Senior Manager, Security & IT Ops
Department: Management
Employment Type: Permanent - Full Time
Location: Remote, United States
Description
We need a hands-on security and internal IT leader who will set direction and step in to do the work. This person will lead company-wide security governance and compliance and make sure employees have reliable, secure technology. The role reports to the executive responsible for all post-sales operations.
This role will manage a small team and may also oversee contractors or outside service providers.
Responsibilities include setting priorities, coaching and developing team members, managing performance, and building the capabilities needed as the function grows.
Day-to-day, this person will create practical policies and safeguards, raise important risks, and directly manage identity, privileged access, critical software, and internal systems when no clear owner exists.
The role will name primary and backup owners, make technical and business responsibilities clear, and recommend investments. Finance, Procurement, Legal, and business leaders will keep formal approval authority for contracts and spending.
This is primarily an internal role, with customer contact when security expertise is helpful. Engineering owns secure product design and fixes. Cloud SRE and Engineering own customer-production reliability, monitoring, deployments, infrastructure-as-code, upgrades, and on-call work. Customer-facing teams own
routine customer delivery.
WHAT YOU’LL DO
-
Set the company's security direction. Own the security plan, information security management system (ISMS), risk register, policies, control ownership, exceptions, annual policy updates, leadership reporting, and ongoing improvement of the company's security and regulatory standing.
-
Keep audits and compliance work on track. Be the main contact for external auditors and lead annual SOC 2 Type II and ISO 27001 work from readiness through final reports. Keep Secureframe, evidence, findings, corrective actions, and quarterly reviews of user access, firewall settings, and risk controls current.
-
Find risks and make sure they are addressed. Run regular security risk assessments, identify weaknesses in business processes, and work with IT, Cloud SRE, and Engineering Operations on practical fixes. Track security patches and bug fixes against required compliance deadlines.
-
Protect access to company systems. Manage access when people join, change roles, or leave. Apply role-based access, least privilege, separation of duties, and regular reviews; keep clear records of root, administrator, service, and shared accounts; and handle critical access work until a lasting owner or automated process is in place.
-
Manage vendor security risk. Assess new and existing vendors, keep administrator and backup-owner records current, track ownership changes, and rate risk based on the sensitivity of company and customer data. Work with the appropriate business teams on due diligence, renewals, use, and exit planning.
-
Make internal IT dependable and easy to use. Create clear ways for employees to ask for help, set response expectations, document how systems are managed, maintain ownership and transition plans, and track service quality. Personally handle or oversee important administrative work until a lasting owner is in place.
-
Guide internal cloud and technology spending. Set clear security and ownership expectations for internal AWS, Google Cloud, Azure, Kubernetes, VPN/SASE, domains, DNS, shared operational channels, logging, and monitoring. Review costs, unused resources, commitments, and whether work belongs with an internal team or a service provider.
-
Prepare the company for incidents and disruptions. Maintain clear response plans, escalation paths, communications, exercises, follow-up actions, and alerting practices for security and internal IT incidents. Work with Engineering and Cloud SRE on customer-impacting events and review the Business Continuity Plan annually against customer commitments.
-
Help customers understand and trust our security. Work with Sales and Legal on customer and prospect security or vendor questionnaires, and join customer conversations about assurance, risk, incidents, or escalations when security leadership is needed.
-
Contribute to the AI Governance Committee. Participate as a contributing member and bring security, privacy, responsible-use, access, vendor-risk, and operational perspectives to reviews of proposed AI tools and current uses. Help the committee create practical guidance, record decisions and exceptions, and check that agreed actions are completed. Business and technical owners remain accountable for their AI solutions.
-
Show meaningful progress in the first year. Within 12 months, establish an approved security plan, clear control ownership, a dependable audit rhythm, an internal IT service model, an ownership register, a privileged-account inventory, internal-cloud standards, and agreed transition or sourcing plans for important gaps.
WHAT YOU HAVE
-
Experience leading across a company. You have owned a company-wide security, compliance, internal IT, or technology-risk program in a cloud or software company. You can influence leaders and lead a small team, contractors, or service providers while staying close to the work.
-
Hands-on audit and compliance experience. You have directly led ISO 27001 and SOC 2 Type II work, external audits, evidence gathering, policy reviews, findings, corrective actions, control reviews, and customer assurance.
-
Sound risk and resilience judgment. You understand privacy and data protection, business-process and vendor risk, vulnerability and patch management, incident response, business continuity, and compliance deadlines.
-
Technical confidence. You can work comfortably with identity, business software, AWS, Google Cloud, Azure, Kubernetes, networking, firewalls, VPN/SASE, domains, DNS, logging, monitoring, and privileged access.
-
Ability to bring order to unclear work. You have stepped into work with no clear owner, protected continuity, documented what matters, clarified responsibilities, and moved work to the right internal team or service provider.
-
Clear and inclusive communication. You can explain risks and choices to executives, auditors, technical and business teams, customers, and prospects, and can work with Sales and Legal on security questionnaires.
-
Education or equivalent experience. A bachelor's degree in Computer Science, Information Security, Information Systems, or a related discipline, or equivalent practical experience, is preferred.
-
Helpful credentials and experience. CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, or a similar certification is helpful. Experience in a distributed company, responsible AI governance, technology cost management, or vendor commercial management is also valuable.
BENEFITS
- Unlimited PTO
- Medical/Dental/Vision Insurance
- HSA/FSA
- Basic & Supplemental Life & AD&D insurance
- Short & Long-term Disability Insurance
- 401k
- EAP (Employee Assistance Program)