VP, Infrastructure and Security

floatme

San Antonio (FL)

On-site

USD 210,000 - 320,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

FloatMe seeks a VP of Infrastructure and Security to own and elevate our infrastructure strategy and security program. This hands-on leader will drive SOC 2 compliance, secure our cloud and on-prem environments, and partner with Product, Engineering, Finance, and Legal to embed security into every initiative.

The role requires deep practical experience across GLBA/PCI DSS, incident response, and threat management, with the ability to communicate risk to executives and bank partners.

Qualifications

  • 10+ years in information security with at least 2 years in a senior IC or leadership role.
  • Demonstrated hands-on experience leading SOC 2 Type I/II audits from scoping through certification.
  • Practical knowledge of GLBA, PCI DSS and other financial services compliance requirements.
  • Direct experience managing bank partner or enterprise security reviews (e.g., SIG, CAIQ, VSA questionnaires).
  • Proficiency with cloud security (AWS and Cloudflare preferred), including IAM, VPCs, CloudTrail, GuardDuty, or equivalents.
  • Hands-on experience with penetration testing methodologies or managing third-party pen test engagements.
  • Strong working knowledge of SIEM, EDR, vulnerability management, and secrets management tooling.
  • Experience building and running an incident response program, including playbooks and tabletop exercises.
  • Excellent written and verbal communication skills.

Responsibilities

  • Steer the architecture of our Cloud, Device, Code, App, AI, and Network infrastructure with security-first designs.
  • Set direction for infrastructure design, security, integrations and partnerships (IT, Data, Security).
  • Serve as primary security point of contact for bank and fintech partners, completing security questionnaires and risk assessments.
  • Own SOC 2 Type II program end-to-end: scoping, control design, evidence collection, auditor management.
  • Maintain compliance posture across GLBA, PCI DSS and other frameworks.
  • Manage core security infrastructure: SIEM, EDR, WAF, IAM, secrets management, vulnerability scanning.
  • Conduct or manage penetration testing and drive remediation.
  • Lead incident response: triage, containment, forensics, post-incident review, breach notification.
  • Build security awareness training and phishing simulations across the company.
  • Review and negotiate security requirements in partner contracts.
  • Partner with Product, Engineering, Finance, and Legal to embed security.
  • Develop and maintain multi-year security roadmap and report posture to leadership.

Skills

Security leadership
Hands-on security
Compliance expert
Clear communicator
Builder and operator
Fintech security

Tools

AWS
Cloudflare
SIEM
EDR

Job description

About the Role

We're hiring a VP of Infrastructure and Security to own and elevate our infrastructure strategy and security program at FloatMe. This role is an exciting opportunity for a security leader looking to grow into a CISO position. The ideal candidate should be very hands-on, not just a "policy manager". We need someone who can sit in a compliance review one hour and be configuring security tooling themselves the next. Infrastructure - This candidate will have stewardship over our infrastructure including individual computer hardware, office infrastructure, cloud infrastructure, code security and infrastructure, app architecture and security, AI security, and critical partnerships architectures. Security - This candidate’s stewardship requires expertise in securing all of the above areas, help us pursue SOC2 compliance, and maintain the highest security for our users and staff. You’ll own our security roadmap, our compliance certifications, our partner security reviews, and the day-to-day technical operations that keep our members’ data safe. Hands-On Required - We’re a small, nimble team, which means this role requires the flexibility to switch gears between tactical execution and strategic planning. This role reports to our SVP of Engineering. If you’re excited to join a fast-moving fintech where you can build something meaningful, we’d love to hear from you!

What You’ll Do
  • Steer the architecture of our Cloud, Device, Code, App, AI, and Network infrastructure with a mind for security-first designs and plans.

  • Set the direction for a small number of our staff regarding our infrastructure design, security, integrations and partnerships, and more (IT, Data, and Security).

  • Serve as the primary security point of contact for our bank and fintech partners, completing security questionnaires, third-party risk assessments, and due diligence requests.

  • Own our SOC 2 Type II program end-to-end, including scoping, control design, evidence collection, and auditor management.

  • Maintain and strengthen our compliance posture across GLBA, PCI DSS, and other applicable financial services regulatory frameworks.

  • Manage and improve our core security infrastructure: SIEM, EDR, WAF, IAM, secrets management, and vulnerability scanning tools.

  • Conduct or manage regular penetration testing and vulnerability assessments, and drive remediation to closure.

  • Lead incident response efforts - including hands-on triage, containment, forensics, post-incident review, and breach notification processes.

  • Build and run security awareness training and phishing simulations across the company.

  • Review and negotiate security requirements in partner and vendor contracts.

