Information Security Officer
UniUni
UniUni is a late-stage last‑mile logistics company operating across the United States and Canada. We move millions of parcels for some of the largest e‑commerce platforms in North America, and our technology stack is cloud‑native, on AWS. We hold an active ISO 27001 certification and SOC 2 Type II attestation. Security and compliance are not afterthoughts at UniUni; they are central to our enterprise customer commitments, investor expectations, and the trust our drivers, shippers, and partners place in us every day. Role Snapshot Reports to: Chief Technology & Product Officer (CTPO) Location: North America (remote with periodic travel to UniUni hubs) Scope: Worldwide operations with focus on North America The Role We are hiring an Information Security Officer to lead UniUni’s security and governance function end to end. This is a hands‑on leadership role reporting directly to the CTPO. You will own the security program across cloud infrastructure, application security, data security and governance, corporate IT, compliance, and risk, and you will be the senior accountable owner for our ISO 27001 certification and SOC 2 Type II attestation. You will work closely with engineering, platform, IT, legal, and executive leadership, and you will be UniUni’s primary security voice in front of customers, auditors, and investors. You will build and lead a small, high‑leverage team and set the bar for how security operates as the business scales. Key Responsibilities Set the security posture of our AWS environments, including IAM, network segmentation, encryption, logging, secrets management, and workload protection. Drive cloud security baselines aligned to CIS Benchmarks and the AWS Well‑Architected Security Pillar, and enforce them through infrastructure as code and platform guardrails. Lead continuous monitoring and threat detection across cloud workloads using native AWS services (GuardDuty, Security Hub, CloudTrail, Config) and complementary third‑party tooling. Run vulnerability management for cloud infrastructure, including patching cadence, remediation SLAs, and exception governance. Application Security Embed secure development practices into the SDLC, including threat modeling, secure code review, SAST, DAST, SCA, and secrets scanning in CI/CD. Partner with engineering leaders to triage and remediate application vulnerabilities without slowing delivery. Run the open source software program, including license compliance, vulnerability tracking, and remediation. Manage the external penetration testing program, from scoping and vendor selection through findings triage and remediation verification. Set and evolve standards for authentication, authorization, session management, and API security across internal and customer‑facing applications. Deliver enterprise SSO (SAML 2.0 and OpenID Connect) for customer‑facing products in support of contractual security commitments. Data Security and Governance Own the data security program end to end, covering data classification, encryption in transit and at rest, key and secrets management, and protections against unauthorized access, exfiltration, and misuse. Maintain and evolve the data classification framework across UniUni’s regional and shared data warehouse environments, and drive schema‑level classification into operational use by engineering and analytics teams. Govern access to production databases, data warehouses, and analytics platforms, including approval workflows, periodic access reviews, and audit trails. Implement and operate data loss prevention controls across endpoints, email, SaaS, and cloud storage, calibrated to the sensitivity of the data and the realities of how the business operates. Set and enforce data residency, retention, and minimization standards in line with customer commitments and regulatory obligations across the jurisdictions in which UniUni operates. Partner with engineering, data, and product teams on privacy by design, including data flow mapping, data sharing agreements, and the secure handling of personal information for shippers, drivers, and end recipients. Lead the response to data subject requests, data incidents, and breach notification obligations under applicable privacy laws. Compliance and Governance Maintain and continuously improve UniUni’s ISO 27001 certification, including surveillance audits, internal audits, risk assessments, and management reviews. Sustain UniUni’s SOC 2 Type II attestation, owning control operation, evidence collection, auditor relationships, and remediation. Own the information security policy framework, including authoring, approval workflows, annual reviews, and employee attestations. Operate the risk management program, including the risk register, risk treatment plans, and executive risk reporting. Lead customer‑facing security activities, including security questionnaires, contract reviews, and security clauses in vendor and customer agreements. Support regulatory compliance efforts relevant to our business, including the DOJ Data Security Program, Canadian PIPEDA, and applicable US state privacy laws. IT Security and Operations Partner with IT to operate and mature endpoint security, including EDR, MDM (Intune), disk encryption, and device compliance. Govern identity and access across SaaS and corporate systems, including SSO adoption, MFA enforcement, privileged access controls, and joiner‑mover‑leaver processes. Own the SaaS inventory and run periodic access reviews, with particular attention to shadow IT and uncontrolled data flows. Lead security awareness training and phishing simulation programs. Run the incident response program, including the IR plan, tabletop exercises, on‑call rotation, and post‑incident reviews. Contribute to business continuity and disaster recovery planning in partnership with engineering and operations. Leadership and Stakeholder Engagement Build and lead a small security team, with hiring underway across two tracks: Compliance and GRC, and Application and Platform Security. Serve as UniUni’s senior security voice with customers, prospects, auditors, regulators, and investors. Report on security program status, KPIs, and risks to the CTPO and the executive team on a regular cadence. Represent security considerations in cross‑functional decisions across product, infrastructure, vendor selection, and business expansion. Required Qualifications 10+ years in information security, with at least 3 years owning a security program or a major security domain. Demonstrated ownership of ISO 27001 certification maintenance and SOC 2 audit execution in a cloud‑native organization. Deep hands‑on experience securing AWS environments at scale, including IAM, networking, logging, and workload protection. Strong application security background across secure coding practices, common vulnerability classes, and modern AppSec tooling (SAST, DAST, SCA, secrets scanning). Demonstrated experience building data security and governance programs, including data classification, encryption, DLP, access governance for data stores, and privacy‑aligned data handling. Practical experience with SAML 2.0 and