Source Job

Hungary

  • Define and implement the data security framework for the lakehouse, including RBAC, ABAC, and column/row-level security.
  • Lead compliance programs for applicable regulations: GDPR, CCPA, HIPAA, SOC 2, PCI-DSS.
  • Conduct data risk assessments and threat modeling for platform components and data pipelines.

Cybersecurity Cloud Security Compliance Risk Assessment

20 jobs similar to InfoSec Management & Compliance Lead

Jobs ranked by similarity.

EMEA

  • Act as the security overlay on EMEA opportunities, engaging customers on security, privacy, and compliance.
  • Lead security conversations with CISOs and security architects, translating ClickHouse architecture into controls frameworks.
  • Design secure deployment patterns, run threat modelling, and own compliance workstreams through production readiness.

ClickHouse is a fast-growing private cloud company that provides real-time analytics, data warehousing, observability, and AI workloads. With over 4,000 customers and 250% year-over-year ARR growth, it is recognized on the 2025 Forbes Cloud 100 list.

Global

  • Provide technical leadership for data security remediation across SharePoint, OneDrive, Microsoft Purview, and Cyera.
  • Work hands-on to investigate findings, validate root cause, and drive remediation actions.
  • Partner with client teams to align remediation to governance models and operational workflows.

Vailexa builds thinkers, creators, and future leaders by giving people space to grow and create real impact. They are a company that values ambition, ideas, and impact, fostering an environment where employees are empowered to succeed.

Ireland

  • Own and advance identity governance and DLP strategies across the enterprise.
  • Design and implement unified IGA programs covering human, AI agent, and service account identities.
  • Enforce least privilege access models and zero-trust principles across all identity types.

Extreme Networks provides end-to-end, cloud-driven networking solutions trusted by over 50,000 customers globally. We have double-digit growth year over year and an inclusive culture that values diversity.

$130,000–$180,000/yr

  • Design and implement security solutions across multi-cloud environments (AWS, GCP, Azure).
  • Lead threat detection, identity management, and compliance posture for clients.
  • Embed security into CI/CD pipelines and develop AI-accelerated internal tooling.

Riveron is a consulting firm that helps organizations implement governance, risk, and compliance practices, including cybersecurity advisory. The firm has an entrepreneurial culture focused on collaboration, diversity, and delivering exceptional outcomes.

$170,000–$200,000/yr
US Unlimited PTO

  • Design and own technical architecture of a multi-cloud data and analytics platform serving VA users and Veteran data.
  • Lead data architecture modernization, governance, and compliance strategies.
  • Collaborate with data engineers, analysts, and VA stakeholders to deliver scalable data products.

Oddball delivers quality software solutions to the federal space. Their team of experienced engineering, product, and UX professionals values learning and growth in a rapidly growing company.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

$130,000–$160,000/yr
US Unlimited PTO

  • Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
  • Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
  • Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.

Airship provides a no-code, AI-powered platform for brands like Alaska Airlines and BBC to create personalized cross-channel customer experiences. The company fosters a digital-first, flexible remote culture with a collaborative team across time zones.

US

  • Lead security and IT for Cardlytics, overseeing security engineering, IT operations, and compliance for a fully remote team.
  • Manage SOX/SOC 2 compliance, identity and access management, and cloud security across AWS environment.
  • Drive AI adoption company-wide while partnering with executives and the board to align security priorities with business strategy.

Cardlytics is a purchase intelligence and incentives platform that helps businesses attract and incentivize consumers through digital reward programs. As a public company (NASDAQ: CDLX) with a lean, high-trust team, they prioritize integrity and growth.

Global

  • You will analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.
  • You will design and support the implementation of secure Azure cloud architectures.
  • You will conduct threat modeling, attack surface analysis, and attack tree creation for applications, services, workloads, and AI-enabled solutions running on Microsoft Azure.

CENSUS provides bespoke cybersecurity services driven by a talented team of Security Engineers, Consultants, and Researchers. The company is technology-focused with deep industry knowledge and is expanding its team to deliver comprehensive top-tier cybersecurity services to clients.

Canada Unlimited PTO

  • Own cloud and platform security end to end across AWS and Azure, including architecture, detection, and response.
  • Build self-serve security tooling and guardrails to replace manual processes and reduce risk.
  • Partner with engineering teams to embed security into CI/CD pipelines and product development.

Ada is an AI customer service platform that enables enterprise companies to deliver instant, proactive, and personalized customer experiences. Established in 2016, the Canadian company has powered over 5.5 billion interactions for brands like Square and YETI, backed by over $250M in funding from top-tier investors.

$127,200–$205,100/yr
Global Unlimited PTO

  • Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
  • Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
  • Review information security requirements in customer contracts and lead responses to complex security questionnaires.

We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.

$60,000–$60,000/yr
Argentina Mexico Brazil Chile Uruguay Colombia Ecuador

  • Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
  • Own SOC 2 Type II program management and the customer-facing trust portal.
  • Author security policies and manage AI compliance frameworks.

Sparkrock helps social benefit organizations like nonprofits, school boards, and government agencies reach their full potential through technology. They are a best-in-class, 100% remote organization with a focus on culture and growth, serving over 150,000 users.

  • Own security architecture, guardrails, and automation across Azure and AWS.
  • Engineer and maintain Kubernetes security and cloud network controls.
  • Mentor junior engineers and drive security maturity across the organization.

Semperis is a cybersecurity company focused on protecting enterprise identities. It has been recognized as one of America's Fastest-Growing Cybersecurity Companies and a multi-year Inc. Best Workplace awardee, with a culture rooted in purpose, growth, and balance.

North America Unlimited PTO

  • Own the vision, strategy, and roadmap for AI Security Governance across five control pillars.
  • Architect and deploy hands-on security controls for AI detection, data protection, and agent permissions.
  • Drive AI-automated workflows and author risk narratives for CISO, board, and Audit Committee audiences.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

United States

  • Develop and implement effective cybersecurity strategies aligned with client objectives and industry best practices.
  • Design and implement advanced security controls and technologies, including SIEM, DLP, and endpoint protection.
  • Lead complex cybersecurity projects, manage client relationships, and contribute to thought leadership.

Avertium provides cybersecurity consulting and managed security services, focusing on Microsoft Cloud and other platforms. The company fosters a culture of remote teamwork, self-discipline, and innovation, leveraging industry best practices to deliver cost-effective solutions.

US

  • Design and implement security controls across AWS GovCloud environments.
  • Integrate security into CI/CD pipelines using Terraform and GitLab.
  • Ensure compliance with FedRAMP and DoD IL-4/5 standards.

Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.

$114,000–$139,000/yr
US

  • Monitor and enforce compliance with security frameworks like NIST CSF, ISO 27001, SOC 2, and regulations such as GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments, develop security policies, and lead internal and external security audits with cross-functional teams.
  • Evaluate third-party vendor security posture, maintain compliance records, and define metrics to assess the success of the security program.

Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. The company values integrity, kindness, and grit, and has been committed to excellence since 2001.

US

  • Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
  • Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
  • Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.

RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.

Ireland 5w PTO

  • Lead the design and evolution of a multi-framework compliance offering for European businesses.
  • Drive end-to-end ISO 27001 implementations and manage a team of compliance specialists.
  • Act as a senior security partner to customers, sales, and product teams.

This company provides a security and compliance platform that helps modern businesses achieve certifications across frameworks like ISO 27001 and SOC 2. It is a fast-growing, remote-first technology environment with a strong emphasis on collaboration and team connection.