
Founding Information Security Lead
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in United States, +3 more locations.
• Take charge of Flodesk's security program, encompassing policies, controls, governance, and long-term maturity strategy.
• Work collaboratively across departments to integrate security into product, operational, and technological decisions.
• Uphold privacy-centric security measures concerning data handling, retention, and customer commitments.
• Oversee SOC 2, ISO 27001, and CCPA readiness, audits, evidence gathering, and ongoing compliance.
• Collaborate with engineering teams on security architecture, development workflows, release processes, and security foundations across cloud infrastructure, applications, data, and internal systems.
• Assess, deploy, and manage security tools and automation.
• Take full responsibility for end-to-end security incident management.
• Design, implement, and consistently enhance security controls.
• Monitor and report on security posture, program maturity, and compliance status.
• Safeguard Flodesk's SaaS platform and customers through protective mechanisms and security capabilities.
• Oversee the company hardware lifecycle from procurement to retirement.
• Provide initial IT support for hardware, software, and network connectivity issues.
• Manage new-hire account setup, device provisioning, and secure access revocation for departing employees.
• Handle domain registrations, DNS management, and general IT maintenance.
• Evaluate new tools for SSO, 2FA, and integration capabilities.
• Maintain a registry of authorized software.
• Over 10 years of experience in information security, demonstrating a history of developing or enhancing security programs.
• More than 3 years in a leadership role within information security.
• Solid foundation in cloud security, identity governance, vulnerability management, and incident response.
• Proven track record of aligning security and privacy practices with GDPR.
• Comfortable working directly with engineering on product security and secure development methodologies.
• Strong and confident communication skills with both technical and non-technical stakeholders.
• Positive attitude, adaptability, and readiness to occasionally manage basic tasks.
• Willingness to travel semiannually.
• Experience in securing SaaS products is a plus.
• Familiarity with implementing SOC 2, ISO 27001/2, or similar frameworks is advantageous.
• Background in reliability, DevOps, or application architecture is a plus.
• Conversational proficiency or better in Vietnamese is an advantage.
• Comprehensive health insurance fully covered for individual plans.
• 16 weeks of paid parental leave for non-birthing parents.
• 22 weeks of paid maternity leave for birthing parents.
• Unlimited flexible time off.
• 401k matching (for US employees only).
• Annual stipend of $1,000 for learning and development.
Primer
Akamai Technologies
Mashreq
Alice
Get handpicked remote jobs straight to your inbox weekly.