Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security & Compliance Manager

Givebutter

Security & Compliance Manager

Givebutter is hiring a Security & Compliance Manager to own Givebutter's security function. Your primary mandate is to further harden our critical systems, codify our security roadmap, and implement controls in close partnership with our Product, Design & Engineering (PDE) team. You will also own our certification program (SOC 2, and eventually ISO 27001) and assist with licensing and registration compliance across all US jurisdictions.

This is a hands-on, high-autonomy role for someone who has lived through the security challenges of a growth-stage fintech and knows what it takes to build real defenses, not just check boxes. You will report directly to the General Counsel and work cross-functionally with PDE, Trust & Safety, IT, and Finance.

We want to hear from people who...

  • Have 7+ years of experience in information security, security engineering, GRC, or a related field, with at least 4 years in a fintech, payments, or financial services environment
  • Have hands-on experience hardening production systems at a growth-stage company, not just writing policies about them
  • Possess deep working knowledge of SOC 2, PCI DSS, and at least one additional framework (NIST CSF, CIS Controls, ISO 27001)
  • Understand modern AI-era threat vectors and can articulate a defensive strategy against them
  • Have technical fluency: you can read a cloud infrastructure diagram, understand why a GitHub permissions model matters, evaluate a pen test report, and translate all of it into actionable guidance for engineering teams
  • Have managed GRC tools hands-on (Vanta, Drata, Secureframe, or similar) and driven remediation workflows to closure, not just monitored dashboards
  • Have led external audits end-to-end: auditor relationships, evidence collection, findings remediation, and board-level reporting
  • Can build programs, not just maintain them: you thrive in environments where the playbook doesn't exist yet and you need to write it
  • Communicate complex security and regulatory topics in plain language to non-technical stakeholders
  • Have strong judgment about when to escalate, when to act independently, and when to push back

Bonus Points

  • CISSP, CISM, CISA, or CEH certification
  • Familiarity with AI security frameworks: NIST AI RMF, MITRE ATLAS, OWASP AI Security and Privacy Guide
  • Experience with BSA/AML program design, SAR filing, or OFAC sanctions screening
  • Experience managing bank partner or sponsor bank compliance relationships
  • Familiarity with Stripe's platform, APIs, and compliance tools
  • Prior experience at a company operating in the charitable giving, nonprofit, or crowdfunding space
  • Experience with state charitable fundraising platform/solicitation registration requirements
  • Track record of building compliance or security programs at a Series A through Series D stage company
  • CAMS or CRCM certification

Responsibilities

Security Roadmap & Systems Hardening

  • Codify and execute the security roadmap for the organization, prioritizing the further hardening of critical systems (payment infrastructure, donor data stores, authentication flows, API integrations) and ensuring compliance with applicable laws (e.g., data privacy and security).
  • Partner directly with PDE leadership to embed security controls into the development lifecycle: threat modeling, secure code review, vulnerability management, and CI/CD pipeline security tooling (SAST, DAST, SCA)
  • Own the security incident response plan end-to-end: detection, containment, investigation, notification, remediation, and post-incident review
  • Work with IT to drive identity and access management improvements, including role-based access controls, MFA enforcement, endpoint security, and session management
  • Develop a deep understanding of fraud vectors in the fundraising and payments space—stolen cards, synthetic identities, friendly fraud, campaign abuse—and help us build systems that adapt as threats evolve.
  • Manage vendor security risk assessments for third-party tools, integrations, and sub-processors, with continuous monitoring rather than annual check-ins
  • Own the penetration testing program: vendor relationships, testing cadence, findings translation into engineering tickets, and remediation tracking to closure
  • Develop and deliver security awareness training for all employees, with targeted modules for PDE, CX, and leadership audiences

Certifications & Audit Management

  • Lead SOC 2 Type II certification end-to-end: gap analysis, control design, evidence collection, remediation tracking, auditor coordination, and ongoing maintenance
  • Build the roadmap toward ISO 27001 certification as the security program matures
  • Serve as primary owner of our GRC platform (Vanta): driving task completion, monitoring compliance gaps, triaging findings, and ensuring remediation owners are accountable
  • Manage all external auditor and certification body relationships
  • Build and maintain evidence repositories that support continuous (not just point-in-time) compliance
  • Prepare board-ready compliance status reports and risk summaries quarterly

