We are seeking a hands-on and pragmatic security leader to oversee our information security program. You will ensure our systems, employees, and data remain secure while aligning risk management with business priorities. Youll lead compliance initiatives, drive security awareness, and embed security into company processes without slowing down innovation.
What you'll be doing:
Own and evolve the companys information security strategy aligned to business objectives.
Lead security operations: incident response, vulnerability management, IAM, and vendor risk assessments.
Ensure compliance with SOC 2, ISO 27001, and other customer/partner security requirements.
Partner with Product & Engineering to integrate security by design.
Manage relationships with security vendors, auditors, and consultants.
Conduct regular employee security training and awareness campaigns.
Report on risks, metrics, and posture to the executive team and board.
Build and mentor a small security function (team or outsourced model).
Requirements: 7+ years of experience in Information Security with at least 3+ years in a leadership role.
Hands-on experience with security operations, GRC frameworks, and cloud security (AWS, GCP, or Azure).
Proven track record managing SOC 2 / ISO 27001 audits.
Strong communication skills with the ability to balance business risk and technical depth.
Prior experience in SaaS or B2B technology companies preferred.
This position is open to all candidates.