OpenID Connect, and a track record of rolling out enterprise SSO and MFA. Experience operating core IT security controls, including EDR, MDM, and SaaS access governance. Track record of leading incident response, including coordination with engineering, legal, and executive stakeholders. Ability to translate security risk into business terms for non‑technical executives, customers, and investors, in writing and in person. Preferred Qualifications Background in logistics, supply chain, or high‑volume transactional businesses. Experience in an organization with worldwide cross‑border data flows and a focus on North America. Familiarity with the DOJ Data Security Program and bulk data transfer rules. Hands‑on experience with the Microsoft security stack (E5, Defender, Entra, Purview, Intune), and the perspective to evaluate it against alternatives such as CrowdStrike. Relevant certifications such as CISSP, CCSP, CISM, or ISO 27001 Lead Auditor or Lead Implementer. Prior experience taking a late‑stage company through IPO‑readiness security maturation. What You Will Find at UniUni A direct reporting line to the CTPO and regular exposure to the CEO, CFO, and the rest of the executive team. A security program with real executive commitment, a live ISO 27001 certification, and an active SOC 2 Type II attestation. Meaningful autonomy to shape the program and the team, balanced by the discipline and cadence of a late‑stage operating company. A growing business with the operational complexity, customer scrutiny, and learning opportunities that come with scale. How We Work We value direct, precise, and accurate communication. We prefer honest and defensible language over favorable framing. We write concise documentation, our meeting minutes stand up to auditor review, and we make decisions with our customers and our long‑term credibility in mind. UniUni is an equal opportunity employer. We evaluate candidates on the basis of qualifications, experience, and demonstrated ability, and we do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected characteristic. #J-18808-Ljbffr UniUni
- ...Chief Information Security Officer (CISO) About the Company Global organization modernizing enterprise risk, data governance, and cyber protection. Industry Internet Type Privately Held About the Role The Company is seeking a Chief Information Security...Suggested
- ...Chief Information Security Officer (CISO) About the Company Accomplished executive search firm Industry Staffing and Recruiting Type Privately Held About the Role The Company is seeking a Chief Information Security Officer (CISO) to oversee and...Suggested
- ...Description Job Description ISSO Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment...SuggestedFull timeLocal areaFlexible hours
- ...Job Description Job Description Information System Security Officer (ISSO) Employment Type: Full-Time, Mid-Level Department: Administrative and Logistics Support As a FSR ISSO, you will be embedded on-site with U.S. Government customers to ensure the secure...SuggestedFull timeFlexible hours
$350k - $400k
...Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that...SuggestedContract workLocal areaShift work- ...re building a smarter, faster, and more secure financial future by revolutionizing the... .... About the team The Security & Information Technology organization is the backbone... ...Global CTO, the Chief Information Security Officer (CISO) & Head of Information Technology...Full timeContract workTemporary workWork at officeWorldwideHome officeFlexible hours
- ...Who are we? Cohere is the leading security-first enterprise AI company. We build cutting... ...in Toronto and San Francisco, with key offices in London, New York City, Montreal,... ...The Opportunity Cohere seeks a Chief Information Security Officer who can help shape Cohere...Work at officeRemote work
$125k - $160k
...Information Security Manager Key Responsibilities Responsible for delivering the programme/plans to ensure the Firm's information assets are adequately protected. Duties will include some or all of the following: Act as a trusted advisor on Information Security...$150k - $200k
...Chief Information Security Officer (CISO) Vistrada is looking to hire strong Chief Information Security Officers (CISO). The CISO will provide strategic cybersecurity guidance and oversight to Vistrada clients by leading and managing their cybersecurity programs to...Work experience placementRemote workFlexible hours- ...Virtual Chief Information Security Officer (CISO) About the Company Flourishing provider of market research & business intelligence services Industry Market Research Type Privately Held About the Role The Company is in need of a Virtual Chief Information...Part time
- CHIEF INFORMATION SECURITY OFFICER THE POSITION IN A NUTSHELL Sciens is seeking a Chief Information Security Officer (CISO), who will be responsible for establishing and operating a right‑sized, risk‑based cybersecurity program that protects the company, supports growth...Temporary workWork experience placement
$300k - $400k
...principles grounded in accountability, teamwork, integrity, and solutions built to scale. Join us! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains:...Work at officeLocal areaWorldwide- Chief Information Security Officer (CISO) US or Canada Location: Remote (U.S. or Canada) Type: US Applicants - Full‑Time; Canadian Applicants - Independent Contractor About Human Agency We’re scaling rapidly and have a growing pipeline of opportunities that demand exceptional...Full timeContract workFor contractorsFor subcontractorWork at officeRemote workDay shift
- JOB SUMMARY Specialty Systems, Inc. has an opening for an Information Security Officer (ISO) with the below described skills and experience to join our team of technical professionals supporting our Department of Defense customer at the Joint Base MDL. In this position...Work experience placementLocal areaWeekend work3 days per week
$160k - $275k
...Technical Information Security Officer Royal Bank of Canada is seeking a Technical Information Security Officer to provide US regional cybersecurity leadership and ensure our operational security capabilities meet regulatory expectations and industry security standards...Flexible hours$160k - $275k
...Technical Information Security Officer Royal Bank of Canada is seeking a Technical Information Security Officer to provide technical leadership in safeguarding sensitive and regulated data across our US operations. This is a strategic role that combines enterprise...Full timeFlexible hours$167.57k
...Information Security Officer, Affiliate Technology Services New York, New York, United States; Washington, District of Columbia, United States About The Job The ACLU seeks applicants for the full-time position of Information Security Officer, Affiliate Technology...Full timeWork at office2 days per week- Geo Owl is seeking an experienced Information System Security Officer (ISSO) to support the National Space Intelligence Center (NSIC) at Wright-Patterson AFB. The ISSO will serve as the primary cybersecurity and information assurance professional for a Special Access Program...
