Manager of Information Security
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Manager of Information Security
Team: Information Security
Reports to: CTO
Location: Remote (US, EST/CST hours)
Manages: IT/Tech Ops (1)
About UsClasp is a Forbes Fintech 50, SHRM-backed company tackling two hard problems at once: helping employers attract and retain talent in critical fields, and easing the student debt crisis. We're at a Series B inflection point, growing fast, with enterprise customers and partner banks who hold us to a high security bar.
Why This RoleWe're an AI-first company with a genuinely strong technical team and solid foundations already in place including a running SOC 2 program, a modern GCP infrastructure, a well-managed macOS/Windows fleet, and an engineering culture that ships. Your mission is to take ownership of the information security program, lead our Information Technology team, and pair with engineering leadership and AI Labs on the deep technical work.
This is the rare security role reporting to the CTO where you get real ownership on day one without inheriting a mess. If you're the kind of security leader who'd rather stand up a SIEM, harden a Terraform pipeline, and build your own tooling than manage a stack of vendors, this role was built for you.
What you'll ownSOC 2, Vanta & governance. Run our SOC 2 program end to end, own evolution of our Information Security policies, own our Vanta instance, run events such as business continuity drills, and represent information security in our Risk + Compliance committee.
IT/Tech Ops. Lead and collaborate with our IT/Tech Ops team across corporate IT and security: laptop procurement, MDM, onboarding/offboarding, SaaS vendor management and hardening, incident response, data loss protection, and more. Together you'll set direction and grow the function and the team as we scale.
Vendor diligence & security questionnaires. Own third-party security reviews, and be the front line for inbound customer and partner-bank security questionnaires
SIEM, Vulnerability Management & IDS. Configure our SIEM, build the alerting that gives us real signal without noise, and manage vendor relationships for real proactive visibility and risk reductions.
Cloud & access security (GCP). Pair with technical leaders to advance our cloud posture, IAM (JIT privilege escalation, group-based access), and platform hardening.
App Sec & secure SDLC. Partner with engineering to advance secure SDLC in a rapidly changing agentic world. Ensure dependency and vulnerability scanning is effective, CI/CD and pipelines are hardened, and new features have robust threat modeling.
AI security agents. Work with the CTO and AI Labs to run build vs buy analysis for all categories of agentic security work: detection/triage, evidence collection, questionnaire drafting, access reviews and more. Additionally, ensure all other deployed agents operate securely..
The security landscape in 2026 is changing fast. We want to implement best-of-breed vendors and roll up our sleeves to engineer in-house solutions when it makes the most sense. We don’t want to just throw head count or complex solutions at a problem that can instead be automated and configured in depth to be more resilient than brittle commercial solutions. You'll be hands-on and genuinely exhilarated to work closely with our technical teams to build and maintain internal security capabilities across SIEM, IDS, and more.
What we're looking forCISSP certification.
5+ years on a security team.
Startup experience — you've worked somewhere scrappy, not only at large/mega companies.
Compliance in the room — you've been at a company that achieved SOC 2 or ISO 27001
.A technical foundation — a semi-technical degree (Information Systems or similar) or a few years of hands‑on technical work (scripting, web development, automation, data analysis, etc.).
AI builder's instinct — comfortable scripting, prototyping, and using AI and modern tooling to solve problems efficiently.
Strong communicator — credible and clear with customers, partner banks, auditors, and internal teams.
You’ll be customer and regulator facing. If you're earlier in your leadership journey, that's fine as we'll back you…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).