Manager, IT Compliance & Vendor Management

Tusk

United States

Remote

USD 120,000 - 175,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Landline is seeking a Manager, IT Compliance & Vendor Management to build and run its cybersecurity control program and oversee the MSP delivering day-to-day IT operations. This role ensures controls align with NIST CSF 2.0 and satisfy partner, regulator, and internal risk requirements.

You will manage policy lifecycle, risk registers, evidence collection, and security training while coordinating audits and vendor contracts across a remote-capable team.

Qualifications

  • Five+ years in IT compliance, information security, IT audit, or IT governance with at least two years leading a control program.
  • Hands-on experience with security frameworks (NIST CSF/NIST 800-53/ISO 27001/SOC 2/CIS Controls).
  • Experience administering GRC or compliance automation platforms (Vanta, Drata, Secureframe, LogicGate, AuditBoard, ServiceNow GRC).
  • Experience overseeing outsourced IT providers and SLAs.
  • Knowledge of core IT controls: IAM, endpoint management, logging, vulnerability management, backup and change control.
  • Ability to critically read SOC 2 Type II reports, noting scope and exceptions.
  • Strong written communication for external-facing documentation.
  • Direct NIST CSF 2.0 Govern experience is a strong plus.
  • Exposure to regulated industries (transportation/aviation) is a plus.
  • Familiarity with PCI DSS, CPRA, breach notification requirements.
  • Contract negotiation experience with technology vendors or providers.
  • ITIL foundation or equivalent service-management background.

Responsibilities

  • Manage the cybersecurity control program mapped to NIST CSF 2.0 across six Functions.
  • Administer the MSP relationship, including performance, escalations, and service delivery.
  • Lead policy lifecycle: drafting, approvals, publication, and attestation tracking.
  • Maintain the enterprise risk register and executive risk reporting.
  • Coordinate evidence for customer security reviews, partner assessments, and external audits.
  • Oversee security awareness training programs and phishing simulations.
  • Ensure MSP-controlled controls function as contracted with evidence-based validation.
  • Govern MSP access, joiner/moderator/leaver processes and access reviews.
  • Maintain RACI for controls shared between Landline and MSP.
  • Oversee vendor intake, security reviews, and data classification with review cadence.
  • Collect and review third-party assurance artifacts (SOC 2 Type II, ISO 27001, pen tests).
  • Track vendor security terms, breach obligations, and data processing agreements.
  • Maintain incident response, business continuity, and disaster recovery documentation.
  • Deliver recurring compliance and vendor performance reports to executives.

Skills

IT compliance
Information security
IT governance
Vendor management
Security controls
SOC 2/CSF reading
Written communication
NIST CSF governance
Regulated industries
Contract negotiation
ITIL basics

Education

CISA/CRISC/CISM/CISSP certification
ITIL foundation

Tools

Vanta
Drata
Secureframe
LogicGate
AuditBoard
ServiceNow GRC

Job description

About The Landline Company

The Landline Company is redefining the airport journey by building infrastructure that decentralizes the airport. Its platform connects air and ground transportation, extending the airport experience into everyday places and enabling seamless door-to-gate travel while unlocking new demand.

The Role

Landline is seeking a Manager, IT Compliance & Vendor Management to build and run the company's cybersecurity control program and to oversee the managed service provider (MSP) that delivers its day-to-day IT operations. This single role owns two connected accountabilities: the performance of Landline's MSP, and the design, operation, and evidencing of the company's control program against the NIST Cybersecurity Framework (CSF) 2.0.

Landline operates in a regulated transportation environment and contracts with airline partners and airports that impose their own security and data-handling requirements. The control program must satisfy those obligations as well as the company's internal risk requirements.