- Koitecc Solutions is seeking an Information Security Officer (ISO) to support our Department of Defense customer at Joint Base MDL. This role involves ensuring cybersecurity compliance and assisting with risk management. Ideal candidates will have security engineering...
- A cybersecurity firm is seeking a Senior Virtual Information Security Officer to provide CISO-level advisory services. In this non-implementational role, you'll guide strategy, mentor Virtual ISOs, oversee deliverables, and communicate effectively with client executives...
$300k - $375k
...regulatory compliance in everything we do. Join us and help build the future of global investing! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains:...Full timeWork at officeWorldwide$215k - $290k
...Description & Requirements What's the Role? As a Business Information Security Officer (BISO) for Finance, you will protect the confidentiality, integrity, and availability of the Finance department's information assets. You will identify and assess security risks...Temporary workFor contractorsWork experience placement$156.7k - $345.8k
...Business Information Security Officer, North America P&C Location: New York, NY; New Jersey; Boston, MA; or Philadelphia, PA Work Arrangement: Hybrid Reports To: Chief Business Technology Officer, North America P&C Employment Type: Full Time Help us insure it...Full time$160k - $275k
...the opportunity? Join RBC's newly established US Cyber Security & Resilience function as a strategic leader responsible... ...initiatives across our US business units. As the Business Information Security Officer (BISO) (Global Security), you'll translate global security...Full timeFlexible hours- ...These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on... ...related to intelligence. INTELLIGENCE AND INFORMATION SECURITY CAREERS IN THE NAVY INTELLIGENCE OFFICER Analyze top-secret information, interpret spy...Full timePart timeWorldwide
$45 - $55 per hour
...as well as ensuring that you have the financial stability and security to think long term. Underpinning all of this is a clear set of... ...an innovative force, where healthcare meets retail. For more information, visit Business Structure The Joint Corp. is a franchisor...Full timePart time$40 - $50 per hour
...continues to grow, we are looking to bring an additional Chiropractor to our team. This is an exciting position! We are a friendly office with a great team! Our position is Part Time! 3 Days A Week! Mon, Wed, & Fri: 9am - 7pm No Weekends! We offer $40 - $50...Hourly payPart timePrivate practiceWork at office3 days per week$85k - $105k
Job Description Job Description SportsMed Physical Therapy is fortunate to be one of the fastest growing multidisciplinary practices in New Jersey. The services we offer our patients are: Chiropractic, Physical Therapy, Occupational Hand Therapy, & Acupuncture. We ...$500 - $600 per day
Job Description Job Description Chiropractor - Staten Island, NY (#1648) Location: Staten Island, NY Employment Type: Full-Time or Part-Time Hourly Rate/Salary: $500−$600/day About Impact Recruiting Solutions: Impact Recruiting Solutions is a dedicated...Hourly payFull timePart timeMonday to FridayFlexible hours3 days per week$45k - $50k
Job Description Job Description Job description: Join a Leading Chiropractic & Wellness Team in Manhattan! Location: Upper West Side, NYC (Directly Across from Central Park) Job Type: Part-time with the ability to move to Full Time. Base Salary: $45,000 –...Full timePart timeFlexible hours2 days per week3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!
- remote ciso New York, NY
- chief information security officer New York, NY
- information security officer iso New York, NY
- ciso New York, NY
- chief information security officer ciso New York, NY
- information security officer New York, NY
- business information security officer New York, NY
- information security lead New York, NY
- information security internship New York, NY
- entry level information security analyst New York, NY



