Security & Compliance Lead
Full-time
Glimpse
ABOUT GLIMPSE
Glimpse is the leading AI platform for CPG brands — automating critical back-office workflows like deductions management, revenue recovery, and cash application. Since launching in April 2024, we've grown from 0 to 200+ customers, raised $52M from investors including a16z, 8VC and Y Combinator. Our AI agents retrieve deduction data, validate charges, automate cash application, and dispute invalid claims — work that would take a full-time employee years to complete. For a $1B CPG brand, a single Glimpse agent reviewed 17,000 deductions in under 24 hours, identifying over $10M in recoverable revenue. We're building the next-generation suite of services for consumer brands and are looking for exceptional people to help us scale. About the role We're a fast-growing startup with a small but talented engineering team, and we're hiring our first Security & Compliance Lead to build the foundation for our security program. This is a high-ownership, high-autonomy role with a broad mandate: you'll own the security and compliance surface end-to-end, from access management and SOC 2 to infrastructure security and customer trust. You'll report to CTO with full ownership of the security and compliance domain. In year one, the work skews toward access management, SOC 2, and customer-facing security. Over time, the role grows into broader security engineering: monitoring, incident response, vendor risk, and architecture review. If you've built a security program from scratch before and liked it, you'll recognize this job. If you want to build something from the ground up rather than slot into an existing program, read on. What you'll own Access & identity management. Production access, service accounts, SSO, and the lifecycle of both - provisioning, periodic review, deprovisioning. SOC 2. You'll own the program end-to-end, mapping controls to our environment, driving evidence collection, and getting us through Type 1 and then Type 2 and other security frameworks. Customer trust. You'll own security questionnaires, RFP security sections, and the customer-facing trust narrative (trust center, security overview docs, DPAs). Infrastructure security. VM lifecycle and patching, baseline hardening, secrets management, vulnerability management, and cloud security posture. Security engineering (over time). Logging and monitoring, incident response runbooks, vendor security reviews, and partnering with engineering on secure design. What we're looking for 5+ years in security or security-adjacent roles You've driven a SOC 2 audit - ideally owned one end-to-end, but if you ran the bulk of a program under a fractional CISO or security leader, that counts Comfortable in cloud environments (AWS, GCP, or Azure) and writing enough code or Terraform to automate access and infrastructure workflows You've owned customer security questionnaires and know how to make them faster Strong written communication Nice to have A previous tour as the first or early security hire at a startup Experience with identity tooling (Okta, AWS IAM Identity Center, Teleport, ConductorOne) Experience with compliance platforms (Vanta, Drata, Secureframe) Other frameworks beyond SOC 2 (ISO 27001, HIPAA, FedRAMP) Background in security engineering, detection, or incident response Traits that do well here High ownership: you don’t just advise - you drive the work to completion. Systems thinking: you can reason about messy workflows and design something scalable, not one-off. Customer empathy + backbone: you listen deeply, then confidently set boundaries and callout tradeoffs. Fast learner: you ramp into new domains and tools quickly.WHY JOIN GLIMPSE
You'll join a company that has found genuine product-market fit and is scaling fast — with the infrastructure, capital, and team to match. Your work will directly shape how hundreds of CPG brands run their back office. And you'll have real ownership: of your accounts, your outcomes, and the AM function itself as we build it from the ground up. Competitive salary with meaningful equity In-person team in NYC – high ownership, fast feedback loops Direct impact on a company growing at an exceptional pace A front-row seat to building the operating system for CPG brands Location: Prime Midtown location — Penn Station, Madison Square Garden, and the city's best transit connections right at your door. *Moving to a new location in August GLIMPSE is an Equal Employment Opportunity Employer. GLIMPSE will consider all qualified applicants for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, marital status, disability, veteran status or any other characteristic protected by law.Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Security & Compliance Lead in New York, NY vacancy
$300k - $400k
...Security Manager You'll own security from groundbreaking to go-live on greenfield data center campus builds, shaping how every site... ...an operator who's equally comfortable auditing guard force compliance against post orders and being elbow-deep in Electronic Security...SuggestedContract workLocal area- A leading compliance firm in the United States is seeking a Senior Compliance Advisor to lead FedRAMP compliance and cloud security initiatives. The ideal candidate will have a Bachelor's in IT or Cybersecurity, 5+ years of experience in cloud compliance, and strong project...Suggested
- A financial services organization is seeking a Virtualization Security & Compliance Consultant to conduct a thorough security audit and enhance the security of their virtual infrastructure. The ideal candidate will have over 6 years of experience in IT security, with at...Suggested
- Crimsafe Security Systems is seeking a Part-Time Brand Protection Manager to join their team in Kentucky. In this pivotal role, you will design, implement, and oversee compliance programs to protect the Crimsafe brand and ensure contractual obligations are met. The ideal...SuggestedPart time
- A leading security consulting firm is seeking a Security Programs Specialist in Kemmemer, Wyoming. This remote position requires extensive expertise in nuclear security, access authorization, and compliance with regulations. Ideal candidates will have a Bachelor's degree...SuggestedRemote job
$132.6k - $195k
Remote Jobs is seeking a highly motivated Sr. Security Compliance Specialist to scale DoorDash's global compliance program. This role involves conducting internal and external audits, with an emphasis on SOC and PCI DSS compliance, and requires strong collaborative skills...Remote work- A community support organization is seeking a Security Shift Supervisor to oversee safety and security at its shelter in New York City. This role will manage staff and ensure compliance with safety procedures while supporting residents. Candidates should have a commitment...Hourly payShift work
- A certified women-owned business in the US seeks a Mainframe Top Secret Security Administrator to oversee data security and compliance. This role, which can be performed remotely, requires extensive experience in TSS and z/OS administration. The ideal candidate will manage...Remote job
- A government service provider in New York is seeking an Information System Security Officer (ISSO) to manage security and compliance for U.S. Government projects. In this role, you will work hands-on with systems, ensuring that security requirements are met while collaborating...
