Talent.com
Information Security Manager
Information Security ManagerKikoff • San Francisco, California, United States
Information Security Manager

Information Security Manager

Kikoff • San Francisco, California, United States
[job_card.variable_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

About The Role

You'll be our first dedicated security leader, owning the technical execution of our security and compliance program.

You’ll drive SOC 2 and PCI DSS compliance, manage our vulnerability program, and build security capabilities that enable our engineering teams to move fast while staying secure. This is a hands‑on role—you’ll design controls, write policies, respond to incidents, and work directly with auditors.

This is initially an individual contributor role with high impact and visibility. As our security program matures, you’ll have the opportunity to build and lead a security team.

Own Compliance

Lead SOC 2 Type II and PCI DSS programs through successful audit

Design and implement security controls without blocking velocity

Serve as primary technical contact for external auditors and assessors

Manage third‑party vendor security assessments and ongoing monitoring

Build automated evidence collection and continuous compliance monitoring

Report security metrics and program status to executive leadership

Manage Security Operations

Establish vulnerability management program with defined SLAs and remediation workflows

Own end‑to‑end vulnerability management : identify, assess, prioritize, and drive remediation to completion across infrastructure and applications

Manage external penetration testing program with third‑party vendors, including scoping, assessment review, and remediation tracking

Perform internal penetration testing and security assessments of applications, APIs, and infrastructure

Build SIEM detection rules, security dashboards, and alert triage processes

Develop and test incident response runbooks

Conduct threat modeling for critical systems and architectural changes

Lead security assessments of new technologies and third‑party integrations

Enable & Collaborate

Partner with platform engineering to implement security roadmap : AWS landing zone design, PAM / JIT workflows, account segmentation, disaster recovery testing

Enforce enterprise security controls (SSO, secrets management, RBAC)

Build and deliver security awareness training program for all employees

Develop and maintain security policies, standards, and procedures

Translate compliance requirements into actionable engineering tasks and drive completion

You Have

Security & Compliance

5+ years in information security, with 2+ years in fintech or a highly regulated industry

CISSP certification (or actively pursuing – must obtain within 12 months of hire)

Hands‑on experience leading SOC 2 and PCI DSS audits from start to finish

Strong incident response background – you've led real security incidents

Experience with vulnerability management platforms (Wiz, Snyk, Tenable)

Technical Skills

Solid understanding of AWS security : IAM, Security Hub, GuardDuty, CloudTrail, KMS

Experience with SIEM platforms (Splunk, Datadog, Elastic) – you can write detection rules and build dashboards

Hands‑on experience with vulnerability assessment and penetration testing tools (Burp Suite, Nessus, Qualys, or similar)

Ability to read code (Ruby, JavaScript, Python) and assess security implications

Knowledge of web application security, API security, and OWASP Top 10

Understanding of access control patterns (PAM, SSO, RBAC, least privilege)

Core Competencies

Strong communication – you can explain risks to engineers and executives alike

Pragmatic risk management in fast‑paced environments

Self‑starter who builds programs from scratch

Collaborative mindset – security as enabler, not blocker

Ability to drive remediation to completion across teams

Nice to Have

Additional certifications (CISM, CISA, CCSP, CEH, OSCP, CRISC)

Experience managing WAF deployments (Palo Alto, Cloudflare, AWS WAF)

Infrastructure‑as‑code experience (Pulumi, Terraform)

Kubernetes security knowledge

SOAR platform experience

DevSecOps or security automation background

Scripting skills (Python, Bash) for security tooling and automation

Kikoff

Kikoff is a FinTech unicorn powering financial progress with AI. Our mission is to provide radically affordable financial tools to help consumers achieve financial security. Founded in 2019, we serve millions of people, many building credit or navigating life paycheck to paycheck. We simplify credit building, reduce debt, and expand access to financial opportunities.

Why Kikoff

This is a consumer fintech startup where you will work with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and relationships.

Benefits

Medical, dental, and vision coverage – Kikoff covers the full cost of health insurance for the employee

Meaningful equity in the form of RSUs

Flexible vacation policy

Competitive pay based on experience (base + equity + benefits)

Hybrid location – 3 days onsite in San Francisco, CA

Visa sponsorship available for H1‑B visas and U.S. green cards for exceptional talent

Equal Employment Opportunity Statement

kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and consider qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

If you need reasonable accommodation for a job opening, please connect with us at talent@kikoff.com and describe the specific accommodation requested for a disability-related limitation.

San Francisco Fair Chance Ordinance : Pursuant to the San Francisco Fair Chance Ordinance, Kikoff will consider for employment qualified applicants with arrest and conviction records.

