SlipstreamJobsFresh Startup & VC-Backed Jobs

IT & Information Security Compliance Manager (Automation & Certifications)

1Kosmos - BlockID - Edison, NJ, United States - In-office - posted 2026-07-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

1Kosmos is seeking an IT & Information Security Compliance Manager to lead and strengthen the company's security and compliance posture across SOC 2, ISO 27001, FedRAMP High, and NIST frameworks. This is a hands-on operational leadership role focused on ensuring audit readiness, control implementation, IT governance, and continuous improvement of security programs. Key responsibilities include leading enterprise security and compliance programs aligned with SOC 2, ISO 27001/27002, FedRAMP High, and NIST 800-53/171 frameworks. You will build and manage automated compliance monitoring and evidence collection through platforms like Drata or Vanta, integrating these with internal systems including ticketing, HRIS, and cloud providers. The role requires preparing for and managing SOC 2 Type I/II and ISO audits, conducting gap analysis, documentation, remediation, and control testing. You will partner with IT Operations and Engineering to embed security controls in infrastructure, cloud, network, and identity systems. Additional responsibilities include maintaining security policies, SSPs, POA&Ms, and audit documentation; overseeing incident response, change management, and vendor risk programs; managing relationships with external auditors and compliance assessors; and defining metrics for audit readiness and compliance automation efficiency. The ideal candidate brings 6+ years of experience in IT security, compliance, or risk management within a SaaS or regulated technology environment. You must have proven experience managing SOC 2 and ISO 27001 programs end-to-end, with hands-on use of compliance automation platforms like Drata, Vanta, or Tugboat Logic. Strong technical understanding of security controls (network, endpoint, access, configuration management, logging/monitoring, vulnerability management) is essential, along with familiarity with AWS/Azure/GCP cloud environments and identity & access management. Preferred qualifications include certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, or FedRAMP Practitioner. Experience managing IT operations processes with a compliance lens and familiarity with compliance automation APIs or integration scripting are bonuses. The role requires on-site presence in Edison, NJ.

Similar roles