SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 120,000 - 160,000 / annual
Halcyon is a cybersecurity platform founded in 2021 by veterans from leading security vendors (Cylance/BlackBerry, Accuvant/Optiv, FireEye, ISS X-Force/IBM). The company specializes in adaptive security and ransomware prevention for mid-market and enterprise customers.
As a Senior Information Security Specialist, you will support the advancement of Halcyon's cybersecurity and GRC (Governance, Risk, and Compliance) programs. This is an individual contributor role focused on strengthening enterprise-wide security posture through cross-functional coordination, third-party risk management, compliance initiatives, and security process maturation.
Key responsibilities include:
- Performing and maintaining third-party risk assessments and tracking vendor remediation activities
- Supporting coordination and analysis of internal and external security testing (vulnerability scans, penetration tests)
- Developing, tracking, and following up on corrective action plans for security gaps and audit findings
- Collaborating with managed security service providers and internal stakeholders to monitor security events and escalations
- Partnering with engineering and operations teams to ensure implementation of security and compliance requirements
- Developing, maintaining, and communicating information security policies, standards, and procedures
- Coordinating security incident response planning, disaster recovery testing, and business continuity exercises
- Monitoring and supporting enforcement of technical and administrative security controls
- Staying current with evolving security and privacy regulations and frameworks (SOC 2, ISO 27001, TX-RAMP, FedRAMP)
The company is fully remote and distributed globally, with a commitment to flexible work arrangements.
Requirements:
- 5+ years of experience in information security, GRC, or IT risk management
- Strong understanding of cybersecurity concepts, controls, and risk frameworks
- Demonstrated experience with third-party risk management processes and tooling
- Proven ability to coordinate security testing and vulnerability management efforts
- Excellent communication, documentation, and cross-functional collaboration skills
- Ability to assess and implement technical and administrative controls across cloud and hybrid environments
- Experience with regulatory compliance and audit support in fast-paced environments
- Hands-on participation in incident response or disaster recovery exercises (preferred)
Bonus qualifications:
- Experience with compliance platforms (Drata, Vanta)
- Knowledge of security frameworks beyond SOC 2 and ISO 27001 (NIST 800-53, CIS Controls)
- Familiarity with secure software development practices or DevSecOps principles
- Background in auditing or supporting third-party security assessments
- Experience with Microsoft 365 and/or Google Workspace security configuration
- Exposure to regulatory environments (HIPAA, GDPR, CCPA)
- Certifications such as CISSP, CISA, CISM, Security+, or similar