$107.7k - $199.3k
Remote Jobs is hiring a Security Compliance Lead Information Risk Analyst responsible for oversight of security governance, compliance execution, and leading complex initiatives across the enterprise. This role requires 6+ years of experience in auditing and IT controls...Remote jobFlexible hours$140k - $190k
GovSignals, based in New York, is seeking a Compliance Operations Lead to own its security and compliance posture. You will architect the compliance program for FedRAMP High, IL5, CMMC Level 2, and SOC 2, ensuring readiness and partnering with engineering teams. The ideal...- EMI Services seeks to hire a Site Lead for the USAF ACC Primary Training Range contract at Grand Bay Range... ...her location’s Range Operations, Maintenance, and Compliance. The Site Lead will also manage training, security, and environmental programs, ensuring high-quality...Contract workFor contractors
$150k - $240k
Profound is seeking a Security GRC Specialist to take charge of security and compliance programs in New York City. This role involves managing compliance frameworks like SOC 2 and ISO 27001, driving audits, and collaborating with engineering to design security controls....- A leading law firm is seeking a Manager of Document Management Systems to oversee the strategic governance, user adoption, and security compliance of document management systems. The ideal candidate will have over 5 years of legal technology experience, strong skills in...
$25 per hour
Security Industry Specialists, Inc. is seeking a Lead Officer to ensure compliance with security standards and policies in the New York area. This role involves overseeing security operations, client liaison, and responding to emergent issues. The ideal candidate must...Hourly pay$120k - $155k
Claritev Corporation is seeking a professional focused on information security compliance within the healthcare sector. The incumbent will enhance governance processes, assist with compliance activities, and support audit readiness in a highly regulated environment. Key...- A leading fintech company in New York is seeking a Senior GRC Lead who will bridge compliance expertise with technical execution. You will manage critical GRC processes to enhance... ...have over 5 years of experience in GRC or Security Engineering and proficiency in key...Work at office
- Radar Labs, Inc. is seeking a Senior GRC Analyst to enhance their security and compliance programs with a focus on third-party risk. This role involves collaborating with multiple teams, evaluating modern SaaS and AI tools, and improving risk management workflows. The ideal...Flexible hours
- A leading cybersecurity firm is seeking a Senior Security Compliance Engineer to drive technical implementation and maintenance of FedRAMP High and DoD IL5 compliance for AWS products. The role requires extensive experience in cloud security, with a focus on regulatory...Remote work
- Israelvcforum is seeking an Information Security Policy and Implementation Specialist to join their TELUS Health Information Security Team. You will lead the development of security policies, ensure compliance with security regulations, and drive policy initiatives across...
- A leading information security platform is seeking an Information Security Consultant to establish and maintain a corporate-wide information security management program. Responsibilities include suggesting improvements to clients' security policies, preparing documentation...Remote job
- ...Job Description Job Description Lead Fire Alarm Technician About the Company Allstate Sprinkler is an affiliated company... ...With a strong commitment to quality workmanship and regulatory compliance, Allstate partners with building owners, property managers, and...Hourly payTemporary workFor contractorsLocal area
- ...firm in New York is seeking a Senior Salesforce Architect to lead secure, government-grade cloud Salesforce deployments. This role combines... ...design architecture and manage integrations while ensuring compliance. Strong experience in regulated environments and excellent...Hourly payFlexible hours
- Overstory is looking for a talented Senior Security Engineer to enhance the company's security and compliance posture. The ideal candidate will lead security initiatives across vulnerability management, compliance, and security operations while collaborating with various...Remote workFlexible hours
- A security consulting company in the United States is looking for a GRC Analyst II to support governance programs for clients. In this role, you will onboard customers, perform gap assessments, and develop security policies. The ideal candidate will have 2-3 years in information...
- Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance policies, and performing risk assessments. Candidates should have over 6 years of experience in...Remote workFlexible hours
- Zafran Security, based in New York, is looking for a Senior DevOps Engineer to enhance their security and compliance posture. This role involves leading technical work for compliance certifications, designing security controls across AWS infrastructure, and collaborating...Remote jobFlexible hours
- Secureframe is seeking a Senior Federal Compliance Manager to lead assessments for federal cybersecurity frameworks and enhance software for federal contractors. The role involves interpreting NIST-based controls, collaborating with engineering teams, and ensuring compliance...For contractors
- ...seeking a Manager of Health Information Management to oversee the integrity and security of patient health information across our services. You will lead and support a team ensuring compliance with all healthcare regulations while collaborating with healthcare providers...Remote jobFull time
- Perdue Farms is seeking a Safety Manager to lead the safety initiatives across its manufacturing complex in Kentucky. This role focuses on building a strong safety culture and ensuring compliance with OSHA regulations and industry standards. The ideal candidate will have...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security & Compliance Lead. Be the first to apply!
Related searches
- regulatory compliance engineer New York, NY
- compliance examiner New York, NY
- regulatory affairs part time New York, NY
- compliance lead New York, NY
- regulatory affairs consultant New York, NY
- compliance aml New York, NY
- director quality assurance regulatory affairs New York, NY
- pharmaceutical regulatory affairs New York, NY
- compliance paralegal New York, NY
- compliance reviewer New York, NY


