Information Security & Compliance Leader
Northslope
⛰️ About Northslope The generational companies of the next century will run on mission‑specific AI software that compounds their competitive advantage, not commoditized SaaS. We purpose‑build production AI applications that enable our customers to operate at the speed, scale, and margins of an enterprise software company, in any industry. We’re building something fundamentally different: software that’s as adaptable as the businesses it serves, created by engineers who understand both code and customer. ️ The Role Northslope operates at the intersection of AI and mission‑critical software development for enterprise and defense organizations. We work across jurisdictions and under complex contractual security requirements. Our compliance posture must scale alongside our ambition. We have achieved ISO 27001, SOC 2 Type II, and Cyber Essentials Plus certification. We are now hiring our first dedicated security leader to own and evolve the program, and to serve as a security architecture partner to our product and delivery teams. This role is accountable for everything at the intersection of security, compliance, and customer trust. You will maintain and mature our certification portfolio, lead customer security diligence, and define governance around AI and SaaS usage. Just as importantly, you will be embedded in how we build and deploy software for customers, ensuring the systems we ship are actively secure and that we are protecting our customers’ information as rigorously as our own. In a world where the attack and leak surface is taking on new dimensions as we field AI capabilities and partner with machines to build production software, this work has never been more urgent. You will partner closely with product engineering, delivery teams, and operations on technical risk, secure architecture, and compliance strategy. You will own our compliance platform and vendor relationships, and serve as the internal and external face of Northslope’s security program. We are not looking for security theater. We are building durable, scalable security that protects the company and our customers without creating unnecessary friction. ✍️ What You’ll Own Certification & Framework Leadership Own and mature Northslope’s SOC 2, ISO 27001, Cyber Essentials Plus, HIPAA, and CMMC programs. Build a unified control environment that scales globally. Embed security requirements directly into our platform architecture from the start, so compliance is a product feature rather than an afterthought. Secure Platform Architecture Partner closely with our product engineering team as a security architect. Define and enforce security patterns across our platform’s multi‑agent orchestration layer, data isolation model, and customer‑facing deployment surfaces. Own threat modeling for new platform capabilities and ensure our architecture meets the security bar required by enterprise and defense customers out of the box. Customer‑Facing Security & Trust Lead all third‑party risk assessments, security questionnaires, and audit engagements. Ensure our platform’s architecture and documentation make it easy to demonstrate compliance to customers. Represent Northslope’s security posture credibly to enterprise buyers, auditors, and legal teams, treating security as a commercial asset that accelerates deal velocity. AI & SaaS Governance Establish governance over AI tools and SaaS used in both internal operations and customer engagements. Define guardrails for how our platform’s AI components handle customer data, including data residency, model access controls, and audit trails. Proactively assess emerging risks as the AI landscape evolves. Identity, Access & Tenant Isolation Own access control strategy across Northslope’s internal systems (SSO, Okta, provisioning/deprovisioning) and across our platform’s multi‑tenant architecture. Define how customer data, workspaces, and third‑party integrations are isolated. Ensure least‑privilege access for both employees and system‑level service accounts. Governance, Incident Readiness & Secure SDLC Own and evolve the ISMS, security awareness training, incident response, and business continuity. Define and enforce secure development lifecycle practices for our platform codebase, including dependency management, secret handling, code review security gates, and vulnerability remediation SLAs. Serve as the primary escalation point for security events across both internal systems and the platform. Vendor Risk, Background Checks & TechOps Partnership Lead background check compliance across the US and UK. Oversee third‑party vendor risk management, including export controls and data residency. Define device and endpoint security standards in partnership with TechOps. Evaluate and approve third‑party services integrated into our platform infrastructure, ensuring they meet the same security bar as our own systems. What We’re Looking For Proven Program Ownership: You have built or significantly matured an information security program at a company of comparable size and complexity. You have owned a GRC platform like Vanta and know how to operationalize it. You are comfortable being the accountable owner. Multi‑Framework Expertise: You have led SOC 2 and ISO 27001 engagements and have meaningful exposure to HIPAA, CMMC, or Cyber Essentials. You understand framework overlap and build unified programs rather than treating each certification as a separate initiative. Technical Credibility: You can design security into cloud‑native platforms and production software, not just audit them after the fact. You understand multi‑tenant data isolation, secure SDLC, and identity architecture at a systems level. Engineers trust your judgment because you’ve shipped alongside them, not because you’ve blocked them. Pragmatic Security Mindset: You focus on protecting the business and its customers, not accumulating certifications. You understand that in a forward‑deployed engineering model, security extends to the systems we build and operate for customers, not just our internal environment. You know how to get to yes. Secure Product Development Experience: You have defined security architecture for a product or platform, not just an internal IT environment. You’ve done threat modeling, designed data isolation patterns, defined secure SDLC practices, or owned security reviews in a CI/CD pipeline. You’re comfortable in a codebase, even if you’re