#J-18808-Ljbffr

[job_alerts.create_a_job]

Information Security Manager • San Francisco, California, United States

[internal_linking.similar_jobs]
Senior Information Security Leader — Cloud, IaC & Risk

Senior Information Security Leader — Cloud, IaC & Risk

Atomic Machines • Emeryville, CA, United States
[job_card.full_time]
A leading micromanufacturing company in California seeks a Cyber Security Engineer to manage and implement security solutions. The ideal candidate will have over 8 years of experience in Information...[show_more]
[last_updated.last_updated_30] • [promoted]
Information Security Architect : 25-06822

Information Security Architect : 25-06822

Akraya, Inc. • San Francisco, CA, United States
[job_card.full_time] +1
Primary Skills : CDP(Expert), Data Architecture(Advanced), Security Vulnerabilities (Advanced), Cloud Architecture Design (Expert), Cloud Security (Proficient). Location : San Francisco, Los Angeles, ...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Manager, Enterprise Security Advisors & Architects

Manager, Enterprise Security Advisors & Architects

Proofpoint • San Francisco, CA, United States
[job_card.full_time]
Proofpoint is a global leader in human- and agent-centric cybersecurity.We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 1...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Platform Engineering Manager — Infra & Security

Platform Engineering Manager — Infra & Security

Menlo Ventures • San Francisco, CA, United States
[job_card.full_time]
A technology company in San Francisco is seeking an experienced Engineering Manager to lead the Infrastructure and Security team. This role involves shaping engineering processes across key function...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Architect

Information Security Architect

Compunnel, Inc. • San Francisco, CA, United States
[job_card.full_time]
We are seeking a Senior / Lead Information Security Architect to design secure cloud architectures, perform system threat modeling, and propose effective security controls for critical workloads.The ...[show_more]
[last_updated.last_updated_30] • [promoted]
Information Security Architect

Information Security Architect

Harvey Nash • San Francisco, CA, United States
[job_card.full_time]
Job title - Information Security Architect.Candidates must be within commuting distance of one of these offices : .The Common Data Platform (CDP) is an enterprise initiative to centralize and manage ...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Information Security Engineer

Information Security Engineer

Workstream • San Francisco, CA, United States
[job_card.full_time]
Workstream is a mission-driven company building the all-in-one HR, payroll, and hiring platform for managing the hourly workforce. Workstream has been purpose-built for the hourly workforce from day...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Engineer

Information Security Engineer

Irvine Technology Corporation • San Francisco, CA, United States
[job_card.full_time]
San Francisco, CA (Hybrid – 3 days on-site).Irvine Technology Corporation (ITC) – a leading provider of technology and staffing solutions. Security Operations & Incident Response.Assist with 24x7 se...[show_more]
[last_updated.last_updated_30] • [promoted]
Chief Information Security Officer Senior Director

Chief Information Security Officer Senior Director

Unity Technologies • San Francisco, California, USA
[job_card.full_time]
Unitys game development platform and ad networks power the majority of mobile games worldwide.The Unity game engine runs on billions of devices across the globe across mobile - but also consoles PC...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Program Manager GRC

Information Security Program Manager GRC

Upstart • Menlo Park, California, USA
[job_card.full_time]
At Upstart were united by a mission that matters : to radically reduce the cost and complexity of borrowing for all Americans. Every day we bring creativity experimentation and advanced AI to reshape...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Technical Manager - Network and Edge Security | Remote, USA

Technical Manager - Network and Edge Security | Remote, USA

Optiv • San Francisco, CA, United States
[filters.remote]
[job_card.full_time]
The Technical Manager for Network and Edge Security is a senior technical leader responsible for driving the success of client engagements, acting as a trusted advisor, and overseeing delivery exce...[show_more]
[last_updated.last_updated_30] • [promoted]
Remote Enterprise Security Engineering Manager

Remote Enterprise Security Engineering Manager

Mural • San Francisco, CA, United States
[filters.remote]
[job_card.full_time]
A technology company based in the United States is seeking an experienced leader for its enterprise security team.The role involves building and overseeing the enterprise security product suite, di...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Program Manager, Information Security

Senior Program Manager, Information Security

VirtualVocations • San Francisco, California, United States
[job_card.full_time]
Program Manager, Information Security.Key Responsibilities Lead and mature the enterprise information security program through a multi-year roadmap aligned to business strategy Own audit, compli...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Enterprise Information Security Leader

Enterprise Information Security Leader

Grocery Outlet Inc. • Emeryville, CA, United States
[job_card.full_time]
A grocery retail company is seeking a Sr.Director of Information Security to lead its cybersecurity program.The role involves developing and executing security strategies, overseeing incident respo...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Security Compliance Manager

Security Compliance Manager

Hive • San Francisco, CA, US
[job_card.full_time]
We are looking for a highly motivated Security Compliance Manager with a deep security and compliance background to lead system development and process improvement. As part of Hive's Security Team, ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Engineering Manager, Infrastructure & Security

Engineering Manager, Infrastructure & Security

HOVER • San Francisco, CA, United States
[job_card.full_time]
Hover is looking for an Engineering Manager to lead our Infrastructure and Security team and help shape how engineering scales as our systems grow in complexity. This role sits at the intersection o...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Product Security Strategy & Ops Leader

Product Security Strategy & Ops Leader

Salesforce • San Francisco, CA, United States
[job_card.full_time]
A leading tech firm in San Francisco is looking for an Operations and Strategy Senior Manager for their Product Security team. In this role, you will oversee strategic initiatives, ensuring alignmen...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Platform Engineering Manager, Infrastructure & Security

Platform Engineering Manager, Infrastructure & Security

Hover • San Francisco, CA, United States
[job_card.full_time]
A tech company specializing in property design is seeking an Engineering Manager to lead the Infrastructure and Security team. This role involves enhancing systems complexity and supporting product ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]