CREDIT OPERATIONS ASSOCIATE
The Iron Sheepdog is seeking a Lead Information Security & Compliance Specialist to spearhead our security initiatives and governance frameworks. The role requires bridging the gap between high-level compliance and hands-on technical security engineering, managing compliance pipelines, protecting fintech workflows, and championing a security-first culture.
Key Responsibilities
Compliance Leadership: Lead and manage the end-to-end process of achieving and maintaining SOC 2 compliance.
Policy & Governance: Create, enforce, and govern comprehensive IT and Information Security policies across the entire organization.
Client Security Liaison: Serve as the primary security liaison for enterprise clients, confidently answering complex security questionnaires and navigating financial audits.
Vendor Management: Interface directly with client security teams, respond to vendor security questionnaires, and optimize IT Managed Service Provider (MSP) relationships.
Security Engineering: Act as a hands-on security engineer to review and improve secure coding practices across our React and Node.js codebase, ensuring the safety of our fintech workflows.
Vulnerability & DevSecOps Management: Manage and monitor DevSecOps tools like Snyk to catch vulnerabilities early in the CI/CD pipeline.
Testing & Infrastructure Security: Conduct internal penetration tests, review Firebase/Firestore security rules, and rigorously develop disaster recovery plans.
AI Security Implementation: Design and execute vulnerability testing specifically for our AI features, running prompt injection tests against our LLMs and chat-bots to ensure data integrity.
Security Culture: Take full ownership of company-wide security awareness training, actively building an internal culture of vigilance and security awareness.
Job Requirements & Skills
Core Requirements (Must Have):
SOC 2 Expertise: Experience managing/leading the end-to-end process of achieving and maintaining SOC 2 compliance, OR comparable/translatable audit and compliance frameworks (e.g., ISO 27001, HIPAA, PCI-DSS).
SaaS & Industry Background: A proven background working within SaaS environments, with a strong preference for candidates experienced in logistics, supply chain, or short-haul trucking platforms (specifically dealing with truck routing and fleet dispatch).
Enterprise Experience: Proven experience serving as a primary security contact for medium to large enterprises.
Ecosystem Exposure: Strong exposure to secure processes for diverse, interconnected ecosystems across web, mobile, cloud infrastructure, and APIs.
Technical & Next-Level Requirements:
Codebase Security: Ability to work hands-on with React and Node.js codebases to implement secure coding practices.
Tooling & Testing: Direct experience with DevSecOps tools (e.g., Snyk), CI/CD pipelines, internal penetration testing, and Firestore/Firebase security rule governance.
AI Vulnerability Testing: Experience or strong capability in running prompt injection tests and securing LLM-powered chatbots.