SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 125,000 - 140,000 / annual
LineVision is a grid-enhancing technology company serving eight of the ten largest US utilities with optical sensors and advanced environmental modeling for dynamic line ratings and grid operations. You will lead the security program as Information Security Lead, reporting to the VP of Security, IT, and Quality, with direct management of a Security Analyst.
You will own the end-to-end security posture across compliance, risk management, security engineering, security operations, incident response, and customer engagements. Key responsibilities include:
**Compliance & Governance**: Own the annual SOC 2 Type II and ISO 27001 audit cycles using Vanta, including controls, internal/external audits, and nonconformity tracking. Lead annual NIST CSF risk assessments, monthly Platform and Hardware risk reviews, and quarterly GRC reviews. Maintain ISMS policies and report efficacy metrics to leadership.
**Security Engineering & Operations**: Conduct AWS cloud and sensor penetration tests, ISA/IEC 62443 product security assessments, and vendor/product risk assessments. Oversee vulnerability management, CrowdStrike Falcon Complete detection rules, NextGen SIEM data feeds, and MSSP relationships. Monitor open-source license compliance.
**Incident Response & Resilience**: Own the incident response program and plan, including annual third-party tabletop exercises, business continuity and disaster recovery planning, and implementation of lessons learned.
**Data Protection & AI Security**: Define and guide data management controls across company systems and applications. Identify risks and define security standards for enterprise and product AI, informing the AI governance program.
**Customer & Sales Support**: Lead responses to customer security questionnaires, contract security reviews, and customer-facing security presentations.
**Team Leadership**: Coach and develop the security team. This role requires participation in a compensated rotational on-call schedule.
Within 3 months, you will establish operational rhythm with the team, take ownership of audit calendars and risk registers, implement intake/prioritization processes, and lead monthly security risk reviews. Within 6 months, deliver SOC 2 Type II and ISO 27001 surveillance audits with no major nonconformances, complete an annual IEC 62443 assessment, extend data controls, and mature detection rules. Within 12 months, propose a 2–3 year security roadmap, reduce questionnaire effort through self-service materials, define security requirements for next-generation products, and establish ISMS efficacy metrics.
The role is hybrid (2–4 days/week in Boston office) and requires strong ownership, planning, communication, judgment, and people leadership skills.
**Requirements**:
- 6+ years in information security, with at least 2 years in a lead or people-management role
- Direct ownership (not only support) of SOC 2 Type II and ISO 27001 audits
- Experience conducting risk assessments with NIST CSF or equivalent framework
- Hands-on experience with penetration test management, vulnerability management, and EDR/SIEM tooling (CrowdStrike preferred)
- Experience with AWS cloud security
- Experience responding to enterprise customer security questionnaires and contract requirements
- CISSP, or commitment to earn it within 18 months of start date
**Preferred Qualifications**:
- Experience with OT/ICS or IoT security, including IEC 62443
- Familiarity with utility sector requirements (CEII, NERC CIP) or other regulated critical infrastructure
- Experience leading incident response for a real event
- Experience with Vanta or similar compliance automation
- Experience in AI Governance and/or assessing the security of AI tools and features