Information Security Manager – Financial Services Technology (Remote)We’re partnering with a growing technology company in the financial services sector that is building modern, cloud-native platforms used by enterprise clients. As the company continues to scale, they are looking for an Information Security Manager to take ownership of their security and compliance function and help shape the next phase of their security maturity.This is a high-impact role with real ownership. You won’t just be maintaining a program - you’ll be improving it, shaping it, and acting as the go-to person for security across the business. The role combines leadership, hands-on technical work, and regular interaction with clients and auditors, so it suits someone who enjoys operating across both technical and business environments.What You’ll Be DoingOwning and running the company’s SOC 2 program and broader security compliance initiativesDeveloping and improving security policies, controls, and governance frameworks (SOC 2, ISO 27001, NIST)Managing and responding to security alerts, vulnerabilities, and incidentsOverseeing cloud and infrastructure security across AWS and Kubernetes environmentsLeading identity and access management, including access reviews and privileged access controlsCoordinating penetration testing, risk assessments, and remediation programsManaging business continuity and disaster recovery planning and testingActing as the main point of contact for client security questionnaires, audits, and security discussionsConducting vendor security reviews and managing third-party riskReporting on security posture, risk, and ongoing improvements to leadershipSupporting security for AI/ML systems and data pipelines, including model security, data protection, and access controlsWhat They’re Looking ForAround 6 years of experience in Information Security with strong hands-on technical experienceExperience running SOC 2 in a real production environmentStrong cloud security experience, particularly in AWS (GCP is a plus)Experience working with Kubernetes and modern cloud infrastructureExperience with EDR/XDR tools such as CrowdStrike (or similar)Familiarity with SOC 2, ISO 27001, and NIST frameworksExperience securing data, APIs, and AI/ML systems is a strong plusExperience working in regulated environments such as financial services, fintech, or SaaSAbility to communicate with both technical teams and non-technical stakeholders, including clients and auditorsCertifications such as CISSP, CISM, or Security are helpful but not essentialWhy This Role Is InterestingFully remote role with a high level of ownership and autonomyYou’ll own security rather than inherit a rigid programYou’ll work in a modern cloud-native environment, not legacy infrastructureYou’ll have direct exposure to clients and leadershipYou’ll be in a role where security is taken seriously and has real visibilityYou’ll be able to make measurable improvements and see the impact of your workIf you’re interested in learning more, please apply or reach out directly for a confidential conversation.
Francis Alexander