Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Officer

UniUni

UniUni is a late-stage last‑mile logistics company operating across the United States and Canada. We move millions of parcels for some of the largest e‑commerce platforms in North America, and our technology stack is cloud‑native, on AWS. We hold an active ISO 27001 certification and SOC 2 Type II attestation. Security and compliance are not afterthoughts at UniUni; they are central to our enterprise customer commitments, investor expectations, and the trust our drivers, shippers, and partners place in us every day. Role Snapshot Reports to: Chief Technology & Product Officer (CTPO) Location: North America (remote with periodic travel to UniUni hubs) Scope: Worldwide operations with focus on North America The Role We are hiring an Information Security Officer to lead UniUni’s security and governance function end to end. This is a hands‑on leadership role reporting directly to the CTPO. You will own the security program across cloud infrastructure, application security, data security and governance, corporate IT, compliance, and risk, and you will be the senior accountable owner for our ISO 27001 certification and SOC 2 Type II attestation. You will work closely with engineering, platform, IT, legal, and executive leadership, and you will be UniUni’s primary security voice in front of customers, auditors, and investors. You will build and lead a small, high‑leverage team and set the bar for how security operates as the business scales. Key Responsibilities Set the security posture of our AWS environments, including IAM, network segmentation, encryption, logging, secrets management, and workload protection. Drive cloud security baselines aligned to CIS Benchmarks and the AWS Well‑Architected Security Pillar, and enforce them through infrastructure as code and platform guardrails. Lead continuous monitoring and threat detection across cloud workloads using native AWS services (GuardDuty, Security Hub, CloudTrail, Config) and complementary third‑party tooling. Run vulnerability management for cloud infrastructure, including patching cadence, remediation SLAs, and exception governance. Application Security Embed secure development practices into the SDLC, including threat modeling, secure code review, SAST, DAST, SCA, and secrets scanning in CI/CD. Partner with engineering leaders to triage and remediate application vulnerabilities without slowing delivery. Run the open source software program, including license compliance, vulnerability tracking, and remediation. Manage the external penetration testing program, from scoping and vendor selection through findings triage and remediation verification. Set and evolve standards for authentication, authorization, session management, and API security across internal and customer‑facing applications. Deliver enterprise SSO (SAML 2.0 and OpenID Connect) for customer‑facing products in support of contractual security commitments. Data Security and Governance Own the data security program end to end, covering data classification, encryption in transit and at rest, key and secrets management, and protections against unauthorized access, exfiltration, and misuse. Maintain and evolve the data classification framework across UniUni’s regional and shared data warehouse environments, and drive schema‑level classification into operational use by engineering and analytics teams. Govern access to production databases, data warehouses, and analytics platforms, including approval workflows, periodic access reviews, and audit trails. Implement and operate data loss prevention controls across endpoints, email, SaaS, and cloud storage, calibrated to the sensitivity of the data and the realities of how the business operates. Set and enforce data residency, retention, and minimization standards in line with customer commitments and regulatory obligations across the jurisdictions in which UniUni operates. Partner with engineering, data, and product teams on privacy by design, including data flow mapping, data sharing agreements, and the secure handling of personal information for shippers, drivers, and end recipients. Lead the response to data subject requests, data incidents, and breach notification obligations under applicable privacy laws. Compliance and Governance Maintain and continuously improve UniUni’s ISO 27001 certification, including surveillance audits, internal audits, risk assessments, and management reviews. Sustain UniUni’s SOC 2 Type II attestation, owning control operation, evidence collection, auditor relationships, and remediation. Own the information security policy