IT, Security, and Compliance Manager

Favorited

• $140K — $170K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in IT, information security, GRC, compliance, or a related field.
  • Proven track record in IT and security programs within a startup or high-growth tech company.
  • Strong grasp of security frameworks, controls, risk management, and compliance requirements.
  • Experience building security and compliance programs from scratch.
  • Familiarity with SOC 2, ISO 27001, GDPR, CCPA/CPRA, and other relevant frameworks.
  • Experience managing security audits and certification processes.
  • Strong skills in identity and access management, SaaS administration, and IT operations.

Responsibilities

  • Own day-to-day IT operations, including systems, applications, and access management.
  • Develop and maintain the information security program, policies, and controls.
  • Manage security and compliance readiness, identifying necessary certifications and frameworks.
  • Create a roadmap for achieving certifications like SOC 2 and ISO 27001.
  • Collaborate with engineering to ensure security controls and practices are in place.
  • Manage employee identity and access, including onboarding and periodic reviews.
  • Establish and maintain security policies covering access control and data protection.

Benefits

  • Unlimited PTO to prioritize work-life balance.
  • 401(k) plan to invest in your future.
  • Comprehensive health insurance to support your well-being.
  • Paid company holidays to recharge.
Full Job Description
Job Title: IT, Security & Compliance Manager
Location: Santa Monica, CA (On-site)
Employment Type: Full-time
Level: Mid-Senior
Company: favorited

About the Role

We're looking for an IT, Security & Compliance Manager to own and build the systems, processes, and programs that keep favorited secure, compliant, and operationally efficient.

This is a highly hands-on role spanning IT operations, information security, compliance, risk management, and vendor management. You'll work closely with executive leadership, engineering, operations, and external partners to establish the right technology controls and security practices as the company scales.

You'll also play a key role in determining which security and compliance certifications favorited should pursue, building the roadmap to achieve them, and ensuring the company maintains the appropriate standards as our customer, creator, and business requirements evolve.

Responsibilities
  • Own day-to-day IT operations, including systems, applications, access management, devices, identity, and employee technology.
  • Develop and maintain favorited's information security program, policies, standards, and controls.
  • Own security and compliance readiness, including identifying appropriate certifications and frameworks for the business.
  • Develop and manage a roadmap for certifications such as SOC 2, ISO 27001, or other relevant standards based on business and customer requirements.
  • Partner with engineering and infrastructure teams to ensure appropriate security controls, monitoring, access management, and infrastructure practices are in place.
  • Manage employee identity and access management, including onboarding, offboarding, permissions, and periodic access reviews.
  • Establish and maintain security policies covering areas such as access control, acceptable use, data protection, incident response, and vendor risk.
  • Own or coordinate security audits, assessments, penetration tests, and compliance reviews.
  • Develop and maintain an effective incident response and security escalation process.
  • Manage technology and security vendors, including vendor selection, evaluation, contracts, renewals, and ongoing performance.
  • Establish a third-party risk management process for vendors that have access to company systems or data.
  • Partner with legal, finance, HR, and leadership on privacy, compliance, and risk-related initiatives.
  • Maintain accurate documentation and evidence required for security and compliance programs.
  • Conduct regular risk assessments and proactively identify opportunities to strengthen the company's security posture.
  • Educate employees on security best practices, policies, and compliance requirements.
  • Help establish scalable IT and security processes that can support favorited as the company grows.


What We're Looking For
  • 5+ years of experience across IT, information security, GRC, compliance, or a related field.
  • Experience owning or significantly contributing to IT and security programs within a startup or high-growth technology company.
  • Strong understanding of security frameworks, controls, risk management, and compliance requirements.
  • Experience building security and compliance programs from the ground up.
  • Familiarity with SOC 2, ISO 27001, GDPR, CCPA/CPRA, and other relevant security and privacy frameworks.
  • Experience managing security audits and certification processes.
  • Strong experience with identity and access management, SaaS administration, endpoint security, and IT operations.
  • Experience evaluating and managing IT and security vendors.
  • Ability to assess the company's needs and determine which security certifications and compliance standards are appropriate.
  • Strong organizational and project management skills with the ability to manage multiple priorities.
  • Excellent communication skills and the ability to work effectively with both technical and non-technical teams.
  • Comfortable operating independently and building processes where they don't yet exist.
  • High level of discretion, judgment, and ownership when dealing with sensitive company and user information.


What Stands Out
  • Experience leading SOC 2 Type II or ISO 27001 certification efforts from planning through completion.
  • Experience working in a consumer technology, gaming, social, livestreaming, or SaaS environment.
  • Experience supporting companies through rapid growth and increasing security or compliance requirements.
  • Familiarity with cloud environments such as AWS or GCP.
  • Experience with security and IT tools across identity, endpoint management, vulnerability management, SIEM, and compliance management.
  • Experience establishing a security program at a company that previously had limited formal security infrastructure.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, or Security+ are a plus.
  • A pragmatic approach to security - someone who understands how to build strong controls without unnecessarily slowing down a fast-moving engineering organization.


Salary & Benefits

Compensation: $140k - $170k base salary

Benefits Include:
  • Unlimited PTO to prioritize work-life balance.
  • 401(k) plan to invest in your future.
  • Comprehensive health insurance to support your well-being.
  • Paid company holidays to recharge.
  • Competitive salary that values your expertise and contributions.

Where You'll Work: This is a full-time, on-site position in Santa Monica.

Similar Jobs

More Jobs at Favorited

More Information Technology Jobs

Find similar IT, Security, and Compliance Manager jobs: