SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Manager, Security & IT Ops

Hazelcast - Remote - Remote

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Hazelcast is seeking a hands-on Senior Manager of Security & IT Ops to lead company-wide security governance, compliance, and internal technology operations. This role reports to the executive responsible for post-sales operations and will manage a small team while potentially overseeing contractors and external service providers. Key responsibilities include: **Security & Compliance Leadership**: Own the company's security direction, including the security plan, information security management system (ISMS), risk register, policies, and control ownership. Serve as the primary contact for external auditors and lead annual SOC 2 Type II and ISO 27001 compliance efforts from readiness through final reports. Maintain Secureframe evidence, track findings and corrective actions, and conduct quarterly reviews of user access, firewall settings, and risk controls. **Risk Management & Assessment**: Conduct regular security risk assessments, identify weaknesses in business processes, and collaborate with IT, Cloud SRE, and Engineering Operations on practical remediation. Track security patches and bug fixes against compliance deadlines. Manage vendor security risk through assessments, due diligence, and ongoing monitoring based on data sensitivity. **Access & Identity Management**: Manage access provisioning and deprovisioning as employees join, change roles, or leave. Apply role-based access control, least privilege principles, and separation of duties. Maintain clear records of root, administrator, service, and shared accounts until lasting owners or automated processes are established. **Internal IT Operations**: Create reliable, secure internal technology services with clear support channels, documented processes, and service-level expectations. Personally handle or oversee critical administrative work until permanent ownership is established. Guide spending on internal cloud platforms (AWS, Google Cloud, Azure), Kubernetes, VPN/SASE, domains, DNS, logging, and monitoring. **Incident Preparedness & Business Continuity**: Maintain clear incident response plans, escalation paths, communications protocols, and exercises for security and IT incidents. Work with Engineering and Cloud SRE on customer-impacting events and review the Business Continuity Plan annually. **Stakeholder Engagement**: Support Sales and Legal on customer security questionnaires and vendor assessments. Participate in the AI Governance Committee, bringing security, privacy, and operational risk perspectives to AI tool reviews and usage decisions. **First-Year Milestones**: Establish an approved security plan, clear control ownership, a dependable audit rhythm, an internal IT service model, an ownership register, a privileged-account inventory, internal-cloud standards, and agreed transition or sourcing plans for critical gaps. **Requirements:** - Proven experience leading a company-wide security, compliance, internal IT, or technology-risk program in a cloud or software company - Direct experience leading ISO 27001 and SOC 2 Type II audits, evidence gathering, policy reviews, findings management, and control reviews - Strong understanding of privacy, data protection, business-process risk, vendor risk, vulnerability management, incident response, business continuity, and compliance deadlines - Technical proficiency with identity systems, business software, AWS, Google Cloud, Azure, Kubernetes, networking, firewalls, VPN/SASE, domains, DNS, logging, and monitoring - Demonstrated ability to bring order to ambiguous work, protect continuity, document processes, clarify responsibilities, and transition work appropriately - Excellent communication skills for explaining risks and choices to executives, auditors, technical and business teams, customers, and prospects - Bachelor's degree in Computer Science, Information Security, Information Systems, or related discipline (or equivalent practical experience) - Helpful: CISSP, CISM, ISO 27001 Lead Implementer/Lead Auditor, or similar certification; experience in distributed companies, responsible AI governance, technology cost management, or vendor commercial management

Similar roles