Sr Manager, Information Security and Compliance

Posted 2 Days Ago
Be an Early Applicant
3 Locations
In-Office
Senior level
Food • Information Technology • Payments • Software • Hospitality
Helping Independent Restaurants Thrive.
The Role
Lead and execute the information security and compliance program across cloud and on-prem environments. Ensure PCI DSS and data privacy compliance (CCPA, Philippines, Malaysia), implement identity and RBAC controls, manage workstation/BYOD solutions, respond to incidents, and grow a team of security professionals while aligning security strategy with business objectives.
Summary Generated by Built In

About us:

Here at Tarro we build products that empower small brick and mortar restaurants by liberating them of the operational burden of running their business. We accomplish this by providing a frictionless connection between them and their customers through our multi-product ecosystem offering AI-enabled order taking, delivery enablement, payment solutions, and point-of-sale software. At Tarro, we use a combination of bits (technology) and atoms (people) to solve real world problems facing small business owners.

We obsess over placing our customers first and working backwards from there. When our customers succeed, we succeed. The restaurant industry in the US is over a $1 trillion total addressable market (TAM), but remains relatively underserved by technology. Large chains are able to afford expensive tech that gives them a huge advantage; we believe that small restaurant owners deserve access to the same technologies at an affordable price.

Tarro has been profitable for nearly a decade and has seen 5x revenue growth in the past four years. As of our last fundraising round in mid-2022, we were valued at $450M and have since seen substantial growth across customer acquisition, product development, and company headcount. Thousands of loyal restaurants have entrusted Tarro with their success, and together we have supported nearly 20 million customers. We are proud to be named one of Built In’s top companies to work for in 2023.

To learn more about our culture, values and how you can be a part of helping mom & pop restaurants thrive, please visit us here! Helping restaurants thrive, not just survive.

What we’re looking for:

We are seeking a highly skilled and experienced Sr Manager of Information Security and Compliance to lead our organization’s information security strategy and operations. The ideal candidate will have a robust background in both cloud and on-premise infrastructure, a deep understanding of data privacy regulations, and extensive experience with PCI DSS compliance and other security frameworks. As a player-coach, the Sr Manager of Information Security will be both a hands-on contributor and a strategic leader, capable of designing, implementing, and managing comprehensive security measures while leading and developing a team of security professionals.

What you will accomplish:

  • You will develop and execute a comprehensive information security strategy aligned with business objectives, regulatory requirements, and risk profiles

  • You will ensure compliance with relevant data privacy regulations, including PCI DSS, Philippines/Malaysia’s DPAs, CCPA, and others as needed

  • You will maintain and ensure compliance with the company’s information security management system

  • You will lead the design, implementation, and maintenance of secure cloud-based and on-premise infrastructure spanning our product and corporate environments

  • You will work closely with internal stakeholders across various departments to ensure alignment on security practices and initiatives.

  • You will grow and manage a team of information security professionals

  • You will participate in production support and data breach incidents and drills

  • You will stay current with emerging security threats, vulnerabilities, and technologies, and proactively adjust security measures as necessary.

One year deliverables:

  • Readiness for PCI DSS Level I audit

  • Compliance with CCPA and the Data Privacy Acts of the Philippines and Malaysia

  • Role-based access control

  • Solution for workstation management and BYOD at scale

About you:

  • You have between 8 and 10 years of IT experience with five or more years leading a team

  • You have experience implementing and managing the following services:

    • Information security management frameworks (PCI DSS, ISO 27001, SOC 2, etc.)

    • Data privacy frameworks (GDPR, CCPA, etc.)

    • Identity management systems and role-based access control

    • Workstation and BYOD management applications

    • Security best practices for hybrid (cloud+on-premise) product and corporate infrastructure

  • You enjoy being a hands-on contributor, an influencer, and a leader, in equal measure

  • You have strong prioritization and project management skills

  • You are resourceful and are comfortable working independently in ambiguous situations

  • You are willing to work in-office 5 days a week, starting at 3am PHT Tuesday-Saturday to align with US hours

Bonus points:

  • You have completed green-field security framework implementations at startups or other small-to-midsize companies

  • You have experience with scripting and APIs

  • You have a practical, business-oriented approach to security practices

  • You are open and willing to take on additional responsibilities that may be outside of this role. We are a growing company!

If you do not meet all the requirements listed above which candidates rarely do, don't worry. We still encourage you to apply!

Tarro is committed to hiring the best team to empower small businesses to thrive. We believe that a diverse workforce is paramount to our success. We welcome talent from all backgrounds - including but not limited to - race, sexual orientation, gender identity, age, nationality, religion, veteran status, political affiliation, and disability.

Skills Required

  • 8-10 years of IT experience
  • 5+ years leading a team
  • Experience implementing and managing PCI DSS, ISO 27001, SOC 2
  • Experience with data privacy frameworks (GDPR, CCPA, Data Privacy Acts of the Philippines and Malaysia)
  • Experience with identity management systems and role-based access control
  • Experience with workstation and BYOD management applications
  • Knowledge of security best practices for hybrid (cloud + on-premise) infrastructures
  • Hands-on contributor and strategic leader (player-coach)
  • Strong prioritization and project management skills
  • Resourceful and comfortable working independently in ambiguous situations
  • Willingness to work in-office 5 days a week, starting at 3am PHT Tuesday-Saturday
  • Experience participating in production support, data breach incidents and drills
  • Green-field security framework implementations at startups or small-to-midsize companies
  • Experience with scripting and APIs
  • Practical, business-oriented approach to security practices
  • Willingness to take on additional responsibilities outside the role

Tarro Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Tarro and has not been reviewed or approved by Tarro.

  • Fair & Transparent Compensation Pay bands are explicitly listed for multiple roles, including higher ranges for senior technical positions, which signals clearer expectations at the offer stage.
  • Healthcare Strength Health, dental, and vision coverage are explicitly described as part of a comprehensive or premium benefits package.
  • Flexible Benefits Flexible remote work is emphasized as a core part of the benefits package, and learning allowances are positioned as an ongoing support benefit.

Tarro Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
1,300 Employees
Year Founded: 2015

What We Do

Tarro was born out of our personal struggles running a take-out restaurant for 10+ years. We know first-hand that small restaurant owners work far too hard to earn razor-thin margins. On top of that, enterprise software vendors offer technology solutions that don’t always work for small restaurants. At Tarro, we use a combination of bits (technology) and atoms (real people) to solve real-world problems facing restaurants. Today, we’ve helped more than 1,800 restaurant owners increase profits and secure a better future for their families. As we’ve grown, our founding principle has never changed: we aim to help independent restaurant owners realize their dreams. Tarro has achieved significant growth over the past two years, growing annual re-occurring revenue by almost 4x to $46 million and quadrupling our customer base of mom-and-pop restaurants.

Why Work With Us

If you want to be part of a hyper-growth and profitable technology company–that’s backed by institutional investors - Tarro is the place for you. Based in Long Island City (aka Queens, NY), we seek creative thinkers who are passionate about using technology to solve the biggest problems facing independent restaurant owners.

Gallery

Gallery

Similar Jobs

Remote or Hybrid
3 Locations
289097 Employees

UL Solutions Logo UL Solutions

Information Technology Manager

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
Philippines
15000 Employees
Hybrid
2 Locations
289097 Employees
Remote or Hybrid
2 Locations
289097 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account