This is a remote position.
- Manage and maintain cybersecurity compliance programs, including NYDFS Cybersecurity Regulation 500, ISO 27001, and enterprise security requirements.
- Conduct vulnerability assessments, coordinate penetration testing, and drive remediation efforts across cloud and internal environments.
- Monitor and respond to security events using AWS security services, SIEM platforms, and other security tools.
- Develop and maintain incident response processes, security controls, and identity and access management (IAM) practices.
- Partner with engineering teams to integrate security into the SDLC through secure coding practices, threat modeling, and application security reviews.
- Support vendor risk assessments, client security reviews, and security documentation for audits and compliance.
- Serve as the security subject matter expert for cloud security, API security, and OWASP Top 10 best practices.
- 7+ years of experience in cybersecurity engineering or information security, preferably within SaaS, fintech, or cloud-based environments.
- Strong experience with cloud security (AWS preferred), identity and access management, logging, monitoring, and security operations.
- Experience with compliance frameworks such as NYDFS, ISO 27001, SOC 2, PCI DSS, or similar.
- Hands-on experience with SIEM platforms, vulnerability management, penetration testing, and incident response.
- Strong understanding of application security, API security, secure SDLC, and OWASP Top 10.
- Excellent communication skills with experience supporting audits, security documentation, and cross-functional collaboration.
- Professional certifications such as CISSP, CISM, or CEH are preferred.
- Awareness or knowledge of IT security best practices as defined by ISO/SOC or similar.
In addition to a competitive long-term total compensation package with salary and performance-based bonus, we have a reward philosophy that goes beyond compensation.
- Be part of a remote-first organization where flexibility is embraced.
- Work and learn alongside talented engineers and technology leaders.
- Explore opportunities to learn and grow through technical and non-technical training programs.
- Gain global exposure by working on products with international teams and clients
- Attend virtual and in-person international technology conferences to expand your knowledge and network.
- Exposure to work in an IT environment that adheres to rigorous security and compliance standards defined by ISO/ SOC.
Skills Required
- 7+ years of experience in cybersecurity engineering or information security
- Experience in SaaS, fintech, or cloud-based environments
- Strong experience with cloud security, preferably AWS
- Experience with identity and access management, logging, monitoring, and security operations
- Experience with compliance frameworks such as NYDFS, ISO 27001, SOC 2, PCI DSS, or similar
- Hands-on experience with SIEM platforms, vulnerability management, penetration testing, and incident response
- Strong understanding of application security, API security, secure SDLC, and OWASP Top 10
- Excellent communication skills and experience supporting audits, security documentation, and cross-functional collaboration
- CISSP, CISM, or CEH certification
- Knowledge of IT security best practices defined by ISO, SOC, or similar standards
What We Do
Aspire is the influencer marketing platform empowering ecommerce brands to build and cultivate influential communities of influencers, ambassadors, affiliates, customers, and more. Brands using Aspire can discover authentic partners, streamline relationships, scale their programs, and measure true business impact — regardless of where they are in their influencer marketing journey. Aspire is trusted by Glossier, Coola, Bombas, Newell, Ruggable, and over 400 additional customers. Investors include Hummer Winblad Venture Partners, Pear.vc, and more. For more information, visit www.aspire.io.









