Manager of Information Security

Clasp

United States

Remote

USD 170,000 - 190,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Student loan repayment benefits
401k matching
Commuter benefits
Flexible PTO policy
Opportunities to grow and perform in a

Job summary

Clasp is seeking a Manager of Information Security to own and drive a comprehensive security program in a remote role serving US-based operations. You will partner with CTO and AI Labs to harden our SOC 2 posture, cloud security, and secure development practices while coordinating with IT/TechOps and external auditors.

You will mentor the security team, influence engineering practices, and build scalable tooling to automate risk management and compliance in an AI-driven fintech environment.

Qualifications

  • CISSP certification required.
  • 5+ years on a security team.
  • Startup experience preferred.
  • Experience with SOC 2 or ISO 27001 compliance.
  • Technical foundation via degree or hands-on work.
  • Experience with AI tooling and prototyping is a plus.
  • Excellent communication with customers, auditors, and teams.

Responsibilities

  • Lead SOC 2 program and governance, evolve information security policies, manage Vanta, and participate in risk/compliance committees.
  • Head IT/TechOps and collaborate across corporate IT, security, onboarding, SaaS vendor management, incident response, and data loss prevention.

Skills

CISSP
5+ years on security team
Startup experience
SOC2/ISO27001 compliance
Technical foundation
AI tooling instinct
Strong communicator

Education

Bachelor's degree in Information Systems or similar

Job description

Manager of Information Security

Team: Information Security

Reports to: CTO

Location: Remote (US, EST/CST hours)

Manages: IT/TechOps (1)

About Us

Clasp is a Forbes Fintech 50, SHRM-backed company tackling two hard problems at once: helping employers attract and retain talent in critical fields, and easing the student debt crisis. We're at a Series B inflection point, growing fast, with enterprise customers and partner banks who hold us to a high security bar.

Why This Role

We're an AI-first company with a genuinely strong technical team and solid foundations already in place including a running SOC 2 program, a modern GCP infrastructure, a well-managed macOS/Windows fleet, and an engineering culture that ships. Your mission is to take ownership of the information security program, lead our Information Technology team, and pair with engineering leadership and AI Labs on the deep technical work.

This is the rare security role reporting to the CTO where you get real ownership on day one without inheriting a mess. If you're the kind of security leader who'd rather stand up a SIEM, harden a Terraform pipeline, and build your own tooling than manage a stack of vendors, this role was built for you.

What you'll own
  • SOC 2, Vanta & governance. Run our SOC 2 program end to end, own evolution of our Information Security policies, own our Vanta instance, run events such as business continuity drills, and represent information security in our Risk + Compliance committee.

  • IT/TechOps. Lead and collaborate with our IT/TechOps team across corporate IT and security: laptop procurement, MDM, onboarding/offboarding, SaaS vendor management and hardening, incident response, data loss protection, and more. Together you'll set direction and grow the function and the team as we scale.

  • Vendor diligence & security questionnaires. Own third-party security reviews, and be the front line for inbound customer and partner-bank security questionnaires

  • SIEM, Vulnerability Management & IDS. Configure our SIEM, build the alerting that gives us real signal without noise, and manage vendor relationships for real proactive visibility and risk reductions.

  • Cloud & access security (GCP). Pair with technical leaders to advance our cloud posture, IAM (JIT privilege escalation, group-based access), and platform hardening.

  • AppSec & secure SDLC. Partner with engineering to advance secure SDLC in a rapidly changing agentic world. Ensure dependency and vulnerability scanning is effective, CI/CD and pipelines are hardened, and new features have robust threat modeling.

  • AI security agents. Work with the CTO and AI Labs to run build vs buy analysis for all categories of agentic security work: detection/triage, evidence collection, questionnaire drafting, access reviews and more. Additionally, ensure all other deployed agents operate securely..

How we think about security in the age of AI

The security landscape in 2026 is changing fast. We want to implement best-of-breed vendors and roll up our sleeves to engineer in-house solutions when it makes the most sense. We don’t want to just throw head count or complex solutions at a problem that can instead be automated and configured in depth to be more resilient than brittle commercial solutions. You'll be hands-on and genuinely exhilarated to work closely with our technical teams to build and maintain internal security capabilities across SIEM, IDS, and more.

