# Security Program Manager

[Oneleet](https://gurify.com/jobs?q=Oneleet) · United States · Posted 2 months ago

[Project Manager](https://gurify.com/jobs/project-manager)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/oneleet/acb72f78-9ba3-42d8-8109-a3b57193b9dd?callix_sid_ref=a916f6f8-1cd6-41f7-9eb1-d87620d9ab0d&callix_ref_id=j57c0xre8f546hkgjeecjbswmn87bxzt)

## Job description

### ABOUT ONELEET

Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.

Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.

### WHO WE’RE LOOKING FOR:

We value passionate self-starters with a growth mindset and a bias for action and personal accountability. If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you’ll fit right in.

### We’re especially drawn to:

- Rebels with a cause — frustrated with the status quo and eager to disrupt it.

- Opinionated (but not obstinate) builders — decisive yet collaborative, who help us move fast.

- Clear communicators — who own their ideas and follow through.

Our mission is simple: make effective cybersecurity painless. We believe cybersecurity should empower, not burden. This belief unites our team and drives every decision we make.

If you’re ready to challenge the status quo and help shape the future of cybersecurity, we’d love to meet you.

The Security Program Manager is part vCISO & part account manager. You will work with our customers from the start to assess their current security/compliance framework, provide guidance and recommendations for improvements, and work with clients to implement recommendations. You're passionate about security, and enjoy sharing your knowledge with not only our customers but your colleagues.

### KEY RESPONSIBILITIES

- Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.

- Provide guidance and recommendations for improving client security posture

- Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.

- Collaborate with clients to customize and refine the security program to match their specific use cases.

- Communicate with clients and stakeholders to ensure smooth and efficient security program creation

- Liaise with auditors to ensure clients' security programs align with auditors' expectations

- Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.

- Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs.

- Be highly technical, learn new technologies quickly, and translate security concepts into implementations.

- Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.

### REQUIREMENTS

### SECURITY/COMPLIANCE EXPERIENCE

- 4+ years in a role involving information security, compliance, or audit (security operations, GRC, vCISO, security advisory, IT/Compliance auditing, or a security-adjacent customer success/IT support role). You’ll need to understand security and operations well enough that compliance becomes the natural byproduct of genuine security, not just checking boxes against the checklist. You should know why the box exists.

- Working and broad knowledge of security best practices, major compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI), and how controls map to real infrastructure and operations. Audit-side insight is particularly relevant.

### ACCOUNT MANAGEMENT EXPERIENCE

- Technical Account Management experience, or client facing or stakeholder facing experience with strong project management instincts. This is a high-volume, high-interruption, relationship-oriented role that requires you to translate between technical and non-technical people. Startup and business fluency matters, whether gained internally or in consulting with startups, for helping companies find a compliance path that truly fits where they are today.

- Ability to understand client infrastructure and map security controls to meet compliance goals and the bigger picture of holistic security and compliance.

- Strong analytical skills to evaluate environments and determine appropriate safeguards.

- Excellent verbal and written communication skills.

- Self-driven with the ability to work independently, comfortable with ambiguity, and able to adapt approach client-by-client in a fast-moving startup environment.

- Willingness to go the extra mile to meet tight deadlines and deliver results.

### BONUS EXPERIENCE

- One or more of the following certifications: CISA, CISSP, CISM

- Exposure to a “Lead Auditor” scope (cross-framework, whole-program view) rather than a single specialty area

- Prior experience in customer success, IT support, or technical support background (useful for pace/responsiveness this role demands)

WHY ONELEET?

At Oneleet, you’ll join a tight-knit team of rebels redefining the cybersecurity industry. We move fast, own our work, and challenge outdated models to make security effortless and effective for companies.

### Here’s what makes us special:

- We value impact over titles, autonomy over micromanagement, and clarity over jargon.

- You’ll tackle meaningful, hard problems with real-world consequences.

- You’ll work with smart, kind, and ambitious teammates who lift each other up.

### PERKS & BENEFITS

- Comprehensive health & wellness benefits

- 20 days PTO per year, plus 8 floating holiday

- Remote work culture

- Team off-sites in stunning places (Amsterdam, Italy, etc).

- Competitive compensation & equity

We hire globally and compensate competitively within each market using geographic pay bands. The range for this role reflects a US national baseline. Offers for candidates in higher cost-of-labor markets (e.g., San Francisco, New York, Zurich) may fall at or above the top of the posted range, while offers in other markets are benchmarked to local standards and are lower. Within any range, individual compensation is determined by work location, skills and experience demonstrated through the interview process, and relevant education or training. This posting reflects base salary only and does not include equity or benefits.