not writing features. AI‑Era Security Awareness: You are thinking actively about the security implications of AI‑assisted software development: code generated by AI agents, data flowing through model APIs, prompt injection risks, and the expanding attack surface that comes with using AI to build production software. You don’t need to have all the answers, but you need to be asking the right questions and helping the team navigate uncharted territory. Delivery‑Embedded Security: You want to be involved in how we build and deploy software for customers, not just how we protect our own systems. You’re energized by working alongside engineering and delivery teams to ensure the systems we ship are secure by design. Executive‑Level Communication: You can clearly articulate risk to employees, customers, legal teams, and auditors. You translate technical complexity into business impact. High Ownership Mentality: You operate independently, close gaps end‑to‑end, and build scalable systems in environments that are evolving quickly. You embrace a ‘nothing is beneath you’ attitude, tackling any task necessary to achieve the desired outcomes. What We Offer Competitive base salary + equity in the form of stock options Comprehensive benefits package including health insurance (inclusive of dental and vision) and 401k matching Flexible hybrid work environment The opportunity to build solutions, systems, and software from the ground up as we scale A small, tight‑knit team where your contributions directly impacts our ability to execute on our mission Occasional travel (less than 10% of your time) for company offsites where you’ll connect with teams across our New York and London hubs Our Principles Only Valuable Problems: Not every problem is worth solving. We work on the projects that will significantly improve our customers’ bottom lines. Outcomes, Not Activity: We create value, not extract it. We focus on our business impact, not racking up billable hours. Forward Deployed Engineering: We never build in a vacuum. We go to the heart of the problem and build alongside our users. One size fits none. Generic software fails the most important customers. We build for the specific — the exact industry, workflow, data, and competitive context of the company we’re serving. Why Northslope At Northslope, we’re built different. We take pride in being more like a product startup than a traditional services firm. We value velocity, ingenuity, and grit, and we relentlessly focus on delivering tangible outcomes for our customers. We also have fun. We get to work on big, hard problems, in a fast‑paced environment, alongside sharp yet kind teammates who help us continuously grow and delight in one another’s successes. We offer full benefits and all the perks you’d expect of a modern tech startup, and are a distributed global team with hubs in London, New York, and UAE. We hope you’re excited to join us and look forward to speaking with you soon. Northslope is committed to building a strong, diverse team. We believe teams with a diversity of lived experience, background, and perspectives create better outcomes for our customers and are just more enjoyable to be part of. We are committed to creating and living a culture of diversity, equity, and inclusion throughout our work. We do not discriminate on the basis of race, national origin, religion, disability, pregnancy, age, military status, marital status, genetic characteristics or information, gender, gender identity, gender variance, or sexual orientation. #J-18808-Ljbffr Northslope
- ...AGFA HealthCare is seeking an Information Security Leader to spearhead the global cybersecurity vision. This role emphasizes leadership in security operations, compliance with healthcare regulations, and engagement with executive stakeholders. The ideal candidate will...SuggestedRemote work
- A dynamic tech company located in New York is seeking a dedicated security leader to enhance its security and compliance programs. This role involves maintaining certifications like SOC 2 and ISO 27001, leading vendor risk assessments, and ensuring a secure architecture...Suggested
- ...Nomad Foods Inc is seeking a Chief Information Security Officer (CISO) to provide strategic oversight of information security and lead initiatives in cybersecurity, data protection, and compliance. This role is crucial for safeguarding critical assets and maintaining operational...Suggested
- ...communications platform in New York is seeking an experienced Information Security Manager to lead the company's information security strategy... ...within SaaS or cloud-based environments, and is skilled in compliance with regulatory frameworks like SOC 2 and GDPR. This role...Suggested
- PSECU Pennsylvania State Employees Credit Union is seeking an Information Security GRC Analyst III to ensure the integrity, confidentiality, and availability of information. You'll monitor compliance, conduct risk assessments, and manage security policies. The ideal candidate...Suggested
- ...UniUni is seeking an Information Security Officer to lead security and governance functions across its cloud infrastructure. The role involves overseeing ISO 27001 and SOC 2 compliance, managing application and data security, and leading incident response efforts. Located...Remote work
- ...NYC Technical Tech Lead Network Security Manage a small team of talented... ...globally Ensure network security compliance with regulatory standards such as PCI DSS... ...Bachelor's degree in computer science, information security, or related field ~5-7...
$130k - $160k
A leading science and technology company is seeking a Policy and Compliance Lead to design and maintain information security policies aligned with industry standards. Responsibilities include leading compliance initiatives, collaborating with multiple teams, and serving...Remote work$185k - $245k
...Information Security Risk Oversight Lead - Second Line of Defense) Location New York Business Area Legal, Compliance, and Risk Ref # 10050628 Description & Requirements Position... ...thought partner to senior leaders by advising on emerging threats,...Temporary workFor contractorsWork experience placement- Ernst & Young Advisory Services Sdn Bhd in Hoboken, New Jersey, is seeking an Assistant Director for the Information Security Portfolio Compliance Enablement function. The ideal candidate will manage security risks, ensure compliance with policies, and work with global...
