InfoSec Lead
Core
Own end-to-end information security due diligence, compliance, and vendor risk management to enable business growth and secure certifications.
Role type
Senior IC InfoSec Lead
Builds
Security strategy, risk programs, compliance certifications (ISO 27001, SOC2), and automated due diligence processes.
Domain
Real estate technology / LegalTech / Information Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
InfoSec strategy & roadmap ownership, risk identification & assessment, third-party risk assurance, compliance program management, automation of due diligence, cross-functional partnership, AI governance literacy, privacy law knowledge
Preferred skills
Cloud security expertise, technical background in IT Security or SWE/DevOps, experience scaling due-diligence processes, independent decision-making
Technologies
ISO 27001, SOC2 Type 2, ISO 42001, EU AI Act, GDPR, CCPA
Responsibilities
Set security strategy and roadmap, run risk identification and assessment, manage vendor security reviews and customer DDQs, maintain compliance certifications, drive automation of manual tasks, partner with Engineering/Product/Legal to embed security
Seniority
Senior, hands-on IC