### Remote-First & Global Hiring

We’re a remote-first company and hire globally in regions where we can legally engage talent directly or via our employer-of-record (EOR) partner. If you’re based outside the U.S., we’ll explore the most compliant hiring arrangement for your location. We make hiring decisions based on merit, skills, and potential regardless of location.

### U.S. Hiring & E-Verify

For U.S.-based candidates, Oneleet participates in E-Verify to confirm employment eligibility, in accordance with federal regulations. We are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.

### How we use AI in this Hiring Process

This company uses automated technology, including AI-assisted tools, to assist in reviewing applications, assessing candidate qualifications, and detecting fraudulent submissions. These tools analyze application data and identity signals to support, but not replace, human hiring decisions. All final hiring decisions are made by a human reviewer. Candidates who require accommodation or who wish to request information about how these tools are used, including requesting the bias audit results, may contact recruiting@oneleet.com. This process is conducted in compliance with applicable federal, state, and local laws.

### Notice for New York City Residents:

You have a right to take at least 10 business days to decide whether to proceed with submitting your information through this process. By continuing, you confirm your understanding of this notice. If you choose to proceed before the 10-business-day period expires, you are making a knowing and voluntary decision to do so.

**Live in Oneleet’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- ON [Security Program Manager](https://gurify.com/job/security-program-manager-at-oneleet-99bfac1eb736) Oneleet · United States · 2 months ago
- SH [Program Manager](https://gurify.com/job/program-manager-at-shieldfc-7952eafd52e9) Shieldfc · NYC, NY · 6 days ago
- PL [Senior Technical Program Manager](https://gurify.com/job/senior-technical-program-manager-at-planetlabs-30dcc35b16c4) Planetlabs · Arlington, VA · last week
- SI [Security Technical Program Manager](https://gurify.com/job/security-technical-program-manager-at-sierra-120634404060) Sierra · San Francisco, CA · 4 weeks ago
- FO [Senior 3PL Program Manager](https://gurify.com/job/senior-3pl-program-manager-at-formlabs-502f0cff9079) Formlabs · Somerville, MA · 2 weeks ago
- GI [Senior Technical Program Manager](https://gurify.com/job/senior-technical-program-manager-at-gitlab-daaf124e0f0f) Gitlab · Remote, United States · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Program Manager","description":"\u003Ch3\u003EABOUT ONELEET\u003C/h3\u003E\u003Cp\u003EOneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.\u003C/p\u003E\u003Cp\u003EHaving just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.\u003C/p\u003E\u003Ch3\u003EWHO WE\u2019RE LOOKING FOR:\u003C/h3\u003E\u003Cp\u003EWe value passionate self-starters with a growth mindset and a bias for action and personal accountability. If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you\u2019ll fit right in.\u003C/p\u003E\u003Ch3\u003EWe\u2019re especially drawn to:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ERebels with a cause \u2014 frustrated with the status quo and eager to disrupt it.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOpinionated (but not obstinate) builders \u2014 decisive yet collaborative, who help us move fast.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EClear communicators \u2014 who own their ideas and follow through.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EOur mission is simple: make effective cybersecurity painless. We believe cybersecurity should empower, not burden. This belief unites our team and drives every decision we make.\u003C/p\u003E\u003Cp\u003EIf you\u2019re ready to challenge the status quo and help shape the future of cybersecurity, we\u2019d love to meet you.\u003C/p\u003E\u003Cp\u003EThe Security Program Manager is part vCISO \u0026amp; part account manager. You will work with our customers from the start to assess their current security/compliance framework, provide guidance and recommendations for improvements, and work with clients to implement recommendations. You\u0026#39;re passionate about security, and enjoy sharing your knowledge with not only our customers but your colleagues.\u003C/p\u003E\u003Ch3\u003EKEY RESPONSIBILITIES\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EConduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProvide guidance and recommendations for improving client security posture\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate with clients to customize and refine the security program to match their specific use cases.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECommunicate with clients and stakeholders to ensure smooth and efficient security program creation\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELiaise with auditors to ensure clients\u0026#39; security programs align with auditors\u0026#39; expectations\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMaintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProvide feedback to Oneleet\u0026#39;s engineering team to inform development of integrations, solutions, and products that deliver on client needs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBe highly technical, learn new technologies quickly, and translate security concepts into implementations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EREQUIREMENTS\u003C/h3\u003E\u003Ch3\u003ESECURITY/COMPLIANCE EXPERIENCE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E4\u002B years in a role involving information security, compliance, or audit (security operations, GRC, vCISO, security advisory, IT/Compliance auditing, or a security-adjacent customer success/IT support role). You\u2019ll need to understand security and operations well enough that compliance becomes the natural byproduct of genuine security, not just checking boxes against the checklist. You should know why the box exists.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking and broad knowledge of security best practices, major compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI), and how controls map to real infrastructure and operations. Audit-side insight is particularly relevant.