Skip to content

Security Program Manager

Assess client security postures, develop customized security programs using frameworks like NIST and SOC2, provide implementation guidance, and collaborate with auditors and internal teams to achieve compliance goals.

75k – 140kBeaverton, ORSecurity EngineeringRemote3+ YOE

About the role

Key Responsibilities

  • Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.
  • Provide guidance and recommendations for improving client security posture.
  • Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.
  • Collaborate with clients to customize and refine the security program to match their specific use cases.
  • Communicate with clients and stakeholders to ensure smooth and efficient security program creation.
  • Liaise with auditors to ensure clients' security programs align with auditors' expectations.
  • Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.
  • Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs.
  • Be highly technical, learn new technologies quickly, and translate security concepts into implementations.
  • Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.

Requirements

  • 3+ years in an information security role.
  • Broad knowledge of security best practices, frameworks, control types, and relevant technologies.
  • Ability to understand client infrastructure and map security controls to meet compliance goals.
  • Strong analytical skills to evaluate environments and determine appropriate safeguards.
  • Excellent verbal and written communication skills.
  • Self-driven with the ability to work independently and move fast in a startup environment.
  • Willingness to go the extra mile to meet tight deadlines and deliver results.

Skills

NistSoc2Iso27001CmmcAWSAzureGCPKubernetesDockerTerraform

Security Engineer

Security Engineer focused on security operations, incident response, monitoring/alerting, and securing SaaS applications and infrastructure. Requires Go experience, Elastic Stack, GCP, and on-call rotation participation.

72k – 144kUnited StatesSecurity EngineeringRemote5+ YOEGoGCP

GRC Program Manager

Owns end-to-end execution of GRC programs including SOC 1/2, PCI DSS, and ISO 27001 audits, control design, risk assessments, and vendor management. Partners with engineering to implement technical controls and documentation for scalable compliance in fintech.

95k – 135kUnited StatesSecurity EngineeringRemote3+ YOESDLCSoc 1

Compliance Analyst

This Compliance Analyst role at Harvey involves owning and maintaining compliance documentation, coordinating evidence collection, and supporting third-party assessments. The role requires hands-on compliance work, close collaboration with Engineering and Security teams, and a detail-oriented approach to ensure program health and continuous monitoring.

99k – 149kSan Francisco, CASecurity EngineeringHybrid3+ YOESaaSCloud Environments

Security Engineer, Application Security

Conduct low-level code security assessments, architecture reviews, and threat modeling for client applications. Build custom security tools bridging vulnerability research and application security. Requires manual code review, binary analysis, and programming proficiency in multiple languages.

100k – 200kUnited StatesSecurity EngineeringRemote5+ YOECGo

Security Engineer (Security Operations, Zero Trust)

Security Engineer focused on security operations, incident response, and Zero Trust implementation. Designs, deploys, and supports security tools like SIEM, EDR, and Cloudflare; triages alerts, automates responses, and collaborates on cloud/IAM security. Requires 3-5 years experience in cloud-native security engineering.

100k – 140kUnited StatesSecurity EngineeringRemote3+ YOEEdrGCP