CareerPlanSign in

InfoSec Lead

New York💼 Full-time🗓 2026-09-21 → 2026-09-26

Core

Own end-to-end information security due diligence, compliance, and vendor risk management to enable business growth and secure certifications.

Role type

Senior IC InfoSec Lead

Builds

Security strategy, risk programs, compliance certifications (ISO 27001, SOC2), and automated due diligence processes.

Domain

Real estate technology / LegalTech / Information Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

InfoSec strategy & roadmap ownership, risk identification & assessment, third-party risk assurance, compliance program management, automation of due diligence, cross-functional partnership, AI governance literacy, privacy law knowledge

Preferred skills

Cloud security expertise, technical background in IT Security or SWE/DevOps, experience scaling due-diligence processes, independent decision-making

Technologies

ISO 27001, SOC2 Type 2, ISO 42001, EU AI Act, GDPR, CCPA

Responsibilities

Set security strategy and roadmap, run risk identification and assessment, manage vendor security reviews and customer DDQs, maintain compliance certifications, drive automation of manual tasks, partner with Engineering/Product/Legal to embed security

Seniority

Senior, hands-on IC

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.