Head of Security and IT
RemoteUnited States
Job Summary
Lead security and IT strategy for a five-person team, serving as the primary point of contact for external auditors and bank partners while managing SOX/SOC 2 compliance and internal audit requirements. Own the identity and access management program across Okta and Google Workspace, maintain the AWS production environment baseline using Terraform and EKS, and triage cloud security findings from Wiz and Expel. Act as an internal champion for AI adoption across non-technical teams and handle end-user support for a hybrid remote workforce. Manage and develop the team, set priorities, and partner directly with the CTO and board to align security priorities with business strategy.
Required Qualifications
- 8+ years in security and/or IT leadership
- 3+ years managing a team directly
- Deep, hands-on background in at least two of: security engineering, security architecture, identity & access management, or vulnerability management
- Direct experience owning or heavily supporting SOX and/or SOC 2 compliance programs
- Experience with modern IAM tooling (Okta, Google Workspace, or similar)
- Experience with cloud security platforms (Wiz or comparable CNAPP/CSPM)
- Comfort operating in a fully remote, lean-team environment
- Working knowledge of AWS and IaC concepts (Terraform)
- Executive-level communication skills
- Familiarity with Databricks, EKS, or MDR/managed-SOC relationships
- Familiarity with or willingness to work within a macOS and Google Workspace environment
Desired Qualifications
- Experience in fintech, adtech, or another environment with heavy third-party/bank compliance scrutiny
- A security or compliance certification (CISSP, CISM, or equivalent)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.