SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Orbital is an AI platform for real estate legal work, trusted by 5,000+ real estate professionals including UK Magic Circle and US Am Law 100 firms. The company has raised $75m to date, including a recent $60m Series B led by Brighton Park Capital, and is scaling rapidly across two continents.
You will own information security and compliance end-to-end as the InfoSec Lead, bringing structure and consistency to work currently handled on a contractor basis. This is a full-time, NYC-based role reporting to the Head of Operations, working independently from the UK-based IT Manager but collaborating closely on interconnected remits.
Key responsibilities include:
**InfoSec & Compliance Delivery:**
- Own the InfoSec strategy and roadmap, setting direction for how security and compliance scale with the business; identify control gaps, prioritize remediation, and track completion.
- Run the risk program: conduct risk identification, assessment, and treatment; maintain the risk register; make calls on acceptable risk levels.
- Own third-party risk assurance in both directions: conduct vendor security reviews and manage customer/vendor due diligence (DDQs). Pull in cross-functional support and jump on client calls as needed. Drive automation of DDQ processes to prevent them from consuming disproportionate time as the function matures.
- Own existing and future compliance certifications: maintain ISO 27001 and SOC2 Type 2 compliance, pursue relevant future certifications, manage the ISMS, conduct quarterly access control reviews, gather audit evidence, schedule audits, and track remediation. Keep policies and public-facing security documentation (trust centre) current.
- Partner cross-functionally with Engineering, Product, and Legal to embed security and compliance into how the company builds and sells; stay close to product changes to ensure customer-facing security information remains accurate.
You'll work alongside Engineering, Product, Legal, and external InfoSec support to keep security and compliance embedded in business operations rather than bolted on after the fact. The role offers genuine cross-functional influence and the opportunity to shape how security and compliance scale with the business as processes and playbooks are still being built.
**Requirements:**
- Significant senior in-house or scale-up InfoSec leadership experience: must have owned due diligence, vendor review, and compliance work end-to-end inside a fast-moving business, not just advised externally.
- Strong understanding of cloud and cloud security; ideally previous technical background in IT Security, SWE, or DevOps.
- Track record of scaling due-diligence processes (templating, automation, self-service) rather than running them manually.
- Comfortable being close to engineering: no need to write code, but must be happy in technical conversations, understand product changes, and weigh in on security-sensitive decisions.
- Pragmatic and delivery-focused: distinguish genuine risks from distractions; keep due diligence and audit work moving at commercial pace.
- AI-literacy with working familiarity with AI governance (ISO 42001, EU AI Act, etc.).
- Comfortable operating independently with real ownership of the roadmap, not a narrow audit-only remit.
- Working knowledge of privacy law (GDPR, CCPA, US state privacy laws) to partner with the legal function.