Company

Technology

Security&ComplianceLead

$150–225k New York, New York, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Lead candidates.

The Brief

“Security & Compliance Lead”

Industry & Context.

Technology

How You'll Work.

Communication Scope

Written communication

Full Job Description

About the role We're a fast-growing startup with a small but talented engineering team, and we're hiring our first Security & Compliance Lead to build the foundation for our security program. This is a high-ownership, high-autonomy role with a broad mandate: you'll own the security and compliance surface end-to-end, from access management and SOC 2 to infrastructure security and customer trust. You'll report to CTO with full ownership of the security and compliance domain. In year one, the work skews toward access management, SOC 2, and customer-facing security. Over time, the role grows into broader security engineering: monitoring, incident response, vendor risk, and architecture review. If you've built a security program from scratch before and liked it, you'll recognize this job. If you want to build something from the ground up rather than slot into an existing program, read on. What you'll own Access & identity management. Production access, service accounts, SSO, and the lifecycle of both - provisioning, periodic review, deprovisioning. SOC 2. You'll own the program end-to-end, mapping controls to our environment, driving evidence collection, and getting us through Type 1 and then Type 2 and other security frameworks. Customer trust. You'll own security questionnaires, RFP security sections, and the customer-facing trust narrative (trust center, security overview docs, DPAs). Infrastructure security. VM lifecycle and patching, baseline hardening, secrets management, vulnerability management, and cloud security posture. Security engineering (over time). Logging and monitoring, incident response runbooks, vendor security reviews, and partnering with engineering on secure design. What we're looking for - 5+ years in security or security-adjacent roles - You've driven a SOC 2 audit - ideally owned one end-to-end, but if you ran the bulk of a program under a fractional CISO or security leader, that counts - Comfortable in cloud environments (AWS, GCP, or Azure) an

Free ATS check

Applying for this Security & Compliance Lead role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about this company?

Real rants from real employees. Read before you apply.

Read Company Rants →