framework, including authoring, approval workflows, annual reviews, and employee attestations. Operate the risk management program, including the risk register, risk treatment plans, and executive risk reporting. Lead customer‑facing security activities, including security questionnaires, contract reviews, and security clauses in vendor and customer agreements. Support regulatory compliance efforts relevant to our business, including the DOJ Data Security Program, Canadian PIPEDA, and applicable US state privacy laws. IT Security and Operations Partner with IT to operate and mature endpoint security, including EDR, MDM (Intune), disk encryption, and device compliance. Govern identity and access across SaaS and corporate systems, including SSO adoption, MFA enforcement, privileged access controls, and joiner‑mover‑leaver processes. Own the SaaS inventory and run periodic access reviews, with particular attention to shadow IT and uncontrolled data flows. Lead security awareness training and phishing simulation programs. Run the incident response program, including the IR plan, tabletop exercises, on‑call rotation, and post‑incident reviews. Contribute to business continuity and disaster recovery planning in partnership with engineering and operations. Leadership and Stakeholder Engagement Build and lead a small security team, with hiring underway across two tracks: Compliance and GRC, and Application and Platform Security. Serve as UniUni’s senior security voice with customers, prospects, auditors, regulators, and investors. Report on security program status, KPIs, and risks to the CTPO and the executive team on a regular cadence. Represent security considerations in cross‑functional decisions across product, infrastructure, vendor selection, and business expansion. Required Qualifications 10+ years in information security, with at least 3 years owning a security program or a major security domain. Demonstrated ownership of ISO 27001 certification maintenance and SOC 2 audit execution in a cloud‑native organization. Deep hands‑on experience securing AWS environments at scale, including IAM, networking, logging, and workload protection. Strong application security background across secure coding practices, common vulnerability classes, and modern AppSec tooling (SAST, DAST, SCA, secrets scanning). Demonstrated experience building data security and governance programs, including data classification, encryption, DLP, access governance for data stores, and privacy‑aligned data handling. Practical experience with SAML 2.0 and OpenID Connect, and a track record of rolling out enterprise SSO and MFA. Experience operating core IT security controls, including EDR, MDM, and SaaS access governance. Track record of leading incident response, including coordination with engineering, legal, and executive stakeholders. Ability to translate security risk into business terms for non‑technical executives, customers, and investors, in writing and in person. Preferred Qualifications Background in logistics, supply chain, or high‑volume transactional businesses. Experience in an organization with worldwide cross‑border data flows and a focus on North America. Familiarity with the DOJ Data Security Program and bulk data transfer rules. Hands‑on experience with the Microsoft security stack (E5, Defender, Entra, Purview, Intune), and the perspective to evaluate it against alternatives such as CrowdStrike. Relevant certifications such as CISSP, CCSP, CISM, or ISO 27001 Lead Auditor or Lead Implementer. Prior experience taking a late‑stage company through IPO‑readiness security maturation. What You Will Find at UniUni A direct reporting line to the CTPO and regular exposure to the CEO, CFO, and the rest of the executive team. A security program with real executive commitment, a live ISO 27001 certification, and an active SOC 2 Type II attestation. Meaningful autonomy to shape the program and the team, balanced by the discipline and cadence of a late‑stage operating company. A growing business with the operational complexity, customer scrutiny, and learning opportunities that come with scale. How We Work We value direct, precise, and accurate communication. We prefer honest and defensible language over favorable framing. We write concise documentation, our meeting minutes stand up to auditor review, and we make decisions with our customers and our long‑term credibility in mind. UniUni is an equal opportunity employer. We evaluate candidates on the basis of qualifications, experience, and demonstrated ability, and we do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected characteristic. #J-18808-Ljbffr UniUni

Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Information Security Officer in New York, NY vacancy
  •  ...Chief Information Security Officer (CISO) About the Company Global organization modernizing enterprise risk, data governance, and cyber protection. Industry Internet Type Privately Held About the Role The Company is seeking a Chief Information Security... 
    Suggested

    Confidential

    New York, NY
    2 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Accomplished executive search firm Industry Staffing and Recruiting Type Privately Held About the Role The Company is seeking a Chief Information Security Officer (CISO) to oversee and... 
    Suggested

    Confidential

    New York, NY
    12 hours ago
  •  ...Description Job Description ISSO Employment Type: Full-Time, Experienced  Department: Information Technology  CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment... 
    Suggested
    Full time
    Local area
    Flexible hours

    Contact Government Services, LLC

    New York, NY
    11 days ago
  •  ...Job Description Job Description Information System Security Officer (ISSO) Employment Type: Full-Time, Mid-Level Department: Administrative and Logistics Support   As a FSR ISSO, you will be embedded on-site with U.S. Government customers to ensure the secure... 
    Suggested
    Full time
    Flexible hours

    Contact Government Services, LLC

    New York, NY
    5 days ago
  • $350k - $400k

     ...Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that... 
    Suggested
    Contract work
    Local area
    Shift work

    Barnes & Noble

    New York, NY
    1 day ago
  •  ...re building a smarter, faster, and more secure financial future by revolutionizing the...  .... About the team The Security & Information Technology organization is the backbone...  ...Global CTO, the Chief Information Security Officer (CISO) & Head of Information Technology... 
    Full time
    Contract work
    Temporary work
    Work at office
    Worldwide
    Home office
    Flexible hours

    Trustly

    New York, NY
    4 days ago
  •  ...Who are we? Cohere is the leading security-first enterprise AI company. We build cutting...  ...in Toronto and San Francisco, with key offices in London, New York City, Montreal,...  ...The Opportunity Cohere seeks a Chief Information Security Officer who can help shape Cohere... 
    Work at office
    Remote work

    Cohere

    New York, NY
    1 day ago
  • $125k - $160k

     ...Information Security Manager Key Responsibilities Responsible for delivering the programme/plans to ensure the Firm's information assets are adequately protected. Duties will include some or all of the following: Act as a trusted advisor on Information Security... 

    Linklaters

    New York, NY
    14 days ago
  • $150k - $200k

     ...Chief Information Security Officer (CISO) Vistrada is looking to hire strong Chief Information Security Officers (CISO). The CISO will provide strategic cybersecurity guidance and oversight to Vistrada clients by leading and managing their cybersecurity programs to... 
    Work experience placement
    Remote work
    Flexible hours

    VISTRADA

    New York, NY
    1 day ago
  •  ...Virtual Chief Information Security Officer (CISO) About the Company Flourishing provider of market research & business intelligence services Industry Market Research Type Privately Held About the Role The Company is in need of a Virtual Chief Information... 
    Part time

    Confidential

    New York, NY
    2 days ago
  • CHIEF INFORMATION SECURITY OFFICER THE POSITION IN A NUTSHELL Sciens is seeking a Chief Information Security Officer (CISO), who will be responsible for establishing and operating a right‑sized, risk‑based cybersecurity program that protects the company, supports growth... 
    Temporary work
    Work experience placement

    Sciens Building Solutions LLC

    New York, NY
    4 days ago
  • $300k - $400k

     ...principles grounded in accountability, teamwork, integrity, and solutions built to scale. Join us! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains:... 
    Work at office
    Local area
    Worldwide

    Tensec

    New York, NY
    12 hours ago
  • Chief Information Security Officer (CISO) US or Canada Location: Remote (U.S. or Canada) Type: US Applicants - Full‑Time; Canadian Applicants - Independent Contractor About Human Agency We’re scaling rapidly and have a growing pipeline of opportunities that demand exceptional... 
    Full time
    Contract work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Day shift

    Human Agency

    New York, NY
    12 hours ago
  • JOB SUMMARY Specialty Systems, Inc. has an opening for an Information Security Officer (ISO) with the below described skills and experience to join our team of technical professionals supporting our Department of Defense customer at the Joint Base MDL. In this position... 
    Work experience placement
    Local area
    Weekend work
    3 days per week

    Koitecc Solutions

    New York, NY
    1 day ago
  • $160k - $275k

     ...Technical Information Security Officer Royal Bank of Canada is seeking a Technical Information Security Officer to provide US regional cybersecurity leadership and ensure our operational security capabilities meet regulatory expectations and industry security standards... 
    Flexible hours

    RBC

    Jersey City, NJ
    1 day ago
  • $160k - $275k

     ...Technical Information Security Officer Royal Bank of Canada is seeking a Technical Information Security Officer to provide technical leadership in safeguarding sensitive and regulated data across our US operations. This is a strategic role that combines enterprise... 
    Full time
    Flexible hours

    RBC

    Jersey City, NJ
    1 day ago
  • $167.57k

     ...Information Security Officer, Affiliate Technology Services New York, New York, United States; Washington, District of Columbia, United States About The Job The ACLU seeks applicants for the full-time position of Information Security Officer, Affiliate Technology... 
    Full time
    Work at office
    2 days per week

    ACLU

    New York, NY
    4 days ago
  • Geo Owl is seeking an experienced Information System Security Officer (ISSO) to support the National Space Intelligence Center (NSIC) at Wright-Patterson AFB. The ISSO will serve as the primary cybersecurity and information assurance professional for a Special Access Program... 

