
Head of Security and IT
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Lead the team dedicated to safeguarding and managing the technology that powers Cardlytics' operations.
• Establish the security and IT strategy, representing the program to executives, the board, and banking partners.
• Supervise a five-member team covering security engineering, IT engineering, network engineering, security compliance, and end-user support.
• Take ownership of the SOX/SOC 2 control environment for engineering and GUARD.
• Act as the primary liaison for external auditors, internal audit, and third-party risk assessments from bank partners.
• Oversee and enhance identity and access management across Google Workspace, Okta, and ConductorOne.
• Maintain the cloud security baseline within the AWS production environment.
• Collaborate with Engineering to identify and resolve security issues flagged by Wiz and Expel.
• Promote safe and effective AI adoption across the company while incorporating AI into security, IT, and compliance workflows.
• Ensure secure device management for the remote workforce using Windows/macOS, BYOD mobile posture, and comprehensive IT help desk support.
• Guarantee proactive SSL/TLS certificate renewal, network resilience, and overall network hygiene.
• Manage and develop the five-member team, set priorities, review work, and fulfill team functions as necessary.
• Collaborate with the CTO to align security and IT priorities with the overall business strategy.
• Communicate risk and program status to non-technical executives, board members, and bank auditors.
• Over 8 years of experience in security and/or IT leadership roles.
• At least 3 years of direct team management experience.
• Extensive, hands-on expertise in at least two of the following areas: security engineering, security architecture, identity and access management, or vulnerability management.
• Proven experience managing or significantly supporting SOX and/or SOC 2 compliance programs, including collaboration with external auditors.
• Familiarity with modern IAM tools such as Okta or Google Workspace.
• Experience with cloud security platforms like Wiz or similar CNAPP/CSPM solutions.
• Comfort working in a fully remote, streamlined team environment, relying on managed or third-party providers.
• Working knowledge of AWS and infrastructure-as-code concepts, including Terraform.
• Executive-level communication skills for translating technical risks into business language.
• Passion for utilizing AI tools in security, IT, and compliance workflows.
• Required familiarity with macOS and Google Workspace; both macOS and Windows environments are supported.
• Experience in fintech, adtech, or environments subject to significant third-party or banking compliance scrutiny is preferred but not mandatory.
• Familiarity with Databricks, EKS, or MDR/managed-SOC relationships is advantageous but not essential.
• CISSP, CISM, or equivalent security/compliance certification is preferred but not required.
• Flexible paid time off along with company holidays.
• Medical, dental, and vision insurance starts on your first day.
• 401(k) retirement plan with company matching contributions.
• Student loan debt repayment option available through the 401(k) plan.
• Employee Stock Purchase Plan.
• Educational assistance for ongoing education.
• Lifestyle Spending Account aimed at physical, emotional, and financial wellness.
• Complimentary subscriptions to the Calm app to support employee mental health and well-being.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.