Allocate

Bringing better transparency and responsible participation to the private markets.

Information Security Lead

Security EngineerSecurity EngineerFull TimeRemoteTeam 51-200Since 2021H1B No SponsorCompany SiteLinkedIn

Location

California + 2 moreAll locations: California, New York, Massachusetts

Posted

48 days ago

Salary

$175K - $195K / year

Bachelor Degree5 yrs expExperience acceptedEnglish

Job Description

• Own and evolve the GRC program in partnership with Legal and our CCO • Lead all efforts to achieve and maintain critical compliance certifications (SOC 2, potentially ISO 27001) • Manage external SOC2 audits and coordinate with third-party auditors (currently 4-6 week intensive periods annually) • Conduct quarterly user access reviews and maintain comprehensive access control documentation • Develop, maintain, and enforce clear, practical security policies across all departments • Work cross-functionally with IT and HR to ensure consistent policy adherence • Monitor compliance with laptop MDM requirements, 2FA, policy attestations, and security training • Develop and execute a comprehensive information security roadmap aligned with business objectives • Lead the organization's migration to a Zero Trust security approach • Select, implement, and manage endpoint detection and response (EDR) solutions • Oversee relationship with our managed IT service provider • Conduct vendor security reviews, risk assessments, and ongoing monitoring • Develop and execute security awareness training programs for all employees

Job Requirements

  • 5+ years of experience in information security, with at least 2 years in a leadership or senior individual contributor role
  • Experience in fintech, banking, healthcare, payments, or other highly regulated industries
  • Proven track record managing SOC 2 compliance, including audit preparation and evidence gathering
  • Deep understanding of GRC frameworks and compliance requirements for fintech companies
  • Experience developing and enforcing security policies in a rapidly growing organization
  • Strong knowledge of endpoint security, including EDR solutions and mobile device management
  • Experience conducting vendor security assessments and managing third-party risk
  • Hands-on experience with security tools and technologies (SIEM, EDR, vulnerability management, etc.)
  • Demonstrated ability to work cross-functionally with Legal, HR, Engineering, and Product teams
  • Excellent written and verbal communication skills, with the ability to explain complex security concepts to non-technical stakeholders
  • Strong project management skills and ability to manage multiple initiatives simultaneously
  • Experience working with managed IT service providers or in-house IT teams
  • Ability to travel to our Palo Alto and/or NYC on a quarterly basis

Benefits

  • Medical
  • Dental
  • Vision
  • 401(k)
  • Responsible time off

Related Categories

Related Job Pages

More Security Engineer Jobs

Instructor, CompTIA Security+ 701

Full Stack Academy

We aim to transform fresh graduates into software professionals while also helping professionals upgrade their skills.

Security Engineer48 days ago
Part TimeRemoteTeam 11-50Since 2012H1B No Sponsor

Part-time Instructor for CompTIA Security+ at Simplilearn

United States
$50 - $55 / hour

Instructor, CompTIA Security+ 701, Simplilearn (Part time)

Full Stack Academy

We aim to transform fresh graduates into software professionals while also helping professionals upgrade their skills.

Security Engineer48 days ago
RemoteTeam 11-50Since 2012H1B No Sponsor

ABOUT SIMPLILEARN Simplilearn is the world’s #1 online Bootcamp provider, enabling learners around the globe with rigorous and highly specialized training offered in partnership with world-renowned universities and leading corporations. We focus on eme...

United States

Cyber Security Project Manager – Client Delivery Programmes, SC Cleared, Part Time

Resillion

Your global quality engineering and cyber security partner from initiation to launch.

Security Engineer48 days ago
Part TimeRemoteTeam 501-1,000H1B No Sponsor

Cyber Security Project Manager managing IT Health Check and Penetration Testing engagements

Cyber Security
South Carolina
$21K / year

Cyber Security Project Manager – Client Delivery Programmes – Must have Cyber Experience, SC Cleared

Resillion

Your global quality engineering and cyber security partner from initiation to launch.

Security Engineer48 days ago
Part TimeRemoteTeam 501-1,000H1B No Sponsor

Cyber Security Project Manager managing IT Health Check and Penetration Testing engagements

South Carolina
$21K / year