Take ownership of information security governance, including policies, risk registers, and control documentation.
Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
Lead incident response, compliance support, and serve as primary counterpart to the vCISO.
Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.
Lead the design and evolution of a multi-framework compliance offering for European businesses.
Drive end-to-end ISO 27001 implementations and manage a team of compliance specialists.
Act as a senior security partner to customers, sales, and product teams.
This company provides a security and compliance platform that helps modern businesses achieve certifications across frameworks like ISO 27001 and SOC 2. It is a fast-growing, remote-first technology environment with a strong emphasis on collaboration and team connection.
Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
Manage identity and access, device fleet, and vendor security with ownership over control state.
Drive compliance as a sales enabler and own the customer-facing security package.
Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.
Own and build Flodesk's security program end to end, including policies, controls, and governance.
Lead SOC 2, ISO 27001, and CCPA readiness while partnering with engineering on secure development.
Manage IT operations, vendor vetting, and security tooling to scale the program.
Flodesk is a fast-growing email marketing company that helps creators and small businesses design emails and monetize their email lists. It is a remote-first company with a globally distributed team and offices in San Francisco, Menlo Park, and Da Nang.
Act as Information Security Officer for FinTech, supporting ISO 27001, SOCv2, and DORA implementation.
Coordinate security activities across teams, ensuring alignment with cyber security strategy and governance.
Track risks, gaps, and remediation, while preparing updates for security leadership.
Coinspaid Dev is the engineering brand behind the technology and infrastructure built within Coinspaid. With over 120 engineers and 11 years of industry experience, the team builds distributed systems and blockchain infrastructure across more than 20 blockchain networks.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Independently execute endpoint security, identity management, and vulnerability remediation across Windows, macOS, Linux, and cloud platforms.
Monitor and analyze alerts within SIEM and EDR, conduct initial investigations, and escalate complex findings as needed.
Partner with IT, Engineering, DevOps, and IAM teams to maintain security controls and support compliance frameworks like SOC 2, HIPAA, and ISO 27001.
Accela is an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement, and enable the development of thriving communities. The company has been operating for nearly 20 years, fosters a diverse and inclusive culture, and is committed to equity and belonging.
Manage day-to-day security operational availability and supportability of a 24x7x365 infrastructure.
Make recommendations on enhancements to security hardware, software, and tools, and perform risk analysis.
Configure, implement, monitor, and support security software/systems including firewalls, VPNs, IDS/IPS, DLP, etc.
eMoney Advisor is a wealth management system that offers transparency, security, mobile access, and superior organization. We serve more than 109,000 financial professionals and support over 6 million end clients, fostering a culture that values diversity and inclusion.
Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.
Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.
Lead SOC 1 and SOC 2 examinations and support end-to-end SOX planning.
Partner with Security, Engineering, Data, and Finance to implement scalable IT controls.
Conduct controls assessments, drive remediation, and produce auditor-ready documentation.
Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions globally, offering spot trading, margin, futures, staking, and OTC services. Part of Payward, it is powered by people from around the world and celebrates diverse talents, backgrounds, and unique perspectives.
Improve perimeter and network-layer defenses (WAF, DDoS mitigation, anti-bot) and secure product APIs against abuse.
Manage vulnerability identification, prioritization, remediation, and coordinate external pentests.
Lead incident response, run the Security Champions program, and manage the Bug Bounty program.
Social Discovery Group (SDG) solves problems of loneliness, isolation, and disconnection by providing social entertainment platforms that connect people across cultures. The company is an international team of digital nomads working remotely worldwide and has been named a Great Place to Work (USA & Japan, 2024–2025).
Lead IT governance and risk management, including executive reporting and risk register maintenance.
Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
Oversee ITSM governance, ServiceNow optimization, and vendor risk management.
Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.
Lead enterprise cybersecurity strategy and operations across cloud and business systems.
Oversee IT operations, IAM, endpoint management, and ensure HIPAA compliance.
Manage vendor risk assessments and communicate technology strategy to executive leadership.
Luna delivers physical therapy in-home and virtually, combining healthcare with technology to improve patient outcomes. It is a high-growth company with a hands-on, collaborative culture focused on innovation and compliance.
Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.
Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.
Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
Answer customer security questionnaires and ensure compliance documents are accurate.
Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.
Lead vulnerability management and SOC 2 compliance across SaaS products and cloud infrastructure.
Harden Azure and Microsoft security tooling (Defender, Intune) and respond to security alerts.
Partner with engineering, IT, and legal to drive secure SDLC, policies, and customer security reviews.
HSP Group is a premier provider of global expansion services, helping companies with legal setup, HR, payroll, compliance, and tax across international markets. The company partners with scale-ups and innovative technology firms to reduce risk and scale faster, fostering a trusted-partner culture.
Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
Perform technical security and compliance reviews of third-party vendors and service providers.
iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.
Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.
Support day-to-day information security operations and maintain strong operational security posture across the platform.
Develop and maintain the System Security Plan and other cybersecurity documentation for security authorization and compliance.
Support FedRAMP High and DoD IL5 compliance activities including continuous monitoring, audits, assessments, and remediation.
The partner company operates a secure, mission-focused technology platform supporting government and commercial teams. It is an equal opportunity workplace committed to considering qualified candidates from all backgrounds.