What we're looking for
  • CISSP certification.

  • 5+ years on a security team.

  • Startup experience — you've worked somewhere scrappy, not only at large/mega companies.

  • Compliance in the room — you've been at a company that achieved SOC 2 or ISO 27001.

  • A technical foundation — a semi-technical degree (Information Systems or similar) or a few years of hands‑on technical work (scripting, web development, automation, data analysis, etc.).

  • AI builder's instinct — comfortable scripting, prototyping, and using AI and modern tooling to solve problems efficiently.

  • Strong communicator — credible and clear with customers, partner banks, auditors, and internal teams.

You’ll be customer and regulator facing. If you're earlier in your leadership journey, that's fine as we'll back you with coaching and support on the tough calls.

Nice to have
  • Fintech, lending, or other regulated / high-trust experience.

  • Hands‑on GCP security depth (AWS experience also welcome).

  • Stood up or owned a SOC 2 program from scratch.

  • Experience fielding diligence from partner banks or enterprise customers.

What we give in return
  • Competitive cash and equity compensation

  • Health benefits (health, dental, & vision)

  • Student loan repayment benefits

  • 401k matching

  • Commuter benefits

  • Flexible PTO policy

  • Opportunities to grow and perform in a fast-paced environment alongside a stellar team

Salary

The salary range for this position is competitive and will be commensurate with the candidate's experience, qualifications, and industry knowledge, ranging between $170,000 - $190,000 annually. In addition to the base salary, we offer an attractive equity component as part of our compensation package, providing an opportunity for eligible employees to share in the success and growth of our company. We are committed to offering competitive compensation and benefits packages to attract and retain top talent.

Closing

If you are a driven engineer with a passion for building systems that meaningfully serve the people who rely on them, we want to hear from you. Join us in reshaping how schools support their students and making a lasting impact on the future of higher education financing.

We are committed to creating a diverse and inclusive workplace where all employees feel valued, respected, and empowered to contribute their unique perspectives and talents. Clasp is an equal opportunity employer and prohibits discrimination and harassment of any kind. We embrace diversity and are dedicated to providing equal employment opportunities to all individuals regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Fullstack Software Engineer, (Clasp Talent)
Fullstack Software Engineer, (Clasp Talent)

clasp-group • Boston (MA)

Hybrid
USD 100,000 - 145,000
Competitive cash and equity compensation
Health benefits (medical, dental, vision)
Flexible PTO policy
+1
Staff+ Software Engineer, Security Infrastructure
Staff+ Software Engineer, Security Infrastructure

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare programs
Vision, dental coverage
HSA/FSA contributions
+8
Staff+ Security Engineer, Developer Tools
Staff+ Security Engineer, Developer Tools

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Mental health support
Parental leave
+3
Staff+ Security Engineer, Core Command
Staff+ Security Engineer, Core Command

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare programs
Medical/Vision/Dental coverage
HSA with employer contributions
+7
Principal Engineer, Security
Principal Engineer, Security

United States Digital Space LLC • Boston (MA)

On-site
USD 244,000 - 366,000
Security Lead
Security Lead

Taktile • United States

On-site
USD 180,000 - 260,000
Equity package
Competitive compensation
Self-development budget
+1
Software Engineering Manager, Data Protection Platform
Software Engineering Manager, Data Protection Platform

United States Digital Space LLC • San Mateo (CA)

On-site
USD 250,000 - 350,000
Healthcare programs
Vision and dental coverage
HSA with employer contributions
+3
Director of Security Architecture & Engineering
Director of Security Architecture & Engineering

MultiPlan • McLean (VA)

On-site
USD 175,000 - 220,000
Staff Software Engineer - Detection and Response Platform
Staff Software Engineer - Detection and Response Platform

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Mental health support
Parental leave
+4
Senior Corporate Security Engineer
Senior Corporate Security Engineer

United States Digital Space LLC • Bellevue (CA)

Hybrid
USD 166,000 - 195,000
Health insurance
Equity ownership
401(k) matching
+2