Licensing & Registration Compliance

  • With the General Counsel's guidance, own all required licenses, registrations, and regulatory filings across US jurisdictions, including state charitable fundraising platform registrations and other licenses
  • Manage the Trust Center: content accuracy, access approvals, and customer-facing compliance documentation

Requirements

  • 7+ years of experience in information security, security engineering, GRC, or a related field, including at least 4 years within a fintech, payments, or financial services environment
  • Hands-on experience hardening production systems at a growth-stage company (Series A–D or equivalent), including areas such as IAM, application security, infrastructure security, vulnerability management, or secure SDLC practices
  • Deep working knowledge of SOC 2 and PCI DSS, plus hands-on experience with at least one additional security framework such as NIST CSF, ISO 27001, or CIS Controls
  • Experience leading external security audits end-to-end, including auditor management, evidence collection, remediation tracking, and executive or board-level reporting
  • Hands-on experience administering GRC/compliance platforms such as Vanta, Drata, Secureframe, or similar, including driving remediation workflows to closure
More About Givebutter

Benefits

  • Remote Work: Work remotely from one of our 10 hubs (Austin, Denver, Indianapolis, Los Angeles, San Francisco, New York, Salt Lake City, Minneapolis, Seattle, and Nashville).
  • Health Insurance: We offer Medical, Dental, and Vision insurance covered 100% for employees as well as HSA and FSA accounts.
  • Dependent Care Coverage: We offer coverage for dependents, with 50% of Medical, Dental, and Vision premiums covered for all eligible dependents.
  • Mental Health: Givebutter health insurance plans come with access to a TalkSpace membership.
  • 401k: We offer a 3% 401k match for all eligible employee's.
  • Vacation and Holidays: Givebutter offers a Flexible PTO policy with uncapped vacation days and company-recognized holidays.
  • Wellness Week: Givebutter closes for one week each summer to prioritize rest and recharge for the entire team.
  • Parental Leave: We offer 12 weeks of paid leave for all parents and comprehensive leave planning management through Aidora.
  • Family Care Support: Access a company-paid UrbanSitter membership plus care credits to book trusted, background-checked caregivers for childcare, senior care, pet care, and household support when you need it most.
  • Home Office Stipend: Upgrade your home office with company-sponsored expenses, including high-quality laptops, monitors, and modern technology.
  • Coworking Stipend: Enjoy a monthly stipend that gives you the freedom to work from coworking spaces or cafés whenever you need connection, community, or a change of scenery.
  • Charitable Giving: Employees are encouraged to donate up to $50/month to any verified nonprofit they wish to support on Givebutter.
  • Professional Development: We offer learning and development reimbursement opportunities.
  • Love What You Do: We are a mission-driven company serving the charitable sector. Feel good about the work you're doing and the company you work for.

Interview Process

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Security & Compliance Manager in United States vacancy
  •  ...A company is looking for a Security Compliance Manager. Key Responsibilities Lead security certification and audit readiness for ISO 27001 and SOC 2 Operate and manage the ISMS controls program, ensuring effective and scalable controls Prepare for audits by organizing... 
    Suggested
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  • $140k - $170k

     ...mission to advance clinical research and improve patient care. One mission. One team. That's OneStudyTeam. The Security Compliance Manager leads the organization's security compliance and assurance efforts-ensuring we meet and maintain certification requirements... 
    Suggested
    Full time
    Work at office
    Remote work
    Visa sponsorship
    Work visa

    OneStudyTeam

    United States
    2 days ago
  • $65k - $110k

     ...A global fintech firm is seeking a compliance specialist to own their compliance program across regulations like SOC 2 and GDPR. The ideal...  ...3–7 years of experience in compliance, with strong program management skills and attention to detail. This role offers a remote work... 
    Suggested
    Remote work

    P2P

    United States
    4 days ago
  •  ...being while providing the most comprehensive and accessible care possible. As Rezilient scales, we are looking to add a Security and Compliance Manager to our growing team. This key member of the team will be responsible for executing and coordinating the company's... 
    Suggested
    Contract work
    Remote work

    Rezilient Health

    United States
    1 day ago
  •  ...Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra...  ...and data platforms. Build a centralized and evolving security controls library mapped to compliance, regulatory and customer requirements. Continuously... 
    Suggested
    Full time
    Flexible hours

    Sierra

    San Francisco, CA
    5 days ago
  • $140k - $180k

     ...Security Compliance Manager We are looking for a highly motivated Security Compliance Manager with a deep security and compliance background to lead system development and process improvement. As part of Hive's Security Team, you will collaborate with engineers and... 

