cybersecurity risk management programs.
  • Define security requirements for vendors, contract manufacturers, and extended factory partners.
  • Oversee onboarding assessments, remediation tracking, and ongoing risk reviews.
  • Support vendor audits, security reviews, and contractual security obligations in partnership with Procurement and Legal.

Strategic Planning & Continuous Improvement

  • Contribute to the development and execution of Onto’s 3-year IT and Security strategic roadmap.
  • Apply a continuous improvement mindset to compliance, security posture, incident readiness, and resilience programs.
  • Identify capability gaps, emerging risks, and investment priorities across people, process, and technology.
  • Support annual planning, budgeting, and executive reporting tied to multi-year strategy.

Agile, Global IT Leadership

  • Operate within an Agile, globally distributed IT organization.
  • Develop metrics, dashboards, and executive reporting for compliance, cybersecurity posture, and operational readiness.
  • Influence cross-functional teams through collaboration, leadership, and subject-matter expertise.

Qualifications

  • 10+ years of progressive experience in IT leadership, cybersecurity, or enterprise risk management.
  • Demonstrated leadership of ISO 27001, CMMC Level 2, and SOX IT control programs.
  • Experience contributing to multi-year (3+ year) IT or security strategic planning and roadmaps.
  • Hands-on experience with cybersecurity posture management and vulnerability management programs.
  • Strong understanding of incident response, BCP/DRP, and operational resilience in hybrid IT environments.
  • Experience managing vendors, partners, and supply-chain IT/security risk.
  • Strong executive communication, stakeholder management, and continuous improvement mindset.

Preferred Qualifications

  • Experience with SEMI E187/E188 or manufacturing-focused frameworks.
  • Familiarity with NIST CSF, NIST 800-53, or NIST 800-171.
  • Experience supporting global operations across North America, Europe, and APAC.
  • Background in semiconductor, advanced manufacturing, or IP-sensitive industries.
  • Experience translating strategy into measurable OKRs, KPIs, and risk metrics.

Leadership Competencies

  • Continuous improvement and risk-based decision-making mindset.
  • Executive presence and calm decision-making under pressure.
  • Ability to balance long-term strategy with near-term execution.
  • Strong collaboration across technical, business, and partner organizations.
  • High integrity, accountability, and operational discipline.

Why Join Onto Innovation?

At Onto Innovation, we believe your work should matter—and so should your well-being. That’s why we offer competitive salaries and a comprehensive benefits package designed to support you and your family. From health, dental, and vision coverage to life and disability insurance, PTO, and a 401(k) with employer match, we’ve got you covered. You’ll also enjoy access to our Employee Stock Purchase Program (ESPP), wellness initiatives, and cutting-edge tools—all within a collaborative, inclusive culture where your contributions are valued and recognized.

Compensation & Growth

• Base Salary Range:

$120,000.00 - $180,000.00, offered in good faith and based on experience, location, and qualifications.
  • Additional Rewards: Annual bonus opportunities and potential long-term incentives tied to both company and individual success.

Empowering Every Voice to Shape the Future:

Benefits

undefined
[job_alerts.create_a_job]

Senior Manager, Information Security • Wilmington,MA (Jonspin)

[internal_linking.similar_jobs]
Manager, Information Technology

Manager, Information Technology

Harbourvest • Boston, MA, United States
[job_card.full_time]
For over forty years, HarbourVest has been home to a committed team of professionals with an entrepreneurial spirit and a desire to deliver impactful solutions to our clients and investing partners...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Head of Cyber & Information Security Oversight (SVP)

Head of Cyber & Information Security Oversight (SVP)

State Street Corporation • Boston, MA, United States
[job_card.full_time]
SVP, Head of Cyber & Information Security Oversight.Why this role is important to us.Enterprise Technology Risk Management (ETRM) is responsible for thought leadership, oversight, monitoring, and a...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Chief Information Security Officer

Chief Information Security Officer

CERES Group • Boston, MA, United States
[job_card.full_time]
Reporting to the Global Chief Technology Officer, the Chief Information Security Officer (formerly known as the Global Security Officer) develops and maintains enterprise security and risk policies...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Project Manager, Cybersecurity

