IT & Information Security Compliance Manager (Automation & Certifications)

1Kosmos

Edison (NJ)

On-site

USD 110,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k)
Paid time off
Professional development budget
Certification reimbursement

Job summary

1Kosmos in Edison, NJ is seeking an IT & Information Security Compliance Manager to own and strengthen our security posture across SOC 2, ISO 27001, FedRAMP High, and NIST. This hands-on leadership role is not a CISO; it focuses on audit readiness, control implementation, IT governance, and continuous improvement of compliance programs.

You will automate evidence collection using Drata or Vanta and collaborate with IT Operations and Engineering to embed security controls in cloud and

Qualifications

  • 6+ years of experience in IT security, compliance, or risk management within a SaaS or regulated technology environment.
  • Proven experience managing SOC 2 and ISO 27001 programs end-to-end; exposure to FedRAMP High or NIST 800-53 is a plus.
  • Hands-on use and administration of Drata, Vanta, Tugboat Logic, or equivalent compliance automation platforms.
  • Familiarity with AWS/Azure/GCP cloud environments, identity & access management, and IT operations.
  • Strong technical understanding of security controls: network, endpoint, access, configuration management, logging/monitoring, vulnerability management.
  • Excellent documentation and communication skills — able to translate control requirements into clear operational actions.
  • Experience leading internal or external audits and managing evidence collection efficiently.
  • Based in (or willing to relocate to) Edison, NJ and work on-site with our leadership and operations teams.

Responsibilities

  • Lead and maintain enterprise security and compliance programs aligned with SOC 2, ISO 27001/27002, FedRAMP High, and NIST 800-53/171 frameworks.
  • Build and manage automated compliance monitoring and evidence collection through Drata, Vanta, or equivalent platforms; integrate these with internal systems (ticketing, HRIS, cloud providers, etc.).
  • Prepare for and manage SOC 2 Type I/II, ISO audits, and FedRAMP readiness assessments: gap analysis, documentation, remediation, and control testing.
  • Partner with IT Operations and Engineering to ensure security controls are embedded in infrastructure, cloud, network, and identity systems.
  • Maintain and update security policies, SSPs, POA&Ms, and other audit documentation.
  • Oversee incident response, change management, and vendor risk programs to ensure consistent compliance coverage.
  • Manage relationships with external auditors and compliance assessors.
  • Define and track metrics for audit readiness, risk posture, and compliance automation efficiency.
  • Stay current with evolving compliance frameworks and technologies that can improve assurance automation.
  • Champion security awareness, training, and continuous improvement across the organization.

Skills

IT security
compliance
risk management
SOC 2
ISO 27001
FedRAMP High
NIST 800-53
Drata
Vanta
Tugboat Logic
cloud security
identity & access management
auditing
documentation

Tools

Drata
Vanta
Tugboat Logic

Job description

Are you ready to shape the future of authentication? Join 1Kosmos and help lead the next wave in identity assurance and passwordless innovation.

1Kosmos is driving the future of identity security, empowering organizations to eliminate passwords and establish trust at every step of the identity lifecycle. As a vibrant team of innovators, we develop advanced authentication solutions trusted by some of the world's leading brands. Join us as we create a passwordless world and set new standards for digital identity assurance.

We are seeking anIT & Information Security Compliance Managerto own and strengthen our company's security and compliance posture across frameworks such asSOC 2,ISO 27001,FedRAMP High, andNIST.

This is a hands-on operational leadership role (not a CISO), focused on ensuring audit readiness, control implementation, IT governance, and continuous improvement of our security programs. The ideal candidate will combine a strong understanding of infrastructure and security controls with experienceautomating compliance workflowsusing tools likeDrataorVanta.

