
Information Security Manager
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Manage the SOC 2 program from start to finish and enhance Information Security policies.
• Take ownership of the Vanta instance and conduct business continuity exercises.
• Serve as the representative for information security in the Risk + Compliance committee.
• Lead and work collaboratively with IT/TechOps in corporate IT and security initiatives.
• Supervise laptop procurement, MDM, onboarding/offboarding processes, SaaS vendor management, incident response, and data loss prevention.
• Set the strategic direction and develop the IT/TechOps function and team.
• Manage third-party security assessments and address security questionnaires from customers and partner banks.
• Configure the SIEM and establish effective alerting mechanisms.
• Maintain vendor relationships to enhance proactive visibility and mitigate risks.
• Enhance GCP cloud security, IAM, JIT privilege escalation, group-based access, and platform hardening strategies.
• Collaborate with engineering on secure SDLC, dependency and vulnerability scanning, CI/CD and pipeline hardening, and threat modeling.
• Work with the CTO and AI Labs on analyzing build versus buy options for agentic security initiatives.
• Ensure that deployed AI agents function securely.
• Report to the CTO and manage the IT/TechOps team.
• CISSP certification is required.
• Minimum of 5 years of experience on a security team.
• Experience working in a startup environment.
• Background at a company that has achieved SOC 2 or ISO 27001 certification.
• A semi-technical degree (such as Information Systems) or several years of hands-on technical experience, including scripting, web development, automation, or data analysis.
• Proficiency in scripting, prototyping, and utilizing AI and modern tools.
• Excellent communication skills with customers, partner banks, auditors, and internal teams.
• Experience interacting with customers and regulators.
• Experience in fintech, lending, or other regulated/high-trust environments is a plus.
• Hands-on experience in GCP security is advantageous; AWS experience is also welcomed.
• Experience establishing or managing a SOC 2 program from the ground up is a plus.
• Experience handling due diligence from partner banks or enterprise clients is beneficial.
• Must not require current or future visa sponsorship to work legally in the United States.
• Competitive cash and equity compensation.
• Comprehensive health benefits (including health, dental, and vision).
• Student loan repayment assistance.
• 401k matching program.
• Commuter benefits.
• Flexible PTO policy.
• Opportunities for growth and performance in a dynamic environment alongside a talented team.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.