SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Information Security Manager

Backstory - Remote - Remote - posted 2026-09-23

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Backstory is seeking a Senior Information Security Manager to own and mature preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments. This is a hands-on technical leadership role that bridges security strategy and implementation. You will translate broad security objectives into concrete technical requirements, controls, tooling, and implementation plans. Key responsibilities include evaluating, selecting, configuring, and deploying security platforms (DLP, insider threat, endpoint security, IAM, vulnerability management, access controls, security monitoring). You'll continuously assess security posture, identify gaps and vulnerabilities, prioritize risk, and drive remediation to completion. You will partner closely with IT, Engineering, DevOps, and Product to integrate security controls into new technologies and business initiatives. You'll build metrics and reporting that provide visibility into control effectiveness and overall security posture. Working with Security Operations, you'll ensure preventative controls provide the visibility and protection needed for threat investigation and response. You will develop, maintain, and test incident response playbooks, business continuity processes, and disaster recovery plans. You'll partner with CISO, CIO, and CTO on security compliance initiatives, working directly with auditors to provide evidence, explain controls, and remediate findings. You'll translate requirements from SOC 2, ISO 27001, ISO 42001, GDPR, CCPA/CPRA, and EU AI Act into practical technical controls. You will provide technical direction and mentorship to security engineers, analysts, IT partners, and external contractors. You'll serve as a trusted security advisor across the organization, translating complex threats and vulnerabilities into actionable recommendations for both technical and non-technical stakeholders. You'll take ownership of ambiguous security challenges from strategy and evaluation through implementation, measurement, and continuous improvement. REQUIREMENTS: - 7+ years of progressive experience in information security with meaningful hands-on experience implementing enterprise security controls - 2+ years of technical leadership, team lead, or people management experience - Deep understanding of cloud, SaaS, endpoint, identity, network, and data security, including traditional and Agentic AI environments and workloads - Strong hands-on experience implementing security tooling and controls (not solely defining policy or overseeing implementation) - Experience across DLP, IAM, endpoint security, vulnerability management, insider threat, access management, and security monitoring - Strong understanding of modern cloud infrastructure, security architecture, and risk management - Experience operating in Mac, Linux, cloud, SaaS, and open-source-heavy environments - Experience automating security controls and workflows through scripting (e.g., Python) and infrastructure as code security (e.g., Terraform, policy as code, CI/CD pipeline guardrails) - Working knowledge of security frameworks including NIST, CIS, ISO 27001, SOC 2, and Zero Trust - Experience participating in security audits, working directly with auditors, gathering technical evidence, and remediating findings - Deep knowledge of securing third-party API and OAuth integrations; scoping, token lifecycle management, and revocation across SaaS and data platforms - Ability to translate complex technical threats and vulnerabilities into actionable solutions with Engineering, Product, IT, and non-technical stakeholders - Strong analytical and problem-solving skills with ability to independently evaluate security challenges and determine the right technical approach - Experience working within U.S.-based technology environments and familiarity with enterprise security expectations - Comfortable operating autonomously in a fast-moving environment where priorities and requirements will continue to evolve

Similar roles