Requirements
Key Responsibilities
  • Lead and maintain enterprise security and compliance programs aligned with SOC 2, ISO 27001/27002, FedRAMP High, and NIST 800-53/171 frameworks.
  • Build and manageautomated compliance monitoringand evidence collection throughDrata,Vanta, or equivalent platforms; integrate these with internal systems (ticketing, HRIS, cloud providers, etc.).
  • Prepare for and manageSOC 2 Type I/II, ISO audits, and FedRAMP readiness assessments: gap analysis, documentation, remediation, and control testing.
  • Partner with IT Operations and Engineering to ensure security controls are embedded in infrastructure, cloud, network, and identity systems.
  • Maintain and update security policies, SSPs, POA&Ms, and other audit documentation.
  • Oversee incident response, change management, and vendor risk programs to ensure consistent compliance coverage.
  • Manage relationships with external auditors and compliance assessors.
  • Define and track metrics for audit readiness, risk posture, and compliance automation efficiency.
  • Stay current with evolving compliance frameworks and technologies that can improve assurance automation.
  • Champion security awareness, training, and continuous improvement across the organization.
Qualifications
Must-Have
  • 6 + years of experience in IT security, compliance, or risk management within a SaaS or regulated technology environment.
  • Proven experience managingSOC 2andISO 27001programs end-to-end; exposure toFedRAMP HighorNIST 800-53is a plus.
  • Hands-on use and administration ofDrata,Vanta, Tugboat Logic, or equivalent compliance automation platforms.
  • Familiarity with AWS/Azure/GCP cloud environments, identity & access management, and IT operations.
  • Strong technical understanding of security controls: network, endpoint, access, configuration management, logging/monitoring, vulnerability management.
  • Excellent documentation and communication skills — able to translate control requirements into clear operational actions.
  • Experience leading internal or external audits and managing evidence collection efficiently.
  • Based in (or willing to relocate to)Edison, NJand work on-site with our leadership and operations teams.
Preferred
  • Certifications such asCISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, orFedRAMP Practitioner.
  • Experience managing or improving IT operations processes with a compliance lens.
  • Familiarity with compliance automation APIs or integration scripting is a bonus.
Benefits
  • Benefits:
  • Comprehensive health, dental, and vision coverage
  • 401(k)
  • Paid time off
  • Professional development budget
  • Certification reimbursement
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Compliance Lead: Audit-Driven & Automation
Security Compliance Lead: Audit-Driven & Automation

1Kosmos • Edison (NJ)

On-site
USD 110,000 - 160,000
Health insurance
401(k)
Paid time off
+2
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

1Kosmos • Woodbridge Township (NJ)

Hybrid
USD 150,000 - 250,000
Competitive compensation and equity package
Flexible work arrangements
Opportunity to shape security at a startup
VP of Engineering
VP of Engineering

1Kosmos • Edison (NJ)

On-site
USD 180,000 - 280,000
Health insurance
Dental insurance
Vision insurance
+2
VP of Engineering
VP of Engineering

Hyperproof • Edison (NJ)

On-site
USD 180,000 - 260,000
Health insurance
Equity package
Unlimited PTO
Senior Implementation Engineer
Senior Implementation Engineer

Hyperproof • Edison (NJ)

Hybrid
USD 140,000 - 190,000
Flexible Hybrid Work Model
Medical / Dental / Vision / 401k
VP of Engineering
VP of Engineering

1Kosmos Inc. • Edison (NJ)

On-site
USD 180,000 - 260,000
Competitive salary and equity package
Health, dental, and vision insurance
Unlimited PTO Policy
+1
Compliance Account Coordinator - NYC
Compliance Account Coordinator - NYC

Rippling • New York (NY)

On-site
USD 27,552 - 34,440
10 days of paid time off (PTO)
11 paid federal holidays
401(k) with 4% company match
+2
Senior Implementation Engineer
Senior Implementation Engineer

1Kosmos • Edison (NJ)

Hybrid
USD 140,000 - 190,000
Flexible Hybrid Work Model
Medical / Dental / Vision / 401k
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Compliance Account Coordinator - NYC
Compliance Account Coordinator - NYC

agencycyber • New York (NY)

On-site
USD 27,552 - 34,440
10 days of paid time off (PTO)
11 paid federal holidays
401(k) with 4% company match
+3