Compliance and IT Security Manager

Enboarder

New York (NY)

Hybrid

USD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Slang AI seeks a senior Compliance & Security Manager to own SOC 2 program, risk registry, and IT operations. You’ll supervise security policies, perform audits, and coordinate vendor reviews while managing day-to-day IT like Google Workspace, SSO, and staff provisioning across multiple SaaS tools.

This role blends compliance discipline with hands-on IT operations. The ideal candidate brings 7+ years in IT/security/compliance, SOC 2 experience, and strong policy writing.

Qualifications

  • 7+ years of IT administration, security, and compliance experience.
  • Bachelors or Masters degree in cybersecurity, IT, IS, CS, or related field.
  • Nationally recognized cybersecurity certifications (Security+, PenTest+, CASM, CISSP or equivalent).
  • Direct experience with SOC 2 audits, evidence collection, control mapping, and auditor coordination.
  • Hands-on experience with Google Workspace or Microsoft 365 administration.
  • Experience with IAM, including SSO configuration and provisioning/deprovisioning across multiple SaaS platforms.
  • Experience with Okta/OneLogin/Rippling/JumpCloud.
  • Experience maintaining a risk registry and driving remediation processes.
  • Familiarity with Drata, Vanta, or similar automation platforms.
  • Experience coordinating penetration tests and remediation of findings.
  • Strong policy and security documentation writing.
  • Ability to manage multiple compliance, security, and IT workstreams independently.

Responsibilities

  • Own and maintain security and compliance programs including SOC 2 readiness and auditor coordination.
  • Maintain and update security policies reflecting regulatory needs.
  • Maintain the risk registry with mitigations and timelines.
  • Plan and execute regular compliance activities and drills.
  • Coordinate annual penetration tests and remediate findings.
  • Review vendor security via SOC 2 reports and DPA.
  • Monitor security events and coordinate incident response.
  • Improve automation workflows in Drata for audit efficiency.
  • Recommend security tooling improvements as needs evolve.
  • Deliver security awareness training for staff.
  • Administer Google Workspace including security configurations (DLP, context-aware access).
  • Manage staff provisioning/deprovisioning across SaaS via Rippling and Google Workspace.
  • Set up and maintain SSO connections across tools; troubleshoot auth issues.
  • Handle IT onboarding/offboarding from security perspective; device provisioning and access revocation.
  • Conduct periodic access audits; verify deprovisioning across systems.
  • Respond to IT help requests via Slack; document escalations.
  • Onboarding/offboarding staff from IT security perspective.

Skills

IT Administration
Security & Compliance
SOC 2 Audits
IAM
Google Workspace
SSO Configuration
Policy Writing
Risk Registry
Incident Response
Security Training

Education

Bachelors or Masters in CS/IT/Cybersecurity
Cybersecurity Degree

Tools

Okta
OneLogin
Rippling
JumpCloud
Drata
Vanta
Google Workspace

Job description

About Slang AI

Slang AI is redefining customer engagement through conversational AI, making every interaction seamless and efficient. Our mission is to transform the restaurant industry by providing the ultimate voice AI solution for consistently outstanding customer experiences.

At Slang AI, we believe how we build matters just as much as what we build. We foster a culture rooted in hospitality, ownership, and clarity, where every “Slangsta” feels valued, supported, and connected to the broader impact of our work in the AI-powered future of restaurants.

Overview

We're looking for a Compliance & IT Security Manager to own and advance our compliance programs, security posture, and core IT functions. This is a senior individual contributor role, not a people management position. You'll be the person responsible for making sure our compliance obligations are met, our security controls are effective, and the systems our team relies on every day are well run and secure as the company grows.

Your primary focus is compliance. You'll own our SOC 2 program end to end, from evidence collection to auditor coordination, along with our risk registry and security policies. Alongside that, you'll own the day-to-day IT functions that keep the company running: administering Google Workspace, managing identity and access across our SaaS tools, configuring SSO, and supporting staff through their full lifecycle. The ideal candidate is someone who can move between coordinating a SOC 2 audit and configuring SSO for a new SaaS tool, and who treats compliance as an ongoing discipline.

