Founding Information Security Lead

Flodesk

Portland (OR)

On-site

USD 120,000 - 220,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Parental leave
Unlimited time off
401k match
Learning stipend

Job summary

Flodesk is seeking a seasoned security executive to own the security program end to end. You will establish governance, controls, and long-term strategy, while partnering with engineering to embed security into the product and cloud platforms.

You will lead SOC 2, ISO 27001, and CCPA readiness, and drive continuous compliance across the organization. A remote-first culture supports flexibility, with travel as needed.

Qualifications

  • 10+ years in information security, with a track record of building or maturing security programs.
  • 3+ years in an information security leadership role.
  • Strong foundation in cloud security, identity governance, vulnerability management, and incident response.
  • Proven experience aligning security and privacy practices with GDPR.
  • Comfortable partnering directly with engineering on product security and secure development practices.
  • Clear, confident communicator with technical and non-technical stakeholders alike.
  • Startup DNA: a can-do attitude, flexibility, and willingness to occasionally roll up your sleeves.
  • Willing to travel on a semiannual basis.

Responsibilities

  • Own and drive Flodesk's security program, including policies, controls, governance, and long-term maturity planning.
  • Collaborate cross-functionally to embed security into product, operations, and technology decisions.
  • Lead audits and maintain evidence collection for SOC 2, ISO 27001, and CCPA readiness.
  • Partner with engineering to secure architecture, development workflows, and cloud foundations.
  • Design, implement, and continuously improve security controls and tooling.
  • Own incident management end-to-end and report on security posture and compliance.
  • Manage IT operations lifecycle and vendor security considerations.

Skills

Security leadership
Program governance
Cloud security
Privacy & GDPR
Collaboration with engineering
Clear communication
Startup mindset
Travel willingness

Job description

Flodesk is one of the world’s fastest-growing email marketing companies, built to help creators sell online and design emails that people love to get. Our commitment to small business owners is to create simple and intuitive tools that help them grow, nurture, and monetize their email list.

We’re a remote-first company headquartered in San Francisco, California, with a globally distributed team—including an in-person office in Da Nang, Vietnam and Menlo Park. Our team reflects the diversity and creativity of the people we serve. Join our mission to level the playing field for small business owners through good design.

About the role

You’ll own Flodesk’s security program end to end: the frameworks, controls, and governance that define our long‑term security posture. Reporting to the COO/CPO, this is a hands‑on, build‑it‑yourself role that drives SOC 2, ISO 27001 and CCPA auditing readiness, embedding security into how engineering ships product, and keeping day‑to‑day IT and vendor operations running. You’ll write the policies, run point on audits, partner with engineering on the technical foundations — all while setting the strategic direction for where security goes next and representing it confidently, internally and externally.

What you’ll do
Security program ownership [40%]
  • Own Flodesk's security program: policies, controls, governance, and long‑term maturity planning
  • Collaborate cross‑functionally to build security into product, operational, and technology decisions
  • Maintain and update - privacy‑related security practices across data handling, retention, and customer commitments
  • Lead SOC 2, ISO 27001 and CCPA readiness, including audits, evidence collection, and continuous compliance
Security implementation & compliance support [40%]
  • Partner with engineering to integrate security into architecture, development workflows, and release processes, and to build and maintain security foundations across cloud infrastructure, applications, data, and internal systems
  • Evaluate, implement, and maintain security tooling and automation to scale the program
  • Own Security Incident Management end to end: process, technical capability, and cross‑company engagement
  • Design, implement, and continuously improve controls
  • Track and report on security posture, program maturity, and compliance statusDefend Flodesk's SaaS platform and its customers by introducing protective mechanisms and security capabilities
IT support & operations [10%]
  • Own the lifecycle of company hardware from procurement to retirement
  • Be the first point of contact for IT issues: hardware, software, network connectivity
  • Run new‑hire setup (accounts, device provisioning) and secure access revocation for leavers. Manage domain registrations, DNS, and general IT housekeeping
Software & vendor operations [10%]
  • Vet new tools before purchase, checking for SSO, 2FA, and integration capabilities
  • Maintain a central registry of approved software so the org stays on authorized tools
What you bring
  • 10+ years in information security, with a track record of building or maturing security programs
  • 3+ years in an information security leadership role
  • Strong foundation in cloud security, identity governance, vulnerability management, and incident response
  • Proven experience aligning security and privacy practices with GDPR
  • Comfortable partnering directly with engineering on product security and secure development practices
  • Clear, confident communicator with technical and non‑technical stakeholders alike
  • Startup DNA: a can‑do attitude, flexibility, and the willingness to occasionally roll up your sleeves on the basics, given our startup mindset
  • Willing to travel on a semiannual basis
Extra points if you have
  • Experience securing SaaS products
  • Experience implementing SOC 2, ISO 27001/2, or similar security/compliance frameworks
  • Background in reliability, DevOps, or application architecture
  • Conversational (or better) Vietnamese
What we bring
  • $120,000–$220,000 base salary, depending on your location and experience. We prefer to hire near our Menlo Park hub for in‑person collaboration with the COO/CPO. Residents in Seattle & San Francisco Bay Area: $160,000–$220,000; all other locations $120,000–$180,000.
  • Fully paid health insurance for individual coverage
  • 16 weeks paid parental leave for non‑birthing parents; 22 weeks paid maternity leave for birthing parents
  • Unlimited flexible time off
  • 401k match (US employees only)
  • $1,000 annual stipend for learning and development

