via Remote Rocketship
$150K - 220K a year
Lead and execute comprehensive information security and IT strategy including governance, risk, compliance, security operations, and enterprise IT.
10+ years in information security with 5+ years leadership, hands-on security operations, vulnerability management, incident response, IT management, and familiarity with cloud security and AI security tools.
Job Description: • Lead and execute a comprehensive information security and IT strategy, including Governance, Risk & Compliance, Security Operations, and Enterprise IT. • Own the design, implementation, and continuous improvement of the company's information security program. • Partner cross-functionally with every aspect of the business to ensure that security is embedded into every layer of the organization. • Oversee IT operations including helpdesk, system administration, and physical network administration, ensuring reliability and security across the environment. • Set the strategy and roadmap for enterprise applications and infrastructure, including identity and access management; evaluate and govern the use of AI-powered productivity and business tools. • Maintain vulnerability management processes including prioritization, remediation tracking, and SLA enforcement; leverage AI tooling to improve detection coverage and triage efficiency. • Lead incident response, coordinating cross-functional teams, managing communications, and driving post-incident reviews. • Own security and IT vendor relationships, contracts, and budgets, including forecasting and investment recommendations. • Deliver regular updates to executive leadership on program status, key risks, and strategic priorities. • Lead, mentor, and develop a team spanning security and IT, managing priorities, workload, and career growth across both operational and strategic work. Requirements: • Bachelor's degree in a related field or equivalent experience. • 10+ years in information security, with at least 5 years in a leadership role. • Demonstrated experience owning a GRC program and TPRM function. • Hands-on background in Security Operations, vulnerability management, and incident response. • Experience leading an IT function and managing vendor relationships. • Comfortable presenting security topics to executive and non-technical audiences. • Proficiency with SIEM and EDR/XDR platforms; familiarity with code scanning tools (Snyk, Semgrep, Checkmarx, etc.). • Understanding of cloud security (AWS, GCP, Azure), IAM platforms, and network infrastructure. • Knowledge of NIST CSF, ISO 27001, SOC 2, HIPAA, and CIS Controls. • Hands-on experience using AI tools for security monitoring and workflow automation; familiarity with securing LLM deployments, agentic workflows, and AI harness/orchestration security. • Ability to assess risk and develop policy guidance for AI-powered workforce tools. Benefits: • Curative Health Plan (100% employer-covered medical premiums for you and 50% coverage for dependents on the base plan.) • $0 copays and $0 deductibles (with completion of our Baseline Visit) • Preventive and primary care built in • Mental health support (Rula, Televero, Two Chairs, Recovery Unplugged) • One-on-one care navigation • Chronic condition programs (diabetes, weight, hypertension) • Maternity and family planning support • 24/7/365 Curative Telehealth • Pharmacy benefits • Comprehensive dental and vision coverage • Employer-provided life and disability coverage with additional supplemental options • Flexible spending accounts • Flexible work options: remote and in-person opportunities • Generous PTO policy plus 11 paid annual company holidays • 401K for full-time employees • Generous Up to 8–12 weeks paid parental leave, based on role eligibility. • This role is eligible for annual discretionary bonus structure and company equity
This job posting was last updated on 8/1/2026