Manager Corporate Technology (Security & IT)
At Caribou, we care about giving people financial freedom so they can focus on what’s most important to them. Today, less than two percent of Americans refinance their auto loans despite drastic increases in the cost of new and used cars. We see huge potential to help folks reduce their monthly auto expenses, as well as increase the predictability of those expenses over time. We do this by building technology to pair customers with community banks and credit unions, and ushering them through the process quickly. On average, our drivers save $162/month on their car loans while protecting their investment long term. Caribou is led by leaders from the technology, automotive, and finance industries. We’re proud to be backed by a great team of investors, including QED Investors, Goldman Sachs, Moderne Ventures, Accomplice, Link Ventures, Motley Fool Ventures and others.
About the Role
Maybe you came up through security—incident response, GRC, compliance programs—and over time took broader ownership of the tools and systems that make a company capable. Or you came up through IT and digital workplace leadership, and earned your security credentials by stepping into the function when your company needed it. Either path lands you in the same place: someone who can guide a senior security team, run the SaaS and AI tools portfolio, and build the enablement motion that turns licensed software into actual productivity.
On the security side, that means you've been the person who delivered a SOC 2 audit, not just the person in the room. You've tuned a SIEM, led an incident, and written GRC controls that held up under scrutiny. On the IT side, that means you've run a SaaS portfolio, built adoption programs that changed how people work, held real accountability for identity and access, and have the instinct to build an AI enablement program for employees who don't write code. What matters is that you've done both meaningfully, not which one came first.
You will own Caribou’s security and IT programs. Your team includes three senior security practitioners and a senior IT administrator. You set the direction, hold the strategy and vendor relationships, and keep the programs advancing. We believe CTech works best as a partnership with employees, not a policing function—you'll keep it that way. This role reports directly to the CTO, designed for a leader who wants to evolve the function and grow their career alongside a rapidly scaling company.
Locations
Candidates are welcome to work remotely from the states of AZ, CO, DC, IL, MD, TX, and VA with a preference for the Chicago IL, Denver CO, or Phoenix AZ areas. Caribou does provide the option to work in-office or hybrid from our Denver, CO or Chandler, AZ offices. We may consider remote candidates in CA, FL, MA, NY, OR, WA, and WI, subject to additional approval. Eligibility by state is subject to change.
Outcomes
Here's what success looks like in the first 12-18 months:
- Caribou's security posture advances year over year—the program has a roadmap, diligence reviews go smoothly, and findings reflect it
- SOC 2 Type II delivers clean with no surprises—systematic evidence collection, not a heroics sprint at audit time
- Detection and response capabilities improve measurably—SIEM, CrowdStrike, Wiz, and DLP are operationally sound and the team can say why
- GRC policy and control documents reflect how Caribou actually operates, not how it operated two years ago
- Licensed tools earn their keep—Google Workspace, Slack, Atlassian, Asana, 1Password, and Adobe are actively used, not just provisioned
- An operational AI enablement program that drives measurable adoption of licensed AI capabilities and a growing backlog of automated workflows
- IT operations run without drama—the MSP delivers, support is responsive, and productivity loss from tech issues stays low
- Every direct report has a growth plan, gets regular coaching, and is taking on more complex work than when you arrived
- The vendor portfolio—security and IT—delivers expected value and you can demonstrate it
Responsibilities
- Own Caribou’s security and IT programs, setting direction, strategy, and vendor relationships
- Lead a team of three senior security practitioners and a senior IT administrator
- Deliver SOC 2 Type II audits with systematic evidence collection
- Improve detection and response capabilities (SIEM, EDR, CSPM, DLP)
- Maintain GRC policy and control documentation that reflects current operations
- Manage the SaaS portfolio, including licensing, governance, adoption, and shadow IT
- Run enterprise-wide software rollouts, ensuring adoption and measurable value
- Build an AI enablement program for non-technical employees
- Oversee identity and access management, including provisioning workflows and audit evidence
- Manage MSP relationships and hold them accountable to service standards
- Translate technical risk into business language while maintaining credibility with your team
- Sequence work effectively, prioritizing when everything feels urgent
- Build programs collaboratively with the people executing them
- Treat security and IT as a service to the company, not a gate
Requirements
- Experience delivering a SOC 2 Type II audit as the primary owner
- Managed a detection and response function: SIEM tuning, EDR deployment, incident ownership
- Built or maintained GRC policy and control documentation that held up under audit scrutiny
- Worked in a regulated environment and understand how compliance obligations translate into operational controls
- Managed security vendor relationships (EDR, CSPM, penetration testing firms) and can assess vendor performance
- Run a SaaS portfolio for a growing company—licensing, governance, adoption, and shadow IT
- Led an enterprise-wide software rollout end-to-end: implementation, adoption, and proof of value
- Researched, planned, or executed a rollout of enterprise AI tools
- Run identity and access management end-to-end—policy, provisioning workflow, and audit evidence
- Managed an MSP relationship and held them accountable to a service standard
- Managed people through the full lifecycle—hiring, developing, delivering hard feedback, and making tough calls
- Translated technical risk into business language without losing precision
- Built programs collaboratively with the people executing them
Nice to have
- Experience deploying AI tools or low-code agent platforms to non-technical employees
- EDR/CSPM platform experience
- GLBA Safeguards Rule or NYDFS familiarity
- Fintech or financial services background
We value diverse paths into corporate technology leadership—consulting backgrounds, career changers, and candidates without four-year degrees have succeeded here—and we're actively building a team that reflects the communities we serve.
Benefits
- Competitive compensation: $171,000 - $214,000
- Eligible for annual performance-based Incentive
- Equity options
- 401k savings program
- Generous paid time off including Flexible Time Off (FTO) for all employees and 100% paid parental leave for all parents
- Company-paid plans for health, dental, vision, mental health, disability, and basic life insurance
- Optional benefits to suit individual circumstances such as HSAs, FSAs, supplemental life and medical insurance, and pet insurance
- Up to $1,000 per year for eligible professional development expenses
Core Values
- Give a damn. What we’re doing matters. We show up determined to deliver results, and we love it.
- Velocity. We’re intentional about where we’re going and we race towards it.
- Make the assist. We have diverse strengths. We offer and ask for help so we all win.