Senior Manager, Security & IT Ops

Posted 5 Hours Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
Senior level
Software
The Role
Leads company-wide security governance, compliance, internal IT, risk management, audits, access controls, vendor security, cloud technology standards, incident preparedness, and AI governance. Manages a small team and service providers while remaining hands-on with security and IT operations. Owns SOC 2 Type II and ISO 27001 programs, supports customer security assurance, and establishes ownership, service, and sourcing frameworks across the company.
Summary Generated by Built In
We need a hands-on security and internal IT leader who will set direction and step in to do the work. This person will lead company-wide security governance and compliance and make sure employees have reliable, secure technology. The role reports to the executive responsible for all post-sales operations.
This role will manage a small team and may also oversee contractors or outside service providers.
Responsibilities include setting priorities, coaching and developing team members, managing performance, and building the capabilities needed as the function grows.
Day-to-day, this person will create practical policies and safeguards, raise important risks, and directly manage identity, privileged access, critical software, and internal systems when no clear owner exists.
The role will name primary and backup owners, make technical and business responsibilities clear, and recommend investments. Finance, Procurement, Legal, and business leaders will keep formal approval authority for contracts and spending.
This is primarily an internal role, with customer contact when security expertise is helpful. Engineering owns secure product design and fixes. Cloud SRE and Engineering own customer-production reliability, monitoring, deployments, infrastructure-as-code, upgrades, and on-call work. Customer-facing teams own
routine customer delivery.

WHAT YOU’LL DO
  • Set the company's security direction. Own the security plan, information security management system (ISMS), risk register, policies, control ownership, exceptions, annual policy updates, leadership reporting, and ongoing improvement of the company's security and regulatory standing.
  • Keep audits and compliance work on track. Be the main contact for external auditors and lead annual SOC 2 Type II and ISO 27001 work from readiness through final reports. Keep Secureframe, evidence, findings, corrective actions, and quarterly reviews of user access, firewall settings, and risk controls current.
  • Find risks and make sure they are addressed. Run regular security risk assessments, identify weaknesses in business processes, and work with IT, Cloud SRE, and Engineering Operations on practical fixes. Track security patches and bug fixes against required compliance deadlines.
  • Protect access to company systems. Manage access when people join, change roles, or leave. Apply role-based access, least privilege, separation of duties, and regular reviews; keep clear records of root, administrator, service, and shared accounts; and handle critical access work until a lasting owner or automated process is in place.
  • Manage vendor security risk. Assess new and existing vendors, keep administrator and backup-owner records current, track ownership changes, and rate risk based on the sensitivity of company and customer data. Work with the appropriate business teams on due diligence, renewals, use, and exit planning.
  • Make internal IT dependable and easy to use. Create clear ways for employees to ask for help, set response expectations, document how systems are managed, maintain ownership and transition plans, and track service quality. Personally handle or oversee important administrative work until a lasting owner is in place.
  • Guide internal cloud and technology spending. Set clear security and ownership expectations for internal AWS, Google Cloud, Azure, Kubernetes, VPN/SASE, domains, DNS, shared operational channels, logging, and monitoring. Review costs, unused resources, commitments, and whether work belongs with an internal team or a service provider.
  • Prepare the company for incidents and disruptions. Maintain clear response plans, escalation paths, communications, exercises, follow-up actions, and alerting practices for security and internal IT incidents. Work with Engineering and Cloud SRE on customer-impacting events and review the Business Continuity Plan annually against customer commitments.
  • Help customers understand and trust our security. Work with Sales and Legal on customer and prospect security or vendor questionnaires, and join customer conversations about assurance, risk, incidents, or escalations when security leadership is needed.
  • Contribute to the AI Governance Committee. Participate as a contributing member and bring security, privacy, responsible-use, access, vendor-risk, and operational perspectives to reviews of proposed AI tools and current uses. Help the committee create practical guidance, record decisions and exceptions, and check that agreed actions are completed. Business and technical owners remain accountable for their AI solutions.
  • Show meaningful progress in the first year. Within 12 months, establish an approved security plan, clear control ownership, a dependable audit rhythm, an internal IT service model, an ownership register, a privileged-account inventory, internal-cloud standards, and agreed transition or sourcing plans for important gaps.