  • Partner cross-functionally with Product, Engineering, Finance, and Legal to embed security into everything we build.

  • Develop and maintain our multi-year security roadmap and report security posture and risk to executive leadership.

Who You Are
  • A driver and an "owner", not a passenger - You make the plans for your area of ownership, you seek the buy-in you need, you propose the alternatives, you drive projects to completion, even if it means you do a big percentage of the work yourself. You will have support, but you will be getting "in the mud" with the rest of us.

  • A hands-on and self-driven security leader - You’re as comfortable writing a detection rule in your SIEM as you are presenting risk to the board. You don’t plan to delegate everything, hands-on as much as you can, and you don’t wait to be asked to own this space, you actually and truly must "own it" completely.

  • A compliance expert - You have deep, practical experience leading SOC 2 audits and navigating financial services frameworks like GLBA and PCI DSS. You know what auditors actually look for.

  • A skilled communicator - You can translate complex technical risk into plain language for bank partners, executives, and non-technical teammates. You’re a trusted voice in the room.

  • A builder and operator - You’re energized by building and improving things, not just inheriting them. You’re comfortable owning both strategy and execution simultaneously.

  • A collaborative team player - You work closely with engineering, product, and compliance without becoming a blocker. You protect the business without slowing it down.

  • Passionate about fintech - You understand the unique security and compliance landscape of consumer financial products and are excited about what we’re building.

Who You Are Not
  • An auditor or "paper pusher" - We need you to not only help us decide what security posture we need, but you will need to help implement that posture yourself. We’re a smaller but very effective team and really need this player to be very hands-on.

  • A recreational player - We are looking for someone hungry, competitive, and an impact player who can truly "cover" this area of our company, making us all sleep easier at night knowing that you have our security and infrastructure posture well-covered.

Requirements
  • 10+ years’ of progressive experience in information security, with at least 2 years in a senior IC or leadership role. Prior leadership experience in a role adjacent to "VP of Infrastructure and Security" preferred. The key here is that you can both be the thinker and leader we need, but also still feel very comfortable being hands-on.

  • Demonstrated hands-on experience leading SOC 2 Type I/II audits from scoping through certification.

  • Practical knowledge of GLBA, PCI DSS, and other financial services compliance requirements.

  • Direct experience managing bank partner or enterprise security reviews (e.g., SIG, CAIQ, VSA questionnaires).

  • Proficiency with cloud security (AWS and Cloudflare preferred), including IAM, VPCs, CloudTrail, GuardDuty, or equivalents.

  • Hands-on experience with penetration testing methodologies or managing third-party pen test engagements.

  • Strong working knowledge of SIEM, EDR, vulnerability management, and secrets management tooling.

  • Experience building and running an incident response program, including playbooks and tabletop exercises.

  • Excellent written and verbal communication skills - you can explain technical risk to non-technical stakeholders.

  • Experience in fintech, neobank, lending, or another consumer financial services environment strongly preferred.

  • CISSP, CISM, CISA, or equivalent certification are a plus.

Bonus points for willingness and capability to
  • Read and review, or automate the review of server-side code for security (Golang)

  • Read and review, or automate the review of apps-side code for security (Flutter)

FloatMe is proud to be an equal opportunity employer. FloatMe provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws, and prohibits discrimination and harassment of any type.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

floatme • San Antonio (FL)

On-site
USD 150,000 - 200,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

SpringTime Ventures • Town of Texas (WI)

On-site
USD 150,000 - 200,000
Head of Infra & Security — Hands-On FinTech Leader
Head of Infra & Security — Hands-On FinTech Leader

floatme • San Antonio (FL)

On-site
USD 210,000 - 320,000
Information Security Analyst & Technical Partner
Information Security Analyst & Technical Partner

Dingoblu Financial Inc • Charlotte (NC)

On-site
USD 65,000 - 90,000
Security Lead
Security Lead

Taktile • United States

On-site
USD 180,000 - 260,000
Equity package
Competitive compensation
Self-development budget
+1
Senior Platform Security Engineer
Senior Platform Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 160,000 - 260,000
Competitive Compensation
Meaningful Equity
Health Benefits
+5
Senior Software Engineer, Security
Senior Software Engineer, Security

Flex • Northern (KY)

Hybrid
USD 170,000 - 230,000
Security Engineer
Security Engineer

Coinflow • Chicago (IL)

On-site
USD 145,000 - 195,000
Health and wellness benefits
401(k) savings plan
Flexible time off
+1
Principal Security Engineer
Principal Security Engineer

Fintech Brand • Tampa (FL)

On-site
USD 90,000 - 120,000
Principal Security Engineer
Principal Security Engineer

Fintech • Tampa (FL)

On-site
USD 110,000 - 130,000