Principal, Information Security
Listed on 2026-08-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Position:
Principal, Information Security
Location:
Remote
Job
# of Openings: 1
Role:Principal, Information Security About interos.ai
interos.ai is the standard for supply chain risk intelligence. Our Resilience platform, powered by an 11B buyer-supplier knowledge graph and 250M+ businesses scored across six risk factors, Cyber, Catastrophic, ESG, Restrictions, Geopolitical, and Finance, is run by Fortune 1000 market leaders and trusted by major Federal departments. As the only AI-powered SaaS platform that comprehensively assesses risk across these domains, interos.ai
helps customers understand their exposure through our proprietary iScore® and assists both real-time and anticipatory opportunities to mitigate supply chain risk.
Our second-generation platform, iQ, is the industry’s first fully productized predictive analytics platform for supply chain risk. iQ orchestrates ERP and Resilience platform insights to deliver AI-driven suggestions for supply chain risk management, helping organizations quantify financial exposure, stay ahead of geopolitical volatility and shifting tariffs, and communicate risk in the language CFOs use every day.
We are not afraid to challenge conventions, explore new ideas, and iterate quickly. Our work is meaningful, the problems are complex, and the pace requires focus, curiosity, and adaptability.
We are looking for people who are humble in how they collaborate, hungry to succeed, and smart in how they work. People who thrive here are energized by broad exposure, comfortable navigating ambiguity, open to feedback, proactive in taking ownership, and motivated by making a real impact.
About the roleWe are hiring an Information Security Lead to be a hands-on player and coach that leads the Information Security & Compliance function . You will build, run, and continuously improve our security posture across security engineering, security operations, and GRC. You will have high visibility, broad scope, and meaningful influence at a small, fast paced start up.
You will have freedom and agency to meaningfully make interos.ai more secure. Each day and week will look different. You might lead an incident response investigation, review architecture proposals, write a polished response to a customer security questionnaire, or reconfigure Defender settings to minimize a recently discovered risk. You operate across the full security spectrum, not just one lane.
This role is roughly: 55% security engineering (engineering, configuration, answering questions from the org, & risk management), 20% GRC (SOC2, CMMC, compliance posture), 25% security operations (incident response, monitoring, DR tabletop exercises, red team/purple team exercises). The daily rhythm looks like 70% hands-on engineering, 10% strategic planning, and 20% cross-team collaboration.
WHAT YOU'LL DO- Own and operate the security tooling stack end to end, including identity and Zero Trust management; endpoint management; network security controls; vulnerability management; and security monitoring and logging
- Lead incident response from initial triage through containment, investigation, root cause analysis, and post-mortem documentation
- Own disaster recovery planning and lead DR and incident response tabletop exercises to validate business continuity and incident readiness
- Plan and lead red team / purple team exercises to validate security controls and stress-test incident response readiness
- Manage third-party penetration testing engagements, tracking findings by severity, coordinating remediation with Engineering, and overseeing the retest cycle
- Work closely with the Engineering and Platform team on architecture and design reviews, providing security guidance on new features, integrations, and infrastructure changes
- Harden cloud and on-premises environments, managing IAM policies, endpoint protection, and network security controls
- Work with contractors and external security partners to maintain SOC2 and CMMC compliance posture, including managing the control environment, coordinating evidence collection, and tracking remediation across teams
- Handle customer-facing and vendor-facing security questionnaires independently,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).