Senior Project Manager, Cybersecurity

Beth Israel Lahey Health • Boston, MA, United States
[job_card.full_time]
Senior Project Manager, Cybersecurity.Be among the first 25 applicants.Senior Project Manager, Cybersecurity.Day (United States of America).When you join the growing BILH team, you're not just taki...[show_more]
[last_updated.last_updated_30] • [promoted]
Information Security Analyst

Information Security Analyst

TradeJobsWorkForce • 02475 Arlington Heights, MA, US
[job_card.full_time]
Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv...[show_more]
[last_updated.last_updated_30] • [promoted]
Vice President, Security & Information Technology

Vice President, Security & Information Technology

CarGurus • Boston, MA, United States
[job_card.full_time]
Vice President, Security & Information Technology.At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination.We started as a small team of developers determined ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Analyst

Information Security Analyst

My3Tech Inc • Boston, MA, United States
[job_card.full_time]
This posting is for an Information Security Analyst to assist the Executive Office for Administration and Finance IT (A&F IT).A&F IT is seeking a highly skilled and detail-oriented Information Secu...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Engineer (Ping Identity)

Information Security Engineer (Ping Identity)

Eliassen Group • Boston, MA, United States
[job_card.full_time]
Information Security Engineer (Ping Identity).Cincinnati, Ohio, with a broad regional branch and ATM network across multiple states.The organization is a principal subsidiary of a public bank holdi...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Associate Director, Info Security — DSPM/DLP Leader (Hybrid)

Associate Director, Info Security — DSPM/DLP Leader (Hybrid)

Alkermes • Boston, MA, United States
[job_card.full_time]
A leading biopharmaceutical company is seeking an Associate Director of Information Security in Boston, MA.This role combines strategic leadership with technical execution, overseeing a team and ma...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Director, Application Security

Senior Director, Application Security

Berkshire Hathaway Specialty Insurance • Boston, MA, United States
[job_card.full_time]
Senior Director, Application Security.Berkshire Hathaway Specialty Insurance.This role is based in Boston, MA and the Base salary range for this position is.Total compensation will be determined by...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior E-Discovery Technology Project Manager

Senior E-Discovery Technology Project Manager

Fox Rothschild • Boston, MA, United States
[job_card.full_time]
As a member of the Information Services Department, the Senior E-Discovery Technology Project Manager is responsible for managing the entire lifecycle of a case, while developing and following work...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Cyber Defense & Engineering - Network Security - Manager

Cyber Defense & Engineering - Network Security - Manager

PwC • Boston, MA, United States
[job_card.full_time]
At PwC, our people in cybersecurity focus on protecting organizations from cyber threats through advanced technologies and strategies.They work to identify vulnerabilities, develop secure systems, ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Manager III- Network Security

Manager III- Network Security

Peapod Digital Labs • Quincy, MA, United States
[job_card.full_time]
USA-MA-Quincy-1385 Hancock Street.Infrastructure-Network (5118708).Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.Food Lion, Giant Food, The GIANT Company, ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
CISO: Strategic Information Security Leader

CISO: Strategic Information Security Leader

SHI • Boston, MA, United States
[job_card.full_time]
A global IT solutions provider in Boston is seeking a Chief Information Security Officer.The CISO will develop and implement a comprehensive information security strategy while managing incident re...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior Security Manager

Senior Security Manager

Northeast Security • Boston, MA, United States
[job_card.full_time]
Job Summary Manage and oversee a high-volume 24/7 Command Center supporting approximately 73 properties.This role manages emergency dispatch, CCTV monitoring, alarm monitoring for access control sy...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior InfoSec Consultant

Senior InfoSec Consultant

EY • Boston, MA, United States
[job_card.full_time]
At EY, we're all in to shape your future with confidence.We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.Join EY and help ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior VP, Security & IT Strategy

Senior VP, Security & IT Strategy

CarGurus LLC • Boston, MA, United States
[job_card.full_time]
A leading online automotive marketplace is seeking a strategic leader to head its Security and IT teams.This position involves designing and implementing security frameworks to ensure operational e...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Manager, Enterprise Security Advisors & Architects

Manager, Enterprise Security Advisors & Architects

Proofpoint • Boston, MA, United States
[job_card.full_time]
Manager, Sales Engineering (Enterprise Security Advisors & Architects).Join Proofpoint as a Manager, Sales Engineering (Enterprise Security Advisors & Architects) – a key leadership role driving th...[show_more]
[last_updated.last_updated_variable_days] • [promoted]