KeyResponsibilities
Compliance & Security
  • Own and maintain the company's security and compliance programs, including SOC 2 audit readiness, evidence gathering, and coordination with external auditors
  • Manage and keep current all company security policies, ensuring they reflect evolving business needs, regulatory requirements, and industry best practices
  • Maintain and update the company's risk registry, tracking identified risks, mitigations, and remediation timelines
  • Plan and execute all regularly scheduled compliance activities, including backup recovery tests, access reviews, business continuity exercises, and tabletop drills
  • Scope, schedule, and coordinate annual penetration tests based on our active production web services and applications, and manage remediation of findings
  • Maintain the company's vendor registry and perform security reviews on both existing and prospective vendors, including evaluating SOC 2 reports, data processing agreements, and security questionnaires
  • Monitor and respond to security events and alerts, triaging issues and coordinating incident response when needed
  • Manage and improve compliance automation workflows in Drata, reducing manual evidence collection and improving audit efficiency
  • Evaluate and recommend security tooling improvements as the company's infrastructure and threat landscape evolve
  • Develop and deliver security awareness training for staff on topics such as phishing, credential hygiene, and data handling
IT & Identity
  • Administer the company's Google Workspace environment, including user management, organizational units, and security configurations such as DLP policies, context-aware access controls, and authentication requirements
  • Own staff account provisioning and deprovisioning across dozens of SaaS platforms via Rippling and Google Workspace, ensuring timely onboarding and thorough offboarding
  • Set up and maintain Single Sign-On (SSO) connections between Rippling and SaaS tools, troubleshooting authentication issues as they arise
  • Own staff onboarding and offboarding from an IT and security perspective, including device provisioning through Rippling, MDM compliance, endpoint security configurations, and timely access revocation
  • Conduct periodic access audits to verify that user permissions are appropriate and that former staff have been fully deprovisioned across all systems
  • Respond to IT help requests via Slack, assisting staff with technical issues, access problems, and general troubleshooting, escalating and documenting as appropriate
Basic Qualifications
  • 7+ years of experience across IT administration, security, and compliance, or a closely related field
  • Bachelor's or Master's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field
  • Nationally recognized cybersecurity certifications such as CompTIA Security+, CompTIA PenTest+, CASM, CISSP, or equivalent
  • Direct experience working through SOC 2 audits, including evidence collection, control mapping, and auditor coordination
  • Hands-on experience administering a cloud productivity and collaboration suite such as Google Workspace or Microsoft 365, including user management, organizational units, security settings, and policy enforcement
  • Experience with identity and access management, including SSO configuration and provisioning and deprovisioning across multiple SaaS platforms
  • Experience with an identity or IT management platform such as Okta, OneLogin, Rippling, JumpCloud, or similar
  • Experience maintaining a risk registry and driving risk remediation processes
  • Familiarity with compliance automation platforms such as Drata, Vanta, or similar
  • Experience coordinating penetration tests and managing remediation of findings
  • Strong written communication skills, particularly for policy authoring, security documentation, and audit evidence
  • Ability to work independently and manage multiple compliance, security, and IT workstreams simultaneously
Nice to Haves
  • CISM (Certified Information Security Manager) from ISACA
  • Hands-on experience hardening a cloud productivity suite, including DLP, context-aware or conditional access, and security key enforcement
  • Experience administering MDM solutions such as Kandji, Jamf, Rippling, or Microsoft Intune
  • Experience leading IT initiatives such as a password manager migration, hardware security key (YubiKey) rollout, or corporate VPN deployment
  • Experience building or improving incident response plans and runbooks
  • Familiarity with zero trust architecture principles
  • Experience with endpoint detection and response (EDR) tools such as CrowdStrike or SentinelOne
  • Background in vendor risk management programs, including maintaining vendor registries and reviewing third-party SOC 2 reports
  • Experience delivering security awareness training programs
  • Familiarity with cloud security concepts across GCP, AWS, or Azure
  • Scripting skills (Python, Bash) for automating security and compliance workflows
  • Prior experience at a fast-growing startup where you owned the security and IT functions
Location

New York / Hybrid or Remote (USA). Employees in the NYC area are expected in-office Tuesday through Thursday. Can be fully remote within the US.

Our Vision

Calling a business shouldn’t feel like a robot-hostage situation, where you’re forced to listen to horrible music and can't reach a human, while enduring a soulless voice uttering "I'm sorry I didn't quite get that" on repeat for eternity. (shudder) That's why we started Slang AI We use the latest AI and audio wizardry to make transacting via voice so enjoyable it’s more human than human. By 2030, we will save businesses and consumers 1 billion minutes of precious time while transforming voice channels into the preferred mode of communication (it's faster and easier than text).

We have backgrounds building product at companies like Spotify, Buzzfeed, the New York Times, and OpenTable —shipping experiences that have reached hundreds of millions of users. Now, we’re using our backgrounds to start a new culture, one that puts product and human-centered design above all else while fostering constant learning and growth. Sound like something you’d like to be part of? Get on board.

Our Values

Overachiever Fever. We’re overachievers (we don’t know any other way)

AI Native. We don't just sell AI. We are Al.

Humility Ability. We approach each other with curiosity and openness (know-it-alls not welcome!)

Be A Good Host. We build for hospitality. We should embody it.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance and IT Security Manager
Compliance and IT Security Manager

Slang AI • United States

Hybrid
USD 140,000 - 190,000
Compliance and IT Security Manager
Compliance and IT Security Manager

Helloslang • New York (NY)

Hybrid
USD 140,000 - 190,000
Sr Backend Engineer
Sr Backend Engineer

Enboarder • New York (NY)

Hybrid
USD 185,000 - 215,000
Account Executive II - Miami
Account Executive II - Miami

Slang AI • Miami (FL)

On-site
USD 70,000 - 120,000
Sr Backend Engineer
Sr Backend Engineer

Slang • New York (NY)

Hybrid
USD 185,000 - 215,000
Account Executive II
Account Executive II

Slang AI • Los Angeles (CA)

Hybrid
USD 160,000 - 180,000
Account Executive II - LA
Account Executive II - LA

Enboarder • Los Angeles (CA)

On-site
USD 85,000 - 170,000
Competitive compensation
Rewards & benefits
Learning & development
Account Executive II - LA
Account Executive II - LA

Slang AI • Los Angeles (CA)

On-site
USD 150,000 - 190,000
Equity
Competitive compensation
Travel opportunities
Account Executive II - NYC
Account Executive II - NYC

Enboarder • New York (NY)

On-site
USD 90,000 - 140,000
Account Executive - CHI
Account Executive - CHI

Enboarder • Chicago (IL)

On-site
USD 90,000 - 130,000