Állás

Manager of Information Security

Egyéb • Remote • Teljes munkaidő Európai Unió EU/EMEA
Manager of Information Security Team: Information Security Reports to: CTO Location: Remote (US, EST/CST hours) Manages: IT/TechOps (1) About Us Clasp is a Forbes Fintech 50, SHRM-backed company tackling two hard problems at once: helping employers attract and retain talent in critical fields, and easing the student debt crisis. We're at a Series B inflection point, growing fast, with enterprise customers and partner banks who hold us to a high security bar. Why This Role We're an AI-first company with a genuinely strong technical team and solid foundations already in place including a running SOC 2 program, a modern GCP infrastructure, a well-managed macOS/Windows fleet, and an engineering culture that ships. Your mission is to take ownership of the information security program, lead our Information Technology team, and pair with engineering leadership and AI Labs on the deep technical work. This is the rare security role reporting to the CTO where you get real ownership on day one without inheriting a mess. If you're the kind of security leader who'd rather stand up a SIEM, harden a Terraform pipeline, and build your own tooling than manage a stack of vendors, this role was built for you. What you'll own SOC 2, Vanta & governance. Run our SOC 2 program end to end, own evolution of our Information Security policies, own our Vanta instance, run events such as business continuity drills, and represent information security in our Risk + Compliance committee. IT/TechOps. Lead and collaborate with our IT/TechOps team across corporate IT and security: laptop procurement, MDM, onboarding/offboarding, SaaS vendor management and hardening, incident response, data loss protection, and more. Together you'll set direction and grow the function and the team as we scale. Vendor diligence & security questionnaires. Own third-party security reviews, and be the front line for inbound customer and partner-bank security questionnaires SIEM, Vulnerability Management & IDS. Configure our SIEM, build the alerting that gives us real signal without noise, and manage vendor relationships for real proactive visibility and risk reductions. Cloud & access security (GCP). Pair with technical leaders to advance our cloud posture, IAM (JIT privilege escalation, group-based access), and platform hardening. AppSec & secure SDLC. Partner with engineering to advance secure SDLC in a rapidly changing agentic world. Ensure dependency and vulnerability scanning is effective, CI/CD and pipelines are hardened, and new features have robust threat modeling. AI security agents. Work with the CTO and AI Labs to run build vs buy analysis for all categories of agentic security work: detection/triage, evidence collection, questionnaire drafting, access reviews and more. Additionally, ensure all other deployed agents operate securely.. How we think about security in the age of AI The security landscape in 2026 is changing fast. We want to implement best-of-breed vendors and roll up our sleeves to engineer in-house solutions when it makes the most sense. We don’t want to just throw head count or complex solutions at a problem that can instead be automated and configured in depth to be more resilient than brittle commercial solutions. You'll be hands-on and genuinely exhilarated to work closely with our technical teams to build and maintain internal security capabilities across SIEM, IDS, and more. What we're looking for CISSP certification. 5+ years on a security team. Startup experience — you've worked somewhere scrappy, not only at large/mega companies. Compliance in the room — you've been at a company that achieved SOC 2 or ISO 27001 . A technical foundation — a semi-technical degree (Information Systems or similar) or a few years of hands-on technical work (scripting, web development, automation, data analysis, etc.). AI builder's instinct — comfortable scripting, prototyping, and using AI and modern tooling to solve problems efficiently. Strong communicator — credible and clear with customers, partner banks, auditors, and internal teams. You'll be customer and regulator facing. If you're earlier in your leadership journey, that's fine as we'll back you with coaching and support on the tough calls. Nice to have Fintech, lending, or other regulated / high-trust experience. Hands-on GCP security depth (AWS experience also welcome). Stood up or owned a SOC 2 program from scratch. Experience fielding diligence from partner banks or enterprise customers. What we give in return Competitive cash and equity compensation Health benefits (health, dental, & vision) Student loan repayment benefits 401k matching Commuter benefits Flexible PTO policy Opportunities to grow and perform in a fast-paced environment alongside a stellar team Salary The salary range for this position is competitive and will be commensurate with the candidate's experience, qualifications, and industry knowledge, ranging between $170,000 - $190,000 annually. In addition to the base salary, we offer an attractive equity component as part of our compensation package, providing an opportunity for eligible employees to share in the success and growth of our company. We are committed to offering competitive compensation and benefits packages to attract and retain top talent. Closing If you are a driven engineer with a passion for building systems that meaningfully serve the people who rely on them, we want to hear from you. Join us in reshaping how schools support their students and making a lasting impact on the future of higher education financing. Apply now to be part of our growing team! We are committed to creating a diverse and inclusive workplace where all employees feel valued, respected, and empowered to contribute their unique perspectives and talents. Clasp is an equal opportunity employer and prohibits discrimination and harassment of any kind. We embrace diversity and are dedicated to providing equal employment opportunities to all individuals regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.

Hasonló állások