Security Program Manager (ISO 27001 & SOC 2) — GRC Lead

Flexhire

United States

On-site

USD 140,000 - 190,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TinyFish is hiring a Senior Security Program Manager to run security and compliance as a program. You will own the operational backbone — audits, evidence collection, policy lifecycle, vendor risk, and customer security reviews — enabling the Security Lead to focus on architecture and threat work.

This IC role reports to the Staff Program Manager and is the first dedicated security program owner in the org, aligning enterprise deals with security requirements.

Qualifications

  • 4-7 years in security or GRC program management, ideally in B2B SaaS.
  • Experience running ISO 27001 and SOC 2 audits end-to-end, including auditor management.
  • Fluency with Vanta (or Drata/Tugboat) and ability to compensate manually where needed.
  • Comfort presenting to customer security teams and instilling confidence in the program.
  • Strong written communication and sound judgment on control gaps.
  • Ability to escalate issues quickly to the right audiences.

Responsibilities

  • Compliance lifecycle: maintain ISO 27001, prep for SOC 2 Type 1 & 2, manage auditors, collect evidence in Vanta.
  • Vulnerability management: own SLA dashboard, breach escalation, exception tracking; ensure timely fixes.
  • Policy lifecycle: annual reviews, policy updates, training rollout, attestation tracking.
  • People-ops security controls: onboarding/offboarding evidence, access reviews, training, background checks.
  • Vendor risk: inventory, pre-procurement assessments, re-assessments, DPA tracking.
  • Customer-facing security: questionnaires, CAIQs, RFPs, security calls; named SPM in trust center.
  • Policy update cadence for terms and privacy; cross-functional collaboration.
  • Risk and incident program ownership: maintain risk register, run quarterly reviews, run tabletop exercises.

Skills

Security program management
ISO 27001 / SOC 2
Vendor risk management
Security audits & evidence collection
Policy lifecycle & controls
Customer security reviews

Tools

Vanta
Drata
Tugboat

Job description

TinyFish is hiring a Senior Security Program Manager to run security and compliance as a program. You will own the operational backbone — audits, evidence collection, policy lifecycle, vendor risk, and customer security reviews — enabling the Security Lead to focus on architecture and threat work.

This IC role reports to the Staff Program Manager and is the first dedicated security program owner in the org, aligning enterprise deals with security requirements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Program Manager
Senior Security Program Manager

Flexhire • United States

On-site
USD 140,000 - 190,000
Remote Security Compliance Leader GRC & Audit
Remote Security Compliance Leader GRC & Audit

Sardine • Northern (KY)

Hybrid
USD 140,000 - 210,000
Generous compensation
Remote-first culture
Health insurance
+5
Security Program Manager: Enterprise GRC & Audit Lead
Security Program Manager: Enterprise GRC & Audit Lead

Lennar • Miami (FL)

On-site
USD 120,000 - 180,000
Health insurance
401(k) match
Paid parental leave
+3
Security & Compliance Manager | ISO/NIST/GRC Lead
Security & Compliance Manager | ISO/NIST/GRC Lead

Cambium Learning Group • United States

Remote
USD 120,000 - 180,000
Remote Security Compliance Lead (SOC 2, PCI)
Remote Security Compliance Lead (SOC 2, PCI)

Mixpeek • Northern (KY)

Hybrid
USD 140,000 - 220,000
Remote-first culture
MacBook Pro delivered to your door
Home office stipend
Remote Security Program Manager - GRC & Compliance Lead
Remote Security Program Manager - GRC & Compliance Lead

Rhymetec • United States

On-site
USD 120,000 - 150,000
No cost medical coverage
Dental and Vision Benefits
PTO and Sick Time
+5
Senior InfoSec GRC Lead – ISO 27001 & SOC 2
Senior InfoSec GRC Lead – ISO 27001 & SOC 2

Camunda • United States

Remote
USD 127,000 - 205,000
Remote work
Annual kickoff events
Health & wellbeing program
+3
Senior GRC Project Manager: ISO 27001 & Security Programs
Senior GRC Project Manager: ISO 27001 & Security Programs

Machine Intelligence Technologies, LLC • Atlanta (GA), Northern (KY)

Hybrid
USD 120,000 - 160,000
GRC Program Manager: Scale Compliance & Risk
GRC Program Manager: Scale Compliance & Risk

Palantir Technologies • Seattle (WA)

On-site
USD 90,000 - 160,000
Medical insurance
401(k) plan
Paid time off
Senior GRC Engineering Leader — Special Programs
Senior GRC Engineering Leader — Special Programs

Workstreet, Inc. • United States

On-site
USD 150,000 - 210,000
Career Development
Technical Training
Competitive Compensation
+2