PRODUCT MANAGER
The Iron Sheepdog is seeking a highly skilled Lead Information Security & Compliance Specialist to spearhead our security initiatives and governance frameworks. The role requires bridging the gap between high-level compliance and hands-on technical security engineering, managing compliance pipelines, protecting fintech workflows, and championing a security-first culture.
About the Role
We are looking for a proactive security professional who thrives in SaaS environments and loves securing cutting-edge tech ecosystems, including cloud, mobile, and AI. This role is process- and compliance-led but also values deep hands-on software-security engineering.
Responsibilities
Compliance Leadership: Lead and manage the end-to-end process of achieving and maintaining SOC 2 compliance.
Policy & Governance: Create, enforce, and govern comprehensive IT and Information Security policies across the entire organization.
Client Security Liaison: Serve as the primary security liaison for enterprise clients, confidently answering complex security questionnaires and navigating financial audits.
Vendor Management: Interface directly with client security teams, respond to vendor security questionnaires, and optimize our IT Managed Service Provider (MSP) relationships to dictate how we best leverage them.
Security Engineering: Act as a hands-on security engineer to review and improve secure coding practices across our React and Node.js codebase, ensuring the safety of our fintech workflows.
Vulnerability & DevSecOps Management: Manage and monitor DevSecOps tools like Snyk to catch vulnerabilities early in the CI/CD pipeline.
Testing & Infrastructure Security: Conduct internal penetration tests, review Firebase/Firestore security rules, and rigorously develop disaster recovery plans.
AI Security Implementation: Design and execute vulnerability testing specifically for our AI features, running prompt injection tests against our LLMs and chat-bots to ensure data integrity.
Security Culture: Take full ownership of company-wide security awareness training, actively building an internal culture of vigilance and security awareness.
Job Requirements & Skills
Core Requirements (Must Have):
- SOC 2 Expertise: Experience managing/leading the end-to-end process of achieving and maintaining SOC 2 compliance, OR comparable/translatable audit and compliance frameworks (e.g., ISO 27001, HIPAA, PCI-DSS).
- SaaS & Industry Background: A proven background working within SaaS environments, with a strong preference for candidates experienced in logistics, supply chain, or short-haul trucking platforms (specifically dealing with truck routing and fleet dispatch).
- Enterprise Experience: Proven experience serving as a primary security contact for medium to large enterprises.
- Ecosystem Exposure: Strong exposure to secure processes for diverse, interconnected ecosystems across web, mobile, cloud infrastructure, and APIs.
Technical & Next-Level Requirements:
- Codebase Security: Ability to work hands-on with React and Node.js codebases to implement secure coding practices.
- Tooling & Testing: Direct experience with DevSecOps tools (e.g., Snyk), CI/CD pipelines, internal penetration testing, and Firestore/Firebase security rule governance.
- AI Vulnerability Testing: Experience or strong capability in running prompt injection tests and securing LLM-powered chatbots.
Location
The role is remote, with a preference for candidates within ~2 hours' drive of Williamsburg, VA (nice-to-have, for periodic on-site audit and consensus work).