The Role
Leads the company’s security, risk, and compliance programs, including SOC 2 audits, future ISO 27001 certification, security policies, risk remediation, controls, and audit readiness. Partners with engineering, product, operations, commercial teams, auditors, regulators, and customers to embed compliance into business processes and support security-related sales conversations.
Summary Generated by Built In
We’re looking for a Security & Compliance Lead to own and lead our security, risk, and compliance efforts across the organization. As the dedicated leader in this space, you will define the strategy, drive execution, and serve as the central point of accountability for all security and compliance initiatives.
This is a highly cross-functional role at the intersection of governance, regulation, and business operations, requiring strong stakeholder management and the ability to translate requirements into practical, business-ready outcomes. You will work closely with engineering, product, operations, and commercial teams to embed security and compliance into how we operate.
If you're pragmatic, business-focused, and confident driving initiatives and influencing across teams, this role is for you.
In this role you will:
- Lead the development and continuous improvement of the company’s security, risk, and compliance programs;
- Own and manage the SOC 2 Type II audit lifecycle and support future certifications such as ISO 27001;
- Define, maintain, and promote security policies, standards, and best practices across the organization;
- Act as the main point of contact for security and compliance topics in customer and pre-sales conversations;
- Partner with product, engineering, and business teams to ensure security and compliance requirements are understood and embedded in processes;
- Identify risks, track remediation efforts, and maintain an effective risk management framework;
- Oversee security controls and processes to ensure alignment with regulatory and business requirements;
- Report on compliance status, risks, and audit readiness to leadership and external stakeholders;
- Influence and coordinate cross-functional teams to achieve security and compliance goals.
Your profile:
- 5+ years of experience in information security, with a strong focus on compliance and risk management in the technology or fintech sectors;
- Proven experience leading security programs and compliance efforts (e.g., SOC 2, ISO 27001, GDPR, etc.);
- Good understanding of modern software development practices, DevOps, cloud infrastructure (e.g., AWS, Azure), and operations;
- Exceptional written and verbal communication skills, with the ability to convey complex security topics to non-technical stakeholders and influence sales outcomes;
- Experience engaging with external auditors, regulators, and enterprise customers;
- Comfortable working independently in a fast-paced, resource-constrained environment;
- Adept at building cross-functional relationships and leading through influence;
- Familiarity with security tools such as identity and access management, vulnerability scanners, endpoint protection, and secure SDLC processes;
- Fluency in English.
We offer:
- Flexible work model – work from home, from our welcoming office at Campus X or a mix of both
- Performance-based bonuses that reward impact and results
- 25 days of paid annual leave
- Vacation Hero Days – earn up to 5 extra days off when you take your full annual leave
- 1 additional day off for your birthday
- 2 days off for volunteering
- Up to 15 days of sick leave per calendar year, fully paid at 100% salary coverage
- Premium healthcare and dental coverage
- Co-funded Multisport card
- Food vouchers
- Access to an Employee Well-Being Program
- Long-Term Employee Value Distribution (LEVD) scheme
- Generous refer-a-friend program
#LI-VR1
About
interop.io is a leading software infrastructure company delivering innovative technology solutions to some of the world’s largest financial institutions. Formed in June 2023 through the merger of Finsemble and Tick42, interop.io brings together the award-winning technologies of both companies to drive seamless application interoperability in capital markets and beyond. Our platform, io.Connect, enables clients to integrate multiple applications into a single, intuitive smart desktop—empowering users to focus on high-value work instead of switching between tools. Beyond our core platform, interop.io provides comprehensive professional services that help financial institutions design and deliver tailored applications that drive productivity and enhance end-user workflows. Our expertise ensures successful implementation, customization, and long-term value for our clients. With over 130 employees across New York, Charlottesville, London, and Sofia, our team is dedicated to building cutting-edge products and shaping the future of financial technology. Join interop.io and be part of a fast-growing, innovative company where your work directly impacts global financial institutions and transforms the way people interact with technology.
Skills Required
- 5+ years of experience in information security, focused on compliance and risk management in technology or fintech
- Experience leading security programs and compliance efforts such as SOC 2, ISO 27001, and GDPR
- Understanding of software development practices, DevOps, cloud infrastructure, and operations
- Exceptional written and verbal communication skills
- Experience engaging with external auditors, regulators, and enterprise customers
- Ability to work independently in a fast-paced, resource-constrained environment
- Cross-functional relationship-building and leadership through influence
- Familiarity with identity and access management, vulnerability scanners, endpoint protection, and secure SDLC processes
- Fluency in English
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
interop.io is the industry's leading desktop interoperability platform, formed by the merger of Finsemble and Glue42. It enables enterprise teams to unify web, native, and legacy applications, providing application integration and streamlining workflows for capital markets.









