We're looking for a Senior Manager of Information Security to lead and mature our security program at a critical inflection point. We've already achieved ISO 27001 and SOC 2 Type 1 certifications — the foundation is in place. Now we need a hands-on leader who can turn that foundation into a durable, well-run program: formalizing policies and procedures, building a high-functioning security team, and protecting our infrastructure, networks, cloud environments, and applications — all without slowing down the engineers and developers who build our products.
This is not a "policy for policy's sake" role. You'll be the person who makes security a natural part of how we build software, not an obstacle to it.
Responsibilities:
Program & Governance
- Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
- Author, formalize, and maintain the policies, standards, and procedures required to close any remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor/third-party risk, change management, business continuity, etc.).
- Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
- Manage relationships with external auditors, pen testers, and compliance partners.
Security Engineering & Operations
- Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end.
- Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response.
- Establish and continuously improve secure SDLC practices — threat modeling, secure code review, dependency and supply-chain security, CI/CD pipeline security.
- Own incident response: build the plan, run tabletop exercises, and lead the response when needed.
- Lead, coach, and develop security team — establishing clear roles, workflows, and a sense of ownership.
- Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
- Define how the team engages with Engineering and Product (embedded reviews, self-service tooling, clear SLAs) to minimize friction and rework.
Cross-Functional Partnership
- Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership.
- Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no."
- Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage.
Qualifications:
- Bachelor's degree in Information Security, Computer Science, Computer Engineering or related field or equivalent work experience.
- 6-8+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
- Direct experience operating within (not just achieving) ISO 27001 and SOC 2 frameworks — you know what "audit-ready" looks like day to day, not just at renewal time.
- Strong technical depth in cloud security (AWS/GCP), network security, and modern application security (SDLC, AppSec tooling, container/Kubernetes security a plus).
- Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment.
- A track record of leading security teams that engineers actually like working with — you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates.
- Experience managing external auditors, penetration testers, and compliance vendors.
- Excellent communication skills — able to flex between a whiteboard session with engineers and a risk briefing with the board.
Nice to Have:
- CISSP, CISM, or similar certification.
- Experience implementing or operating under ISO 27701 (privacy extension to 27001) and the NIST Cybersecurity Framework (CSF).
- Experience in a company of similar size/stage (post-certification, scaling team).