Information Security Officer
Listed on 2026-06-07
-
IT/Tech
Cybersecurity, Data Security
Uni Uni is a late-stage last‑mile logistics company operating across the United States and Canada. We move millions of parcels for some of the largest e‑commerce platforms in North America, and our technology stack is cloud‑native, on AWS.
We hold an active ISO 27001 certification and SOC 2 Type II attestation. Security and compliance are not afterthoughts at Uni Uni; they are central to our enterprise customer commitments, investor expectations, and the trust our drivers, shippers, and partners place in us every day.
Role Snapshot
Reports to:
Chief Technology & Product Officer (CTPO)
Location:
North America (remote with periodic travel to Uni Uni hubs)
Scope:
Worldwide operations with focus on North America
We are hiring an Information Security Officer to lead Uni Uni’s security and governance function end to end. This is a hands‑on leadership role reporting directly to the CTPO. You will own the security program across cloud infrastructure, application security, data security and governance, corporate IT, compliance, and risk, and you will be the senior accountable owner for our ISO 27001 certification and SOC 2 Type II attestation.
You will work closely with engineering, platform, IT, legal, and executive leadership, and you will be Uni Uni’s primary security voice in front of customers, auditors, and investors. You will build and lead a small, high‑leverage team and set the bar for how security operates as the business scales.
Key ResponsibilitiesSet the security posture of our AWS environments, including IAM, network segmentation, encryption, logging, secrets management, and workload protection.
Drive cloud security baselines aligned to CIS Benchmarks and the AWS Well‑Architected Security Pillar, and enforce them through infrastructure as code and platform guardrails.
Lead continuous monitoring and threat detection across cloud workloads using native AWS services (Guard Duty, Security Hub, Cloud Trail, Config) and complementary third‑party tooling.
Run vulnerability management for cloud infrastructure, including patching cadence, remediation SLAs, and exception governance.
Application Security
Embed secure development practices into the SDLC, including threat modeling, secure code review, SAST, DAST, SCA, and secrets scanning in CI/CD.
Partner with engineering leaders to triage and remediate application vulnerabilities without slowing delivery.
Run the open source software program, including license compliance, vulnerability tracking, and remediation.
Manage the external penetration testing program, from scoping and vendor selection through findings triage and remediation verification.
Set and evolve standards for authentication, authorization, session management, and API security across internal and customer‑facing applications.
Deliver enterprise SSO (SAML 2.0 and OpenID Connect) for customer‑facing products in support of contractual security commitments.
Data Security and Governance
Own the data security program end to end, covering data classification, encryption in transit and at rest, key and secrets management, and protections against unauthorized access, exfiltration, and misuse.
Maintain and evolve the data classification framework across Uni Uni’s regional and shared data warehouse environments, and drive schema‑level classification into operational use by engineering and analytics teams.
Govern access to production databases, data warehouses, and analytics platforms, including approval workflows, periodic access reviews, and audit trails.
Implement and operate data loss prevention controls across endpoints, email, SaaS, and cloud storage, calibrated to the sensitivity of the data and the realities of how the business operates.
Set and enforce data residency, retention, and minimization standards in line with customer commitments and regulatory obligations across the jurisdictions in which Uni Uni operates.
Partner with engineering, data, and product teams on privacy by design, including data flow mapping, data sharing agreements, and the secure handling of personal information for shippers, drivers, and end recipients.
Lead the response to data subject requests, data incidents, and breach…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).