What You Will Do
  • Maintain the company's control set mapped to NIST CSF 2.0 across all six Functions: Govern, Identify, Protect, Detect, Respond, and Recover
  • Administer the Vanta GRC platform, including integrations, control monitoring, evidence collection, automated test configuration, and remediation tracking
  • Perform periodic control testing and design effectiveness reviews, document results, and drive remediation to closure with named owners and due dates
  • Own the policy lifecycle: drafting, annual review, approval routing, publication, and attestation tracking
  • Maintain the enterprise risk register, including risk scoring methodology, treatment decisions, and executive reporting
  • Prepare and coordinate evidence for customer security reviews, airline partner assessments, insurance questionnaires, and external audits or assessments
  • Administer the security awareness training program, including phishing simulation and completion tracking
  • Serve as the primary relationship owner for the MSP, managing escalations, scheduling, and day-to-day service delivery expectations
  • Monitor and report on contracted service levels, document breaches, drive root-cause analysis, and enforce contractual remedies where warranted
  • Chair quarterly business reviews with the MSP, setting the agenda, tracking commitments, and maintaining a running action log
  • Own the MSP contract lifecycle, including scope changes, renewals, pricing negotiation, and the exit and transition plan
  • Verify that MSP-operated controls function as contracted, requiring evidence rather than assertion
  • Govern access administration performed by the MSP, including joiner/mover/leaver execution, privileged access review, and periodic user access certification
  • Maintain the responsibility assignment matrix (RACI) that defines which controls the MSP operates, which Landline operates, and which are shared
  • Operate the vendor intake and security review process for new technology purchases
  • Maintain the vendor inventory with data classification, criticality tiering, and review cadence
  • Collect and review third-party assurance artifacts (SOC 2 Type II reports, ISO 27001 certificates, penetration test summaries), including analysis of complementary user entity controls and any qualified opinions
  • Track vendor contract security terms, breach notification obligations, and data processing agreements
  • Maintain the incident response plan and coordinate the annual tabletop exercise
  • Serve as compliance lead during security incidents, covering evidence preservation, regulatory notification analysis, and post-incident reporting
  • Maintain business continuity and disaster recovery documentation, and coordinate annual restoration testing with the MSP
  • Deliver a recurring compliance and vendor performance report to executive leadership
  • Provide security and compliance input to procurement, legal, and operations
  • Track and report program metrics
What We're Looking For
  • Five or more years in IT compliance, information security, IT audit, or IT governance, including at least two years with direct responsibility for a control program or audit function
  • Hands-on experience implementing or operating a recognized security framework (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or equivalent)
  • Experience administering or serving as a primary user of a GRC or compliance automation platform (Vanta, Drata, Secureframe, LogicGate, AuditBoard, ServiceNow GRC, or equivalent)
  • Experience managing or formally overseeing an outsourced IT provider, including service level monitoring and escalation
  • Working knowledge of core IT controls: identity and access management, endpoint management, logging and monitoring, vulnerability management, backup and recovery, and change management
  • Ability to read a SOC 2 Type II or similar report critically, including scope boundaries, exceptions, carve-outs, and complementary user entity controls
  • Clear written communication, as this role produces documentation that external parties read and rely on
  • Professional certification such as CISA, CRISC, CISM, or CISSP is a plus
  • Direct NIST CSF 2.0 implementation experience, particularly the Govern function and cybersecurity supply chain risk management (GV.SC), is a strong plus
  • Experience in transportation, aviation, logistics, or another operationally regulated industry is a plus
  • Familiarity with PCI DSS, CCPA/CPRA, or state breach notification requirements is welcome
  • Prior experience building a compliance program from an early or undefined baseline is valued
  • ITIL foundation or an equivalent service management background is a plus
  • Contract negotiation experience with technology vendors or service providers is a plus
Location

Remote in a major metro area in Canada or the United States, with business travel as needed

Compensation

120,000-175,000

Why Landline
  • Help build the infrastructure that decentralizes the airport and enables travel to begin anywhere
  • Work on first-of-their-kind concepts at the intersection of aviation, transportation, and infrastructure
  • Direct exposure to senior leaders across airlines, airports, and public-sector partners
  • A highly engaged, fast-moving team shaping a new model for how people travel
  • Significant opportunity for growth as the company scales
Benefits
  • Comprehensive benefits and PTO plan including medical, dental, vision, 401(k), disability, parental leave, and company-paid life insurance
  • Flight benefit privileges with our airline partners
  • Discretionary PTO
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, Marketing & Branding
Senior Manager, Marketing & Branding

Tusk • United States

On-site
USD 90,000 - 110,000
Medical, dental, and vision insurance
401(k) plan
Paid time off
+1
Fleet Manager
Fleet Manager

Landline Company • Falls Township (PA)

Remote
USD 90,000 - 120,000
401(k) plan
Paid time off
Flight benefits
+1
Motorcoach Fleet Manager
Motorcoach Fleet Manager

Landline Company • Fort Collins (CO)

On-site
USD 90,000 - 120,000
401(k) plan
Paid time off
Flight benefits with airline partners
+1
Motorcoach Fleet Manager
Motorcoach Fleet Manager

The Landline Company • Fort Collins (CO)

On-site
USD 90,000 - 140,000
401(k) plan
Paid time off
Flight benefits
+1
Operations Analyst / Industrial Engineer
Operations Analyst / Industrial Engineer

Tusk • United States

Remote
USD 80,000 - 120,000
Medical, dental, and vision insurance
401(k) plan
Paid time off
+2
Fleet Manager New York, NY, Fort Collins, CO and 3 others Fleet Manager opening
Fleet Manager New York, NY, Fort Collins, CO and 3 others Fleet Manager opening

Landline Co. • Northern (KY)

On-site
USD 90,000 - 120,000
401(k) plan
Paid time off
Flight benefits
+1
Operations Analyst / Industrial Engineer
Operations Analyst / Industrial Engineer

The Landline Company • United States

On-site
USD 90,000 - 130,000
401(k) plan
Paid time off
Flight benefits
+1
Manager, Networking - Core Networking
Manager, Networking - Core Networking

Forward Air Corp. • Coppell (TX)

On-site
USD 150,000 - 190,000
Competitive base pay
Health insurance
401(k) match
+2
Remote IT Compliance & Vendor Management Lead
Remote IT Compliance & Vendor Management Lead

Tusk • United States

Remote
USD 120,000 - 175,000
Senior Managing Consultant, Environmental Services
Senior Managing Consultant, Environmental Services

Landrum & Brown, Incorporated • Santa Monica (CA)

Hybrid
USD 160,000 - 180,000