SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Alice (formerly ActiveFence) is seeking an experienced InfoSec & SecOps Lead to join the CISO team and drive comprehensive security initiatives across the organization.
Key Responsibilities:
- Maintain holistic security corporate architecture and hardening across network, systems, and applications
- Evaluate and implement security remediations to enhance organizational security posture
- Oversee corporate security measures including access control, surveillance, and emergency response planning
- Manage relationships with external security vendors for third-party risk management (TPRM) and incident response (IR)
- Lead security operations including monitoring, incident response, and analysis of security logs and alerts
- Conduct regular security assessments and manage remediation programs
- Develop and maintain effective incident response plans with post-incident reviews
- Identify, prioritize, and monitor vulnerability remediation efforts across the organization
- Collaborate with IT, DevOps, R&D, and G&A teams to implement security policies and procedures
- Partner with business units to create safe-use guardrails for AI implementations
- Conduct security reviews for internal AI implementations against frameworks like OWASP Top 10 for LLMs
- Develop automated dashboards tracking real-time security health metrics (MTTR, manual toil reduction)
- Educate employees across all business units on security best practices
Required Qualifications:
- Bachelor's degree in Computer Science, Information Security, or related field
- 4+ years of hands-on InfoSec & SecOps experience, preferably in startups and cloud-based environments
- Proven ability to transition from manual SOC workflows to automated incident response
- Hands-on experience building playbooks that automate repetitive security tasks
- Experience leveraging AI/ML capabilities (e.g., Coralogix/Splunk anomaly detection, Okta Identity Threat Protection) for threat detection
- Foundational knowledge of securing LLMs and generative AI tools
- Strong experience with Okta, Adaptive Shield/Astrix, Coralogix/Splunk, endpoint security, and network security tools
- Expertise in WAF and endpoint security solutions
- Cloud security knowledge and experience with AWS, GCP
- Understanding of security frameworks (NIST, CIS) and standards
- Experience with security incident response and investigation
- Knowledge of security orchestration, automation, and response (SOAR) tools
- Strong analytical, problem-solving, and communication skills
- Ability to work independently and collaboratively
Preferred Qualifications:
- Relevant certifications (CISSP, CISM, CEH, CompTIA Security+, SSCP)
- Familiarity with scripting languages (Python, Node.js) and automation tools
Note: Position may require occasional on-call or after-hours work.