    Hive

    San Francisco, CA
    3 days ago
  • The Security and Compliance Manager will be responsible for spearheading all facets of information security, including compliance, risk management, vulnerability management, and daily security operations. They will be involved in developing and implementing robust security... 
    Temporary work
    Work experience placement
    Flexible hours

    Core BTS

    Indianapolis, IN
    2 days ago
  •  ...specializes in the delivery of professional business and information management services. STI-TEC offers government and commercial clients...  ...Office (MMO).   In this cutting-edge new MMO the Security Compliance Manager will manage security protocols across programs,... 
    Contract work
    For contractors
    For subcontractor
    Work at office

    Dynamics ATS Organic

    Dayton, OH
    11 days ago
  • $115k

     ...Safety And Security Manager About Wonder Everything's on the menu at Wonder. Except compromise. Wonder is the mealtime platform...  ...diagnose the root cause and implement the cure. Closing the Compliance Loop: Partner with the EHS Data, Systems & Compliance... 
    Permanent employment
    Work at office
    Shift work

    Wonder

    New York, NY
    1 day ago
  • $53.75 per hour

     ...About the job SECURITY COMPLIANCE PROJECT MANAGERMax Pay Rate: $53.75Work Arrangement: RemoteAgency Interview Type: Web Cam Interview Only....  ...resumes will be considered.Short Description:The IT Project Manager will provide project management support to DHS Security Team... 

    Padmore Global Connections LLC

    Atlanta, GA
    1 day ago
  •  ...remaining at the forefront of innovation. Every day, we work to secure what our clients value most, from their families to their...  ...Job Details Position Summary The Security Training & Compliance Manager - Healthcare Services is responsible for developing,... 
    Contract work
    Summer work
    Work at office
    Remote work
    Flexible hours
    Weekend work
    Afternoon shift

    Prosegur Security USA

    Bridgeport, CT
    5 days ago
  • $140k - $165k

     ...Security, IT and Compliance Manager Applied Research Laboratories (ARL) is seeking a research laboratory-level IT, Security & Compliance Manager to lead secure IT operations and regulatory compliance for a defense-focused applied research environment. This role ensures... 
    For contractors
    Work at office
    Immediate start
    Afternoon shift

    The University of Texas at Austin Staff

    Austin, TX
    3 days ago
  • $140k - $165k

     ...Job Posting Title: Security, IT and Compliance Manager ---- Hiring Department: Applied Research Laboratories ---- Position Open To: All Applicants ---- Weekly Scheduled Hours: 40 ---- FLSA Status: Exempt from FLSA ---- Earliest... 
    For contractors
    Work at office
    Immediate start
    Afternoon shift

    University of Texas at Austin

    Austin, TX
    2 days ago
  • Altaaerotechnic in Greensboro, NC, is seeking a Manager of Security responsible for leadership and oversight of security operations. This...  ...managing the Ground Security Coordinator program, ensuring compliance with DOT, FAA, and company regulations. The ideal candidate... 

    Altaaerotechnic

    Greensboro, NC
    5 days ago
  • Goeasternair in Greensboro, NC is seeking a Manager of Security to oversee security operations and training compliance. The role involves managing the Ground Security Coordinator program and training employees on security protocols in line with FAA regulations. Candidates... 
    Full time

    Goeasternair

    Greensboro, NC
    2 days ago
  • Wayspring is seeking a Manager of Security (Governance, Risk & Compliance) to protect its mission and reputation. This role involves key responsibilities such as managing HIPAA and HITRUST compliance, overseeing vendor risks, and shaping security programs that embed compliance... 

    Wayspring

    Nashville, TN
    1 day ago
  •  ...strategic oversight and direction over the company’s compliance in multiple information control domains. The position will manage and lead the implementation of CMMC L2. This...  ...flows throughout the organization, supporting security protocols and regulatory requirements.Develop... 