- A government service provider in New York is seeking an Information System Security Officer (ISSO) to manage security and compliance for U.S. Government projects. In this role, you will work hands-on with systems, ensuring that security requirements are met while collaborating...
$90k - $130k
...short, We Enable Possibility℠. TheManager, IT Compliance, working closely with the CISO and Director of IT Security, will provide management, leadership and delivery... ...activities (SOX, SOC 2, etc.) and customer information security due diligence reviews. Responsibilities...Remote jobTemporary workWork at office- ...A leading information security platform is seeking an Information Security Consultant to establish and maintain a corporate-wide information security management program. Responsibilities include suggesting improvements to clients' security policies, preparing documentation...Remote work
$150k - $190k
Compass Pathways in New York seeks a Senior Manager, IT Information Security to lead its cybersecurity program during a critical phase of growth. The role emphasizes collaboration with IT leadership and external partners to protect company data, users, and systems. Candidates...- ...facility, ensuring a safe and compliant environment for patients and staff. Responsibilities include staff management, regulatory compliance, and emergency cleaning response. The ideal candidate will have 2-5 years in environmental services, preferably with supervisory...Shift work
- ...REE Medical, LLC is seeking a full-time remote Information Systems Security Manager to lead a team of security professionals. You will develop... ...systems to protect sensitive data and ensure regulatory compliance. The ideal candidate has a Bachelor's degree in a related...Full timeRemote work
- ...Supervisor I in Social Work for Domestic Violence Services. This role involves overseeing staff, managing case assignments, and ensuring compliance with social service mandates. Ideal candidates will have a Master’s Degree in Social Work and relevant experience....
- ...A staffing solutions company is seeking a Senior Compliance Analyst to manage claims compliance across 50 states. This fully remote role requires at least 7 years of experience in claims compliance or insurance regulation and a law degree. The ideal candidate will lead...Remote work
$136.4k - $181.4k
...Clinical Research Manager to oversee clinical monitoring activities and the performance of the CRA team. This leadership role ensures compliance with ICH-GCP, local regulations, and company standards while fostering a positive team culture. The ideal candidate has a minimum...Local area- ...LastPass is seeking a Principal Business Information Security Officer to lead and mature their risk advisory function. This role involves transforming GRC operations and providing timely risk guidance across the organization. The position emphasizes collaboration with...Remote work
- ...Professional to manage initiatives across the U.S. The role requires participating in audits, delivering trainings, and ensuring compliance with regulations like OSHA. Ideal candidates will have a degree in a related field and 5-7 years of experience in Health and Safety...
- ...Waltz is seeking a Senior Compliance Officer with a strong background in financial services to run and scale their compliance program. This is a challenging role requiring 10+ years of compliance experience, ideally in fintech or banking. The position is remote-friendly...Remote work
- ...Woven Health Collective is seeking a Contract Sr. Ethics and Compliance Manager in the United States. This role is focused on executing and improving compliance programs, ensuring client and regulatory alignment, and managing risks. Candidates should have 5+ years of...Contract work
$80k - $140k
...ServerFarm seeks a Compliance Manager to lead compliance across North American operations. This position ensures adherence to relevant regulations and develops operational strategies to manage risks effectively. Candidates should have a Bachelor’s degree and 8+ years...- ...Trade Compliance Recruiting Solutions is seeking a Customs & Trade Advisory Leader Analyst to provide expert consulting on customs and trade. This remote role involves advising clients on global trade strategies, managing projects, and building strong client relationships...Remote work
$88k - $121k
...Denny's is seeking a Food Safety Leader responsible for strategic oversight of food safety and compliance across our restaurants. The role requires extensive experience in food safety, including training, advising franchisees, and ensuring operational excellence. Ideal...Remote work- FALL CREEK FARM & NURSERY seeks a dedicated Training Manager to lead safety and training initiatives in New York. This pivotal role involves developing protocols that ensure operations meet regulatory standards while fostering a culture of safety excellence across all ...
- ...A leading financial services firm is seeking a Privacy Compliance Coverage Officer to manage compliance with privacy regulations and oversee the firm's privacy program. The role requires strong expertise in data privacy laws, risk management, and excellent communication...
$70k - $80k
...Fountain is seeking a Compliance Manager to oversee compliance processes in a remote setting. The ideal candidate will have 4+ years of experience managing compliance for highly regulated roles and 2-4 years of people management experience. Responsibilities include managing...Full timeRemote work- ...for Regulatory Affairs. This role requires a seasoned regulatory leader with a strong background in advanced therapies to shape... ...interacting with FDA and global health authorities, and ensuring compliance. The ideal candidate will have 15+ years of experience, including...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security & Compliance Leader. Be the first to apply!
- underwriting team lead New York, NY
- group finance manager New York, NY
- office team lead New York, NY
- clinical team lead New York, NY
- team leader New York, NY
- team manager warehouse New York, NY
- team lead data science New York, NY
- disability team leader New York, NY
- group operations director New York, NY
- school leader New York, NY

