Skip to main content
Oneleet
Oneleet

Security Program Manager

RemoteWorldwide
Published
Role
Security
Experience
Mid
Employment
Full-time
Company size
Startup
$75k–$140k/yr
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

Security/compliance program manager with 4+ years in information security, compliance, audit, GRC, vCISO, security advisory, or adjacent customer-facing security work. Needs broad knowledge of SOC 2, ISO 27001, HIPAA, GDPR, PCI and the ability to map controls to real infrastructure and operations. Client-facing technical account/project management experience is required.

Core skills

SOC 2ISO 27001GRC

Required skills

NISTHIPAAGDPRPCI

Optional skills

CISACISSPCISM

What you'll do

  • Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.
  • Provide guidance and recommendations for improving client security posture
  • Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.
  • Collaborate with clients to customize and refine the security program to match their specific use cases.
  • Communicate with clients and stakeholders to ensure smooth and efficient security program creation
  • Liaise with auditors to ensure clients' security programs align with auditors' expectations
  • Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.
  • Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs.
  • Be highly technical, learn new technologies quickly, and translate security concepts into implementations.
  • Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.

What they require

  • 4+ years in a role involving information security, compliance, or audit (security operations, GRC, vCISO, security advisory, IT/Compliance auditing, or a security-adjacent customer success/IT support role).
  • You’ll need to understand security and operations well enough that compliance becomes the natural byproduct of genuine security, not just checking boxes against the checklist.
  • You should know why the box exists.
  • Working and broad knowledge of security best practices, major compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI), and how controls map to real infrastructure and operations.
  • Audit-side insight is particularly relevant.
  • Technical Account Management experience, or client facing or stakeholder facing experience with strong project management instincts.
  • This is a high-volume, high-interruption, relationship-oriented role that requires you to translate between technical and non-technical people.
  • Startup and business fluency matters, whether gained internally or in consulting with startups, for helping companies find a compliance path that truly fits where they are today.
  • Ability to understand client infrastructure and map security controls to meet compliance goals and the bigger picture of holistic security and compliance.
  • Strong analytical skills to evaluate environments and determine appropriate safeguards.
  • Excellent verbal and written communication skills.
  • Self-driven with the ability to work independently, comfortable with ambiguity, and able to adapt approach client-by-client in a fast-moving startup environment.
  • Willingness to go the extra mile to meet tight deadlines and deliver results.
  • Preferred: Exposure to a “Lead Auditor” scope (cross-framework, whole-program view) rather than a single specialty area
  • Preferred: Prior experience in customer success, IT support, or technical support background (useful for pace/responsiveness this role demands)

Benefits

  • Comprehensive health & wellness benefits
  • 20 days PTO per year, plus 8 floating holiday
  • Remote work culture
  • Team off-sites in stunning places (Amsterdam, Italy, etc).
  • Competitive compensation & equity
  • You’ll join a tight-knit team of rebels redefining the cybersecurity industry.
  • We value impact over titles, autonomy over micromanagement, and clarity over jargon.
  • You’ll tackle meaningful, hard problems with real-world consequences.
  • You’ll work with smart, kind, and ambitious teammates who lift each other up.

Oneleet is the full-stack cybersecurity platform offering automated security and compliance solutions, including penetration testing for SOC 2 and beyond.

CybersecurityStartuponeleet.com/
$75k–$140k/yr