Security & Compliance Lead

Glimpse

New York (NY)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary with meaningful equity
In-person team in NYC
Direct impact on company growth
Opportunity to shape operational processes

Job summary

Glimpse, a fast-growing AI platform for CPG brands based in New York, is hiring its first Security & Compliance Lead. This role offers high autonomy and ownership, focusing on building a security program from scratch.

Responsibilities include managing access and identity, overseeing SOC 2 compliance, and ensuring customer trust. Ideal candidates will possess 5+ years in security, experience with audits, and familiarity with cloud environments.

Join us to shape how hundreds of CPG brands run their back office!

Qualifications

  • 5+ years in security or security-adjacent roles.
  • Experience driving a SOC 2 audit.
  • Comfortable in cloud environments and able to automate workflows.

Responsibilities

  • Oversee access and identity management processes.
  • Manage SOC 2 program and customer trust initiatives.
  • Implement infrastructure security measures.

Tools

AWS
GCP
Azure
Terraform
Okta
AWS IAM Identity Center
Teleport
ConductorOne
Vanta
Drata
Secureframe

Job description

ABOUT GLIMPSE

Glimpse is the leading AI platform for CPG brands — automating critical back-office workflows like deductions management, revenue recovery, and cash application. Since launching in April 2024, we've grown from 0 to 200+ customers, raised $52M from investors including a16z, 8VC and Y Combinator.

Our AI agents retrieve deduction data, validate charges, automate cash application, and dispute invalid claims — work that would take a full-time employee years to complete. For a $1B CPG brand, a single Glimpse agent reviewed 17,000 deductions in under 24 hours, identifying over $10M in recoverable revenue.

We're building the next-generation suite of services for consumer brands and are looking for exceptional people to help us scale.

About the role

We're a fast-growing startup with a small but talented engineering team, and we're hiring our first Security & Compliance Lead to build the foundation for our security program. This is a high-ownership, high-autonomy role with a broad mandate: you'll own the security and compliance surface end-to-end, from access management and SOC 2 to infrastructure security and customer trust.

You’ll report to CTO with full ownership of the security and compliance domain.

In year one, the work skews toward access management, SOC 2, and customer-facing security. Over time, the role grows into broader security engineering: monitoring, incident response, vendor risk, and architecture review.

If you've built a security program from scratch before and liked it, you'll recognize this job. If you want to build something from the ground up rather than slot into an existing program, read on.

What you'll own

Access & identity management. Production access, service accounts, SSO, and the lifecycle of both - provisioning, periodic review, deprovisioning.

SOC 2. You’ll own the program end-to-end, mapping controls to our environment, driving evidence collection, and getting us through Type 1 and then Type 2 and other security frameworks.

Customer trust. You’ll own security questionnaires, RFP security sections, and the customer‑facing trust narrative (trust center, security overview docs, DPAs).

Infrastructure security. VM lifecycle and patching, baseline hardening, secrets management, vulnerability management, and cloud security posture.

Security engineering (over time). Logging and monitoring, incident response runbooks, vendor security reviews, and partnering with engineering on secure design.

What we’re looking for
  • 5+ years in security or security‑adjacent roles

  • You’ve driven a SOC 2 audit - ideally owned one end-to-end, but if you ran the bulk of a program under a fractional CISO or security leader, that counts

  • Comfortable in cloud environments (AWS, GCP, or Azure) and writing enough code or Terraform to automate access and infrastructure workflows

  • You’ve owned customer security questionnaires and know how to make them faster

  • Strong written communication

Nice to have
  • A previous tour as the first or early security hire at a startup

  • Experience with identity tooling (Okta, AWS IAM Identity Center, Teleport, ConductorOne)

  • Experience with compliance platforms (Vanta, Drata, Secureframe)

  • Other frameworks beyond SOC 2 (ISO 27001, HIPAA, FedRAMP)

  • Background in security engineering, detection, or incident response

Traits that do well here
  • High ownership: you don’t just advise - you drive the work to completion.

  • Systems thinking: you can reason about messy workflows and design something scalable, not one‑off.

  • Customer empathy + backbone: you listen deeply, then confidently set boundaries and callout tradeoffs.

  • Fast learner: you ramp into new domains and tools quickly.

WHY JOIN GLIMPSE

You’ll join a company that has found genuine product‑market fit and is scaling fast — with the infrastructure, capital, and team to match. Your work will directly shape how hundreds of CPG brands run their back office. And you’ll have real ownership: of your accounts, your outcomes, and the AM function itself as we build it from the ground up.

  • Competitive salary with meaningful equity

  • In‑person team in NYC – high ownership, fast feedback loops

  • Direct impact on a company growing at an exceptional pace

  • A front‑row seat to building the operating system for CPG brands

Location

Prime Midtown location — Penn Station, Madison Square Garden, and the city's best transit connections right at your door. *Moving to a new location in August

GLIMPSE is an Equal Employment Opportunity Employer. GLIMPSE will consider all qualified applicants for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, marital status, disability, veteran status or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevOps Engineer
DevOps Engineer

CAPSULE • New York (NY)

On-site
USD 170,000 - 210,000
Competitive salary
Equity
In-person NYC team
+1
Customer Success Engineer
Customer Success Engineer

glimpse • New York (NY)

On-site
USD 80,000 - 110,000
Competitive salary with meaningful equity
Direct impact on company growth
Fast feedback loops in NYC team
Community Associate
Community Associate

CAPSULE • New York (NY)

On-site
USD 60,000 - 80,000
Competitive salary
Equity options
High ownership environment
Deployment Strategist
Deployment Strategist

CAPSULE • New York (NY)

On-site
USD 140,000 - 210,000
Competitive salary + meaningful equity
In-person team in NYC
Deployment Strategist
Deployment Strategist

Glimpse • New York (NY)

On-site
USD 120,000 - 180,000
Competitive salary + equity
In-person NYC team
Direct impact on growth
+1
Security & Compliance Lead - SOC 2, Cloud Security, Trust
Security & Compliance Lead - SOC 2, Cloud Security, Trust

Glimpse • New York (NY)

On-site
USD 120,000 - 160,000
Competitive salary with meaningful equity
In-person team in NYC
Direct impact on company growth
+1
Deduction Analyst
Deduction Analyst

Glimpse • New York (NY)

On-site
USD 85,000 - 125,000
Equity
In-person NYC team
Deduction Analyst
Deduction Analyst

CAPSULE • New York (NY)

On-site
USD 80,000 - 120,000
Competitive salary with meaningful eq​
In-person team in NYC
Direct impact on a fast-growing start‑
GTM Recruiter
GTM Recruiter

Dime Campus, Inc. • New York (NY)

On-site
USD 120,000 - 170,000
Competitive salary
Meaningful equity
In-person NYC team
+2
GTM Recruiter
GTM Recruiter

Glimpse • New York (NY)

On-site
USD 90,000 - 130,000
Equity
In-person team in NYC