SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Landline is redefining airport infrastructure by decentralizing the airport experience through remote terminals and seamless door-to-gate travel. The company operates across North America with partnerships including Air Canada, American Airlines, Sun Country Airlines, and CLEAR.
This Manager role owns two connected accountabilities: overseeing the managed service provider (MSP) that delivers day-to-day IT operations, and designing, operating, and evidencing the company's control program against the NIST Cybersecurity Framework (CSF) 2.0. Landline operates in a regulated transportation environment with security and data-handling requirements imposed by airline partners and airports.
Key responsibilities include:
- Maintaining the control set mapped to NIST CSF 2.0 across all six Functions (Govern, Identify, Protect, Detect, Respond, Recover)
- Administering the Vanta GRC platform, including integrations, control monitoring, evidence collection, and remediation tracking
- Performing periodic control testing and design effectiveness reviews
- Owning the policy lifecycle: drafting, annual review, approval routing, publication, and attestation tracking
- Maintaining the enterprise risk register with risk scoring methodology and executive reporting
- Preparing and coordinating evidence for customer security reviews, airline partner assessments, insurance questionnaires, and external audits
- Administering the security awareness training program, including phishing simulation
- Serving as primary relationship owner for the MSP, managing escalations and service delivery expectations
- Monitoring and reporting on contracted service levels, documenting breaches, and driving root-cause analysis
- Chairing quarterly business reviews with the MSP and owning the contract lifecycle
- Verifying that MSP-operated controls function as contracted
- Governing access administration performed by the MSP
- Operating the vendor intake and security review process for new technology purchases
- Maintaining vendor inventory with data classification and criticality tiering
- Collecting and reviewing third-party assurance artifacts (SOC 2 Type II reports, ISO 27001 certificates)
- Maintaining the incident response plan and coordinating annual tabletop exercises
- Serving as compliance lead during security incidents
- Maintaining business continuity and disaster recovery documentation
- Delivering recurring compliance and vendor performance reports to executive leadership
Required qualifications: Five or more years in IT compliance, information security, IT audit, or IT governance, with at least two years of direct responsibility for a control program or audit function. Hands-on experience implementing or operating a recognized security framework (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or equivalent). Experience administering a GRC or compliance automation platform (Vanta, Drata, Secureframe, LogicGate, AuditBoard, ServiceNow GRC, or equivalent). Experience managing or formally overseeing an outsourced IT provider, including service level monitoring and escalation. Working knowledge of core IT controls: identity and access management, endpoint management, logging and monitoring, vulnerability management, backup and recovery, and change management. Ability to critically read SOC 2 Type II or similar reports. Clear written communication skills.
Preferred qualifications: Professional certification such as CISA, CRISC, CISM, or CISSP. Direct NIST CSF 2.0 implementation experience, particularly the Govern function and cybersecurity supply chain risk management (GV.SC). Experience in transportation, aviation, logistics, or another operationally regulated industry. Familiarity with PCI DSS, CCPA/CPRA, or state breach notification requirements. Prior experience building a compliance program from early stage.