Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.
Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.
Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.
Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.
Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.
Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.
Act as central contact for information security in the business group, working with development teams and customers.
Implement local ISMS, conduct risk analyses and security reviews.
Collaborate with corporate security and advise on practical security requirements.
Haufe provides digital research systems and software solutions, making complex professional knowledge easily applicable for over one million customers. It is a Great Place to Work® with cross-functional teams across Germany, Romania, and Spain.
Lead and mature the information security program, building on ISO 27001 and SOC 2 foundations.
Develop and operationalize security policies, risk management, and incident response.
Partner with Engineering and Product to integrate security into software development.
This is a partner company role managed by Jobgether, a platform that uses AI-powered matching to connect candidates with hiring companies. The partner is a rapidly scaling SaaS and cloud technology environment, with a growing security team and established ISO 27001 and SOC 2 programs.
Own and build the group-wide ISMS following BSI standards and ISO 27001 certification.
Manage risk, incident response, and security awareness across technical and organizational domains.
Work hands-on with IT and engineering teams, ensuring security governance and regulatory compliance.
Vektor Group builds AI platforms for customers in the defence and government sector. It is a startup with flat hierarchies, real ownership, and fast decisions.
Act as Information Security Officer for FinTech, supporting ISO 27001, SOCv2, and DORA implementation.
Coordinate security activities across teams, ensuring alignment with cyber security strategy and governance.
Track risks, gaps, and remediation, while preparing updates for security leadership.
Coinspaid Dev is the engineering brand behind the technology and infrastructure built within Coinspaid. With over 120 engineers and 11 years of industry experience, the team builds distributed systems and blockchain infrastructure across more than 20 blockchain networks.
Take ownership of information security governance, including policies, risk registers, and control documentation.
Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
Lead incident response, compliance support, and serve as primary counterpart to the vCISO.
Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.
Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.
Own internal audits end-to-end for customers, from kickoff to final report.
Review and sample evidence against ISO 27001 controls and communicate findings clearly.
Manage multiple audits simultaneously while keeping them on schedule and improving framework content.
Secfix automates security compliance for European companies (ISO 27001, GDPR, TISAX, SOC 2). The 100% remote team with hubs in Munich, Berlin, and London is high-performing and backed by top VCs after raising a $12M Series A.
Own and build Flodesk's security program end to end, including policies, controls, and governance.
Lead SOC 2, ISO 27001, and CCPA readiness while partnering with engineering on secure development.
Manage IT operations, vendor vetting, and security tooling to scale the program.
Flodesk is a fast-growing email marketing company that helps creators and small businesses design emails and monetize their email lists. It is a remote-first company with a globally distributed team and offices in San Francisco, Menlo Park, and Da Nang.
Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
Manage identity and access, device fleet, and vendor security with ownership over control state.
Drive compliance as a sales enabler and own the customer-facing security package.
Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.
Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.
Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.
Drive SOC 2, ISO 27001, and PCI 4.0 compliance audit cycles: gather evidence, design controls, and coordinate with auditors.
Own the compliance automation platform Vanta: monitor control status, chase failing checks, and update risk register.
Run vendor and third-party risk reviews, security assessments, and respond to customer security questionnaires.
AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. With under 100 people, it is a capital-efficient AI company generating roughly $500K ARR per employee and operating as a true meritocracy with no bureaucracy.
Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.
Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.
Own the overall security posture, including policy, standards, and risk framework.
Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
Lead incident response, vulnerability management, and customer security assurance.
RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.
Lead and grow a small security team while owning Canary's security and compliance program end-to-end.
Serve as the primary security voice to customers, partners, and auditors, translating security posture for varied audiences.
Set technical direction for security tooling and stay hands-on in architecture and threat-model reviews.
Canary Technologies is a leading agentic AI platform for hotel and guest management, powering digital infrastructure for over 20,000 hotels in 125+ countries. With nearly $200M raised, they are a top-funded hotel tech company, recognized for growth and workplace excellence.
Improve perimeter and network-layer defenses (WAF, DDoS mitigation, anti-bot) and secure product APIs against abuse.
Manage vulnerability identification, prioritization, remediation, and coordinate external pentests.
Lead incident response, run the Security Champions program, and manage the Bug Bounty program.
Social Discovery Group (SDG) solves problems of loneliness, isolation, and disconnection by providing social entertainment platforms that connect people across cultures. The company is an international team of digital nomads working remotely worldwide and has been named a Great Place to Work (USA & Japan, 2024–2025).
Develops and maintains information security policies, procedures, and controls ensuring compliance with HITRUST, SOC 2, HIPAA, and other frameworks.
Leads audit readiness and execution, managing HITRUST and SOC 2 Type II examinations from planning through report issuance.
Drives continuous improvement of security processes, risk management, and incident response across the organization.
MRO specializes in information security assurance and regulatory compliance, helping organizations manage risk and maintain audit readiness. The company fosters a security-focused culture with a team of experienced professionals.