SlipstreamJobsFresh Startup & VC-Backed Jobs

Manager, IT Compliance & Vendor Management

Landline - Fort Collins, CO, United States - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Landline is redefining airport infrastructure by decentralizing the airport experience through remote terminals and seamless door-to-gate travel. The company operates across North America with partnerships including Air Canada, American Airlines, Sun Country Airlines, and CLEAR. This Manager role owns two connected accountabilities: overseeing Landline's managed service provider (MSP) performance and designing, operating, and evidencing the company's cybersecurity control program against the NIST Cybersecurity Framework (CSF) 2.0. Landline operates in a regulated transportation environment with security and data-handling requirements imposed by airline partners and airports. Key responsibilities include: - Maintaining the control set mapped across all six NIST CSF 2.0 Functions (Govern, Identify, Protect, Detect, Respond, Recover) - Administering the Vanta GRC platform, including integrations, control monitoring, evidence collection, and remediation tracking - Performing periodic control testing and design effectiveness reviews - Owning the policy lifecycle: drafting, annual review, approval routing, publication, and attestation - Maintaining the enterprise risk register with risk scoring and executive reporting - Preparing evidence for customer security reviews, airline partner assessments, insurance questionnaires, and external audits - Administering security awareness training and phishing simulations - Serving as primary relationship owner for the MSP, managing escalations and service delivery expectations - Monitoring and reporting on contracted service levels and enforcing contractual remedies - Chairing quarterly business reviews with the MSP - Owning the MSP contract lifecycle including scope changes, renewals, and pricing negotiation - Verifying MSP-operated controls function as contracted - Governing access administration including joiner/mover/leaver execution and privileged access review - Maintaining the RACI matrix defining control responsibilities - Operating the vendor intake and security review process for new technology purchases - Maintaining vendor inventory with data classification and criticality tiering - Collecting and reviewing third-party assurance artifacts (SOC 2 Type II, ISO 27001 certificates, penetration test summaries) - Tracking vendor contract security terms and data processing agreements - Maintaining incident response and business continuity documentation - Delivering recurring compliance and vendor performance reports to executive leadership Required qualifications: Five or more years in IT compliance, information security, IT audit, or IT governance, with at least two years of direct responsibility for a control program or audit function. Hands-on experience implementing or operating a recognized security framework (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls). Experience administering a GRC or compliance automation platform (Vanta, Drata, Secureframe, LogicGate, AuditBoard, ServiceNow GRC). Experience managing or formally overseeing an outsourced IT provider. Working knowledge of core IT controls including identity and access management, endpoint management, logging and monitoring, vulnerability management, backup and recovery, and change management. Ability to critically read SOC 2 Type II reports. Clear written communication skills. Preferred qualifications: Professional certification (CISA, CRISC, CISM, CISSP). Direct NIST CSF 2.0 implementation experience, particularly the Govern function and cybersecurity supply chain risk management. Experience in transportation, aviation, logistics, or another operationally regulated industry. Familiarity with PCI DSS, CCPA/CPRA, or state breach notification requirements. Prior experience building a compliance program from early stage.

Similar roles