    Mustang Survival Mfg Inc

    Jacksonville, FL
    3 days ago
  • A diversified financial service provider seeks a Security Compliance Manager to enhance their enterprise security compliance program. Responsibilities include managing compliance operations, tracking security exceptions, and overseeing documentation. The ideal candidate... 
    Remote job

    CardWorks, Inc.

    Orlando, FL
    5 days ago
  • Eastern Airlines LL is seeking a Manager of Security in Greensboro, NC. This full-time position involves overseeing security training, managing compliance with FAA regulations, and leading the Ground Security Coordinator program. The ideal candidate will possess a Bachelor... 
    Full time

    Eastern-Airlines-LL

    Greensboro, NC
    4 days ago
  • $111.37k - $163.35k

     ...shaping the future of identity centric security solutions. From our comprehensive portfolio...  ...our Data Security Services (DSS) Compliance team, as it relates to leading projects...  ...position functions as part of a Product Management Compliance team responsible for ensuring... 
    Remote work
    Relocation
    Flexible hours

    Entrust

    Shakopee, MN
    1 day ago
  • $80k - $120k

    SAIC is looking for a Security Manager in Camp Smith, HI, to lead security programs for sensitive government operations. The candidate must...  ...and physical security, developing policies, ensuring compliance, and handling incidents. A bachelor's degree in a related field... 

    SAIC

    Waipahu, HI
    4 days ago
  • $122k - $237k

    Security Compliance - Technical Program Manager - Weights & Biases CoreWeave, the AI hyperscaler, has acquired Weights & Biases to create the most powerful end‑to‑end platform for AI development, deployment, and iteration. Since 2017 CoreWeave has built a global footprint... 
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    Weights & Biases

    New York, NY
    4 days ago
  • $122.2k - $174.6k

    Gainwell Technologies is seeking a Senior Manager of Security Compliance to oversee a team ensuring compliance for state-based customers. This role demands extensive experience in Security Compliance and Audit Management, preferably within a healthcare context. Exceptional... 
    Remote job
    Flexible hours

    Gainwell Technologies

    Wisconsin
    14 hours ago
  • $500 per month

     ...includes broker‑dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 6...  ..., we encourage you to apply. Your Role Join Alpaca Securities’ dynamic and fully remote AML Compliance team dedicated to safeguarding the integrity of the... 
    Remote work
    Home office

    Framework Ventures

    New York, NY
    4 days ago
  •  ...Framework Ventures is seeking an AML Compliance Manager to join its fully remote team. The role involves leading AML investigations, ensuring compliance with regulations, and enhancing internal controls. Ideal candidates should have 5-8 years of experience in AML or financial... 
    Remote work
    Home office

    Framework Ventures

    New York, NY
    4 days ago
  •  ...Title: Compliance Manager (Information Security) Reports to: Vice President of Legal and Compliance Location: North Sioux City, SD Job Description: The Compliance Manager (Information Security) will be an integral part of the Legal & Compliance (L&C... 
    Work at office

    Sterling Computers

    North Sioux City, SD
    2 days ago
  • $100k - $180k

    Anser is looking for a Security Manager in Hawaii to support the Foreign Disclosure Program. This role involves leading daily security operations, managing personnel security actions, and ensuring compliance with DoD security requirements. Applicants must have an active... 

    Anser

    Honolulu, HI
    3 days ago
  •  ...maintain the organization's comprehensive data governance and security, privacy and compliance frameworks and policies.  Serve as the Privacy Officer...  ..., risk assessments, and incident response planning Manage relationships with outside counsel, regulators, and third... 
    Remote work

    Bask Health

    United States
    4 days ago
  •  ...As the Director Information Security & Compliance at DBMG, you'll be responsible for establishing and maintaining the information security...  ...senior business leaders as part of a strategic enterprise risk management program. • Develop, maintain, and continuously improve... 
    For contractors
    Work experience placement
    Work at office
    Afternoon shift

    DBM Global Inc

    Phoenix, AZ
    2 days ago
  •  ...Manager Of Security And Compliance (Grc) As the Manager of Security and Compliance (GRC), you will oversee the programs that protect our organization and customers through effective risk management, regulatory compliance, and customer trust. This role focuses on maintaining... 
    Local area
    Remote work
    Flexible hours

    Tapcheck

    Plano, TX
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security & Compliance Manager. Be the first to apply!