Founding Information Security Lead
Posted 9hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Founding Information Security Lead owning security, compliance, and IT operations for Flodesk’s email marketing platform. Building SOC 2, ISO 27001, and CCPA readiness.
Responsibilities:
- Own Flodesk's security program, including policies, controls, governance, and long-term maturity planning
- Collaborate cross-functionally to embed security into product, operational, and technology decisions
- Maintain privacy-related security practices for data handling, retention, and customer commitments
- Lead SOC 2, ISO 27001, and CCPA readiness, audits, evidence collection, and continuous compliance
- Partner with engineering on security architecture, development workflows, release processes, and security foundations across cloud infrastructure, applications, data, and internal systems
- Evaluate, implement, and maintain security tooling and automation
- Own security incident management end to end
- Design, implement, and continuously improve controls
- Track and report security posture, program maturity, and compliance status
- Defend Flodesk's SaaS platform and customers with protective mechanisms and security capabilities
- Manage company hardware lifecycle from procurement to retirement
- Provide first-line IT support for hardware, software, and network connectivity
- Run new-hire account setup, device provisioning, and secure access revocation for leavers
- Manage domain registrations, DNS, and general IT housekeeping
- Vet new tools for SSO, 2FA, and integration capabilities
- Maintain a registry of approved software
Requirements:
- 10+ years in information security, with a track record of building or maturing security programs
- 3+ years in an information security leadership role
- Strong foundation in cloud security, identity governance, vulnerability management, and incident response
- Proven experience aligning security and privacy practices with GDPR
- Comfortable partnering directly with engineering on product security and secure development practices
- Clear, confident communication with technical and non-technical stakeholders
- Can-do attitude, flexibility, and willingness to occasionally handle basic tasks
- Willingness to travel on a semiannual basis
- Experience securing SaaS products is an advantage
- Experience implementing SOC 2, ISO 27001/2, or similar frameworks is an advantage
- Background in reliability, DevOps, or application architecture is an advantage
- Conversational or better Vietnamese is an advantage
Benefits:
- Fully paid health insurance for individual coverage
- 16 weeks paid parental leave for non-birthing parents
- 22 weeks paid maternity leave for birthing parents
- Unlimited flexible time off
- 401k match (US employees only)
- $1,000 annual stipend for learning and development


