WHAT YOU HAVE
  • Experience leading across a company. You have owned a company-wide security, compliance, internal IT, or technology-risk program in a cloud or software company. You can influence leaders and lead a small team, contractors, or service providers while staying close to the work.
  • Hands-on audit and compliance experience. You have directly led ISO 27001 and SOC 2 Type II work, external audits, evidence gathering, policy reviews, findings, corrective actions, control reviews, and customer assurance.
  • Sound risk and resilience judgment. You understand privacy and data protection, business-process and vendor risk, vulnerability and patch management, incident response, business continuity, and compliance deadlines.
  • Technical confidence. You can work comfortably with identity, business software, AWS, Google Cloud, Azure, Kubernetes, networking, firewalls, VPN/SASE, domains, DNS, logging, monitoring, and privileged access.
  • Ability to bring order to unclear work. You have stepped into work with no clear owner, protected continuity, documented what matters, clarified responsibilities, and moved work to the right internal team or service provider.
  • Clear and inclusive communication. You can explain risks and choices to executives, auditors, technical and business teams, customers, and prospects, and can work with Sales and Legal on security questionnaires.
  • Education or equivalent experience. A bachelor's degree in Computer Science, Information Security, Information Systems, or a related discipline, or equivalent practical experience, is preferred.
  • Helpful credentials and experience. CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, or a similar certification is helpful. Experience in a distributed company, responsible AI governance, technology cost management, or vendor commercial management is also valuable.


BENEFITS
  • Unlimited PTO
  • Medical/Dental/Vision Insurance
  • HSA/FSA
  • Basic & Supplemental Life & AD&D insurance
  • Short & Long-term Disability Insurance
  • 401k
  • EAP (Employee Assistance Program)


About
The world's largest leading companies trust Hazelcast and its unified real-time data platform to take instant action on streaming data. With a stream processing engine and fast data store integrated into a single solution, businesses can simplify real-time architectures for next-gen applications and AI/ML departments to drive new revenue, mitigate risk, and operate efficiently - at a low TCO. To learn more about Hazelcast, or to join our community of CXOs, architects, and developers at brands such as HSBC, JPMorgan Chase, Volvo, New York Life, Domino's, and others, visit hazelcast.comEqual Opportunities at HazelcastWe welcome people from all backgrounds, ethnicities, races, religions, gender, sexual identities, abilities, and personal circumstances, in a spirit of inclusivity and belonging.We are proud to be an equal opportunities employer, and believe we see strength in diversity. If you require any accommodation to assist you in the interview process, please submit this with your application.We offer competitive salaries with a flexible, empathetic and highly collaborative working environment. If you are motivated by the prospect of a career with a forward-thinking tech company, we'd love to hear from you.

Skills Required

  • Experience owning a company-wide security, compliance, internal IT, or technology-risk program in a cloud or software company
  • Experience leading a small team, contractors, or service providers
  • Direct experience leading ISO 27001 and SOC 2 Type II work, including audits, evidence, policies, findings, corrective actions, and control reviews
  • Knowledge of privacy and data protection, business-process and vendor risk, vulnerability and patch management, incident response, business continuity, and compliance deadlines
  • Technical confidence with identity, business software, AWS, Google Cloud, Azure, Kubernetes, networking, firewalls, VPN/SASE, domains, DNS, logging, monitoring, and privileged access
  • Ability to clarify ownership, document critical work, maintain continuity, and transition responsibilities to internal teams or service providers
  • Strong communication skills with executives, auditors, technical and business teams, customers, prospects, Sales, and Legal
  • Bachelor's degree in Computer Science, Information Security, Information Systems, or a related discipline, or equivalent practical experience
  • CISSP, CISM, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or similar certification
  • Experience in a distributed company, responsible AI governance, technology cost management, or vendor commercial management
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Palo Alto
117 Employees
Year Founded: 2008

What We Do

Hazelcast is the leading in-memory computing platform company which addresses the growing demand for enhanced application performance, speed and scalability. Hazelcast’s in-memory computing platform is comprised of two core products: Hazelcast IMDG and Jet. Hazelcast IMDG is an in-memory data grid built and proven to provide the performance at scale required by the world’s largest organizations. Hazelcast Jet, is an ultra-fast, application embeddable, stream and batch processing engine capable of supporting real-time streaming data. The company also offers Hazelcast Cloud, a fully managed, low latency data layer for cloud-based workloads at any scale. Hazelcast’s customers include six of the world’s 10 largest banks and 36 of the Fortune Global 500; its technology is deployed at nearly every major credit card company, five of the world’s largest e-commerce companies and four of the largest telecommunications companies.

Similar Jobs

AcuityMD Logo AcuityMD

Senior Product Manager

Healthtech • Software
Easy Apply
Remote or Hybrid
Boston, MA, USA
250 Employees
175K-215K Annually

Lob Logo Lob

Business Operations Manager

Logistics • Marketing Tech • Software
Easy Apply
Remote
United States
125 Employees
153K-170K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Absence Team Leader

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
In-Office or Remote
New York, NY, USA
12000 Employees
74K-129K Annually

New York Life Insurance Company Logo New York Life Insurance Company

CVP, Regional Sales Director - Stable Value Investment Only (SVIO)

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
In-Office or Remote
New York, NY, USA
12000 Employees
125K-150K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account