Responsibilities
- Lead the full lifecycle of the organization's information security and IT initiatives with direct, hands-on execution.
- Sustain secure configurations and identity governance in AWS, including regular audits and use of native security tools.
- Manage enterprise security controls, including endpoint detection and response, email protection, identity management, network visibility, and data loss prevention.
- Direct the strategic oversight and daily coordination of third-party IT service providers, ensuring high performance and stakeholder responsiveness.
- Act as the internal technical authority for corporate IT systems and the escalation point for security-related IT matters.
- Ensure ongoing SOC 2 Type II compliance across all Trust Service Criteria, managing auditor interactions and evidence workflows.
- Support compliance with CCPA and privacy regulations by managing data access requests, website tracking technologies, and privacy workflows in collaboration with Legal.
- Oversee application security for web and mobile platforms, including organizing annual penetration tests and guiding engineering teams through remediation.
- Operate the organization’s vulnerability management program, including risk prioritization, tracking, and reporting.
- Lead incident response efforts, maintaining response plans, conducting simulations, and managing real-world security events through resolution and post-mortem analysis.
- Develop and validate business continuity and disaster recovery plans in coordination with Engineering and Operations teams.
- Execute and document quarterly access reviews for critical systems to ensure appropriate permissions and compliance.
- Evaluate security clauses in vendor and customer contracts, respond to customer security questionnaires, and conduct vendor risk assessments.
- Support the personnel security program, including security awareness training and access controls during onboarding and offboarding, in partnership with HR.
- Chair the Information Security & IT Committee to assess tools, define acceptable use policies, and manage data exposure risks across approved technologies, including AI platforms.
- Advance the secure integration of AI and emerging technologies by engaging relevant internal and external stakeholders.
Requirements
- Minimum of seven years in information security with direct ownership of security programs.
- Professional experience in a growth-stage startup, preferably as the lead security practitioner.
- Background in delivering or managing IT services operations.
- Strong commitment to internal customer service and adherence to service level expectations.
- Direct experience leading SOC 2 Type II audits, not just supporting them.
- Proficiency with modern compliance automation platforms such as Vanta, Drata, or OneTrust.
- Working understanding of CCPA and U.S. data privacy regulations.
- Experience evaluating security terms in contracts.
- Demonstrated interest and knowledge in AI tools relevant to early-stage technology companies.
- Proven ability to lead security, compliance, or technology transformation in a fast-moving environment.
- Familiarity with security risks associated with AI and governance of SaaS-based AI solutions.
Nice to Have
- Knowledge of ISO 27001, NIST 800-53, NERC CIP, or OWASP frameworks.
- Ability to write Bash scripts for automating system tasks and enforcing device management policies.
- Excellent written communication skills, capable of executive briefings and producing audit-ready documentation.
- Hold a CISSP, CISM, or comparable industry certification.
Responsibilities
- Own and execute WeaveGrid's information security and IT program end-to-end — this is a high-impact, hands-on IC role.
- Maintain cloud security posture across AWS (IAM governance, configuration review, cloud-native security tooling)
- Own the corporate security control environment — EDR, email security, identity governance, network monitoring, DLP
- Oversee strategy and day-to-day management of our IT services contractor(s). Ensure operational excellence and intervene as needed to ensure timely responses to internal stakeholders.
- Serve as the internal technical owner of the corporate IT environment and escalation point for security-intersecting IT issues
- Manage SOC 2 Type II compliance across all five Trust Service Criteria, including auditor relationships and evidence collection
- Support CCPA and privacy compliance by monitoring and managing data subject access requests and the associated overarching process, applicable website technologies, and ad hoc privacy requests, in partnership with the Legal team.
- Own application security for our web and mobile products, including coordinating annual penetration tests and driving remediation with Engineering.
- Run the vulnerability management program — prioritization, tracking, and reporting.
- Manage incident response — maintain the IR plan, run tabletop exercises, and handle real incidents through to post-mortem.
- Maintain and test BC/DR plans in coordination with Engineering and Operations.
- Conduct and document quarterly access reviews across critical systems.
- Review security terms in vendor and customer contracts; complete customer security questionnaires; run vendor risk assessments.
- Help administer the personnel security program (security awareness training, onboarding/offboarding controls) in partnership with the People team.
- Lead the company’s Information Security & IT Committee — evaluating tools, defining acceptable use, and managing data exposure risk across sanctioned tools, including AI platforms
- Drive AI and new technology adoption within WeaveGrid, engaging internal and external stakeholders as applicable
Required
- 7+ years in information security with meaningful program ownership experience
- Experience at a growth-stage startup company, ideally as a primary security practitioner
- Experience providing or overseeing IT services
- Obsessed with client service and meeting internal SLAs
- Hands-on SOC 2 Type II experience — you've run an audit, not just supported one.
- Familiarity with leading security and compliance governance tools (i.e. Vanta, Drata, OneTrust).
- Working knowledge of CCPA and US data privacy requirements
- Experience reviewing contractual security requirements.
- Deep interest in and knowledge of leading AI tooling, as applicable to early-stage startups.
- Proven track record driving security, compliance, and/or technology change within a fast-paced organization.
- Familiarity with AI security risks and SaaS AI governance
Preferred
- Experience or familiarity with ISO 27001, NIST 800-53, NERC CIP, OWASP.
- Comfortable writing Bash scripts for automation and MDM enforcement tasks
- Strong written communication — you can brief an exec and write audit-ready documentation
- CISSP, CISM, or equivalent