Flodesk is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Flodesk is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email people@flodesk.com

Notice to California-based Candidates and Vietnam-based Candidates for Employment

This Candidate Privacy Notice is intended to provide information about how Flodesk collects and uses personal information to California consumers and candidates located in Vietnam (Vietnam‑based candidates) who apply for employment with Flodesk. If you are employed by Flodesk, refer to the Employee Handbook for additional information. For any questions about this notice, please contact People@flodesk.com.

Personal Information Flodesk Collects:

Identifiers Including name, address, email, telephone number, social security number, driver license number, passport number, and other personal identifying information. For California-based candidates: Characteristics of protected classifications under California or federal law including demographic information and other personal information obtained during the application process, such as gender, race, national origin. Professional or employment‑related information, such as salary/compensation and benefits packages, other relocation or job preferences, prior background, experience, skills, and other information in support of your application, reference information. Any other information you provide as a part of recruitment, job application, or interview process.

Purposes for Collecting Personal Information:

To consider qualifications, skills, and interest for employment. To communicate with you during the recruitment and interview process. To provide compensation, including payroll, and administer stock options and benefits, including medical, dental, vision, commuter, and retirement benefits. To provide human resources services and conduct performance evaluations. To monitor work eligibility including work‑related licenses, credentials, training, and eligibility to work in the United States or in Vietnam. To improve recruitment and interview processes and ensure a safe and efficient working environment. To comply with applicable legal or regulatory requirements as Flodesk may transfer or store internationally your information, including to or in the United States, European Union and Vietnam and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.

For Vietnam-based candidates

By clicking "Submit Application", You confirm that you have read the Privacy Notice and agree to allow Flodesk to process your personal data for this application, including cross‑border transfer. You have the right to withdraw your consent or request data deletion at any time by contacting people@flodesk.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Founding Information Security Lead
Founding Information Security Lead

Flodesk • Menlo Park (CA)

Hybrid
USD 120,000 - 220,000
Health insurance
Parental leave
Unlimited time off
+2
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Voiceflow • San Francisco (CA)

On-site
USD 165,000 - 202,000
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Flexport • San Francisco (CA)

On-site
USD 165,000 - 202,000
Relocation support
Competitive salary & benefits
Head of Information Security
Head of Information Security

Sendbird • San Mateo (CA)

On-site
USD 280,000 - 320,000
Medical, dental, and vision coverage
Generous PTO
$3,500 annual personal growth boost
+3
Principal People Team Business Partner - R&D
Principal People Team Business Partner - R&D

Cloudflare • United States

On-site
USD 178,000 - 245,000
Equity in Cloudflare
Health & Welfare benefits
401(k) plan
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Voiceflow • United States

On-site
USD 165,000 - 202,000
Principal / Senior Software Engineer
Principal / Senior Software Engineer

Flagship Pioneering • Cambridge (MA)

On-site
USD 108,000 - 209,000
Healthcare coverage
Annual incentive program
Retirement benefits
+1
Senior Product Manager, Email Security
Senior Product Manager, Email Security

Triwill Group • Austin (TX), Northern (KY)

Hybrid
USD 140,000 - 200,000
Health Insurance
Dental Insurance
Vision Insurance
+3
Senior Engineering Director, Security Products
Senior Engineering Director, Security Products

CloudFlare • Northern (KY), New York (NY)

Hybrid
USD 300,000 - 415,000
Equity
Health & Welfare Benefits
Flexible PTO
+2
Senior UAS Flight Test & Operations Engineer
Senior UAS Flight Test & Operations Engineer

Flagship Pioneering • Colorado Springs (CO)

On-site
USD 115,000 - 150,000