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EACCOUNT MANAGEMENT EXPERIENCE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ETechnical Account Management experience, or client facing or stakeholder facing experience with strong project management instincts. This is a high-volume, high-interruption, relationship-oriented role that requires you to translate between technical and non-technical people. Startup and business fluency matters, whether gained internally or in consulting with startups, for helping companies find a compliance path that truly fits where they are today.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to understand client infrastructure and map security controls to meet compliance goals and the bigger picture of holistic security and compliance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong analytical skills to evaluate environments and determine appropriate safeguards.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExcellent verbal and written communication skills.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESelf-driven with the ability to work independently, comfortable with ambiguity, and able to adapt approach client-by-client in a fast-moving startup environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWillingness to go the extra mile to meet tight deadlines and deliver results.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EBONUS EXPERIENCE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOne or more of the following certifications: CISA, CISSP, CISM\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExposure to a \u201CLead Auditor\u201D scope (cross-framework, whole-program view) rather than a single specialty area\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrior experience in customer success, IT support, or technical support background (useful for pace/responsiveness this role demands)\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWHY ONELEET?\u003C/p\u003E\u003Cp\u003EAt Oneleet, you\u2019ll join a tight-knit team of rebels redefining the cybersecurity industry. We move fast, own our work, and challenge outdated models to make security effortless and effective for companies.\u003C/p\u003E\u003Ch3\u003EHere\u2019s what makes us special:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EWe value impact over titles, autonomy over micromanagement, and clarity over jargon.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u2019ll tackle meaningful, hard problems with real-world consequences.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u2019ll work with smart, kind, and ambitious teammates who lift each other up.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EPERKS \u0026amp; BENEFITS\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EComprehensive health \u0026amp; wellness benefits\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E20 days PTO per year, plus 8 floating holiday\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERemote work culture\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETeam off-sites in stunning places (Amsterdam, Italy, etc).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive compensation \u0026amp; equity\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe hire globally and compensate competitively within each market using geographic pay bands. The range for this role reflects a US national baseline. Offers for candidates in higher cost-of-labor markets (e.g., San Francisco, New York, Zurich) may fall at or above the top of the posted range, while offers in other markets are benchmarked to local standards and are lower. Within any range, individual compensation is determined by work location, skills and experience demonstrated through the interview process, and relevant education or training. This posting reflects base salary only and does not include equity or benefits.\u003C/p\u003E\u003Ch3\u003ERemote-First \u0026amp; Global Hiring\u003C/h3\u003E\u003Cp\u003EWe\u2019re a remote-first company and hire globally in regions where we can legally engage talent directly or via our employer-of-record (EOR) partner. If you\u2019re based outside the U.S., we\u2019ll explore the most compliant hiring arrangement for your location. We make hiring decisions based on merit, skills, and potential regardless of location.\u003C/p\u003E\u003Ch3\u003EU.S. Hiring \u0026amp; E-Verify\u003C/h3\u003E\u003Cp\u003EFor U.S.-based candidates, Oneleet participates in E-Verify to confirm employment eligibility, in accordance with federal regulations. We are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.\u003C/p\u003E\u003Ch3\u003EHow we use AI in this Hiring Process\u003C/h3\u003E\u003Cp\u003EThis company uses automated technology, including AI-assisted tools, to assist in reviewing applications, assessing candidate qualifications, and detecting fraudulent submissions. These tools analyze application data and identity signals to support, but not replace, human hiring decisions. All final hiring decisions are made by a human reviewer. Candidates who require accommodation or who wish to request information about how these tools are used, including requesting the bias audit results, may contact recruiting@oneleet.com. This process is conducted in compliance with applicable federal, state, and local laws.\u003C/p\u003E\u003Ch3\u003ENotice for New York City Residents:\u003C/h3\u003E\u003Cp\u003EYou have a right to take at least 10 business days to decide whether to proceed with submitting your information through this process. By continuing, you confirm your understanding of this notice. If you choose to proceed before the 10-business-day period expires, you are making a knowing and voluntary decision to do so.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-program-manager-at-oneleet-8acf9fa56a38"},"url":"https://gurify.com/job/security-program-manager-at-oneleet-8acf9fa56a38","datePosted":"2026-07-06","validThrough":"2026-10-22T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Oneleet","sameAs":"https://jobs.ashbyhq.com/oneleet"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"US"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United States","item":"https://gurify.com/jobs/united-states"},{"@type":"ListItem","position":3,"name":"Security Program Manager","item":"https://gurify.com/job/security-program-manager-at-oneleet-8acf9fa56a38"}]}
```
