SlipstreamJobsFresh Startup & VC-Backed Jobs

IT, Security, and Compliance Manager

Favorited - Santa Monica, CA, USA - In-office - posted 2026-10-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 140,000 - 170,000 / annual

Favorited is a digital community platform focused on connecting creators and audiences through gaming and interactive features. The company is seeking an IT, Security & Compliance Manager to build and own the systems, processes, and programs that keep the organization secure, compliant, and operationally efficient as it scales. This is a highly hands-on role spanning IT operations, information security, compliance, risk management, and vendor management. You will report to executive leadership and work closely with engineering, operations, and external partners to establish appropriate technology controls and security practices. Key responsibilities include: - Owning day-to-day IT operations: systems, applications, access management, devices, identity, and employee technology - Developing and maintaining the company's information security program, policies, standards, and controls - Identifying appropriate security and compliance certifications (SOC 2, ISO 27001, etc.) and building the roadmap to achieve them - Partnering with engineering and infrastructure teams to ensure proper security controls, monitoring, and access management - Managing employee identity and access management, including onboarding, offboarding, and periodic access reviews - Establishing and maintaining security policies covering access control, acceptable use, data protection, incident response, and vendor risk - Owning or coordinating security audits, assessments, penetration tests, and compliance reviews - Developing and maintaining incident response and security escalation processes - Managing technology and security vendors through selection, evaluation, contracts, renewals, and performance monitoring - Establishing third-party risk management processes for vendors with system or data access - Partnering with legal, finance, HR, and leadership on privacy, compliance, and risk initiatives - Conducting regular risk assessments and identifying opportunities to strengthen security posture - Educating employees on security best practices and compliance requirements - Helping establish scalable IT and security processes to support company growth The company values self-starters, open communication, and real-time feedback. The work culture is intense and fast-moving, with a focus on gaming and community engagement. REQUIREMENTS: - 5+ years of experience across IT, information security, GRC, compliance, or related field - Experience owning or significantly contributing to IT and security programs within a startup or high-growth technology company - Strong understanding of security frameworks, controls, risk management, and compliance requirements - Experience building security and compliance programs from the ground up - Familiarity with SOC 2, ISO 27001, GDPR, CCPA/CPRA, and other relevant security and privacy frameworks - Experience managing security audits and certification processes - Strong experience with identity and access management, SaaS administration, endpoint security, and IT operations - Experience evaluating and managing IT and security vendors - Ability to assess company needs and determine appropriate security certifications and compliance standards - Strong organizational and project management skills with ability to manage multiple priorities - Excellent communication skills and ability to work effectively with technical and non-technical teams - Comfortable operating independently and building processes where they don't yet exist - High level of discretion, judgment, and ownership when dealing with sensitive company and user information PLUS (desirable): - Experience leading SOC 2 Type II or ISO 27001 certification efforts from planning through completion - Experience in consumer technology, gaming, social, livestreaming, or SaaS environments - Experience supporting companies through rapid growth and increasing security or compliance requirements - Familiarity with cloud environments such as AWS or GCP - Experience with security and IT tools across identity, endpoint management, vulnerability management, SIEM, and compliance management - Experience establishing a security program at a company with previously limited formal security infrastructure - Relevant certifications such as CISSP, CISM, CISA, CRISC, or Security+ - Pragmatic approach to security that balances strong controls with fast-moving engineering organizations

Similar roles