    Geo Owl LLC

    Brooklyn, NY
    1 day ago
  • Koitecc Solutions is seeking an Information Security Officer (ISO) to support our Department of Defense customer at Joint Base MDL. This role involves ensuring cybersecurity compliance and assisting with risk management. Ideal candidates will have security engineering... 

    Koitecc Solutions

    New York, NY
    1 day ago
  • A cybersecurity firm is seeking a Senior Virtual Information Security Officer to provide CISO-level advisory services. In this non-implementational role, you'll guide strategy, mentor Virtual ISOs, oversee deliverables, and communicate effectively with client executives... 

    Hatch IT

    New York, NY
    12 hours ago
  • $300k - $375k

     ...regulatory compliance in everything we do. Join us and help build the future of global investing! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains:... 
    Full time
    Work at office
    Worldwide

    DriveWealth

    New York, NY
    4 days ago
  • $215k - $290k

     ...Description & Requirements What's the Role? As a Business Information Security Officer (BISO) for Finance, you will protect the confidentiality, integrity, and availability of the Finance department's information assets. You will identify and assess security risks... 
    Temporary work
    For contractors
    Work experience placement

    Bloomberg

    New York, NY
    3 days ago
  • $156.7k - $345.8k

     ...Business Information Security Officer, North America P&C Location: New York, NY; New Jersey; Boston, MA; or Philadelphia, PA Work Arrangement: Hybrid Reports To: Chief Business Technology Officer, North America P&C Employment Type: Full Time Help us insure it... 
    Full time

    Tokio Marine HCC

    New York, NY
    2 days ago
  • $160k - $275k

     ...the opportunity? Join RBC's newly established US Cyber Security & Resilience function as a strategic leader responsible...  ...initiatives across our US business units. As the Business Information Security Officer (BISO) (Global Security), you'll translate global security... 
    Full time
    Flexible hours

    RBC Capital Markets, LLC

    Jersey City, NJ
    5 days ago
  •  ...These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on...  ...related to intelligence. INTELLIGENCE AND INFORMATION SECURITY CAREERS IN THE NAVY INTELLIGENCE OFFICER Analyze top-secret information, interpret spy... 
    Full time
    Part time
    Worldwide

    U.S. Navy

    Queens, NY
    12 hours ago
  • $45 - $55 per hour

     ...as well as ensuring that you have the financial stability and security to think long term. Underpinning all of this is a clear set of...  ...an innovative force, where healthcare meets retail. For more information, visit     Business Structure The Joint Corp. is a franchisor... 
    Full time
    Part time

    The Joint Chiropractic

    New York, NY
    9 days ago
  • $40 - $50 per hour

     ...continues to grow, we are looking to bring an additional Chiropractor to our team. This is an exciting position! We are a friendly office with a great team! Our position is Part Time! 3 Days A Week! Mon, Wed, & Fri: 9am - 7pm No Weekends! We offer $40 - $50... 
    Hourly pay
    Part time
    Private practice
    Work at office
    3 days per week

    NSI Healthcare

    New York, NY
    23 days ago
  • $85k - $105k

    Job Description Job Description SportsMed Physical Therapy is fortunate to be one of the fastest growing multidisciplinary practices in New Jersey. The services we offer our patients are: Chiropractic, Physical Therapy, Occupational Hand Therapy, & Acupuncture. We ...

    SportsMed Physical Therapy

    Jersey City, NJ
    22 days ago
  • $500 - $600 per day

    Job Description Job Description Chiropractor - Staten Island, NY (#1648) Location: Staten Island, NY Employment Type: Full-Time or Part-Time Hourly Rate/Salary: $500−$600/day About Impact Recruiting Solutions: Impact Recruiting Solutions is a dedicated...
    Hourly pay
    Full time
    Part time
    Monday to Friday
    Flexible hours
    3 days per week

    Impact Recruiting Solution

    New York, NY
    9 days ago
  • $45k - $50k

    Job Description Job Description Job description: Join a Leading Chiropractic & Wellness Team in Manhattan! Location: Upper West Side, NYC (Directly Across from Central Park) Job Type: Part-time with the ability to move to Full Time. Base Salary: $45,000 –...
    Full time
    Part time
    Flexible hours
    2 days per week
    3 days per week

    CPW Wellness

    New York, NY
    11 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!