Job Title: IT, Security & Compliance Manager
Location: Santa Monica, CA (On-site)
Employment Type: Full-time
Level: Mid-Senior
Company: favorited
About the RoleWe're looking for an
IT, Security & Compliance Manager to own and build the systems, processes, and programs that keep favorited secure, compliant, and operationally efficient.
This is a highly hands-on role spanning
IT operations, information security, compliance, risk management, and vendor management. You'll work closely with executive leadership, engineering, operations, and external partners to establish the right technology controls and security practices as the company scales.
You'll also play a key role in determining
which security and compliance certifications favorited should pursue, building the roadmap to achieve them, and ensuring the company maintains the appropriate standards as our customer, creator, and business requirements evolve.
Responsibilities- Own day-to-day IT operations, including systems, applications, access management, devices, identity, and employee technology.
- Develop and maintain favorited's information security program, policies, standards, and controls.
- Own security and compliance readiness, including identifying appropriate certifications and frameworks for the business.
- Develop and manage a roadmap for certifications such as SOC 2, ISO 27001, or other relevant standards based on business and customer requirements.
- Partner with engineering and infrastructure teams to ensure appropriate security controls, monitoring, access management, and infrastructure practices are in place.
- Manage employee identity and access management, including onboarding, offboarding, permissions, and periodic access reviews.
- Establish and maintain security policies covering areas such as access control, acceptable use, data protection, incident response, and vendor risk.
- Own or coordinate security audits, assessments, penetration tests, and compliance reviews.
- Develop and maintain an effective incident response and security escalation process.
- Manage technology and security vendors, including vendor selection, evaluation, contracts, renewals, and ongoing performance.
- Establish a third-party risk management process for vendors that have access to company systems or data.
- Partner with legal, finance, HR, and leadership on privacy, compliance, and risk-related initiatives.
- Maintain accurate documentation and evidence required for security and compliance programs.
- Conduct regular risk assessments and proactively identify opportunities to strengthen the company's security posture.
- Educate employees on security best practices, policies, and compliance requirements.
- Help establish scalable IT and security processes that can support favorited as the company grows.
What We're Looking For- 5+ years of experience across IT, information security, GRC, compliance, or a related field.
- Experience owning or significantly contributing to IT and security programs within a startup or high-growth technology company.
- Strong understanding of security frameworks, controls, risk management, and compliance requirements.
- Experience building security and compliance programs from the ground up.
- Familiarity with SOC 2, ISO 27001, GDPR, CCPA/CPRA, and other relevant security and privacy frameworks.
- Experience managing security audits and certification processes.
- Strong experience with identity and access management, SaaS administration, endpoint security, and IT operations.
- Experience evaluating and managing IT and security vendors.
- Ability to assess the company's needs and determine which security certifications and compliance standards are appropriate.
- Strong organizational and project management skills with the ability to manage multiple priorities.
- Excellent communication skills and the ability to work effectively with both technical and non-technical teams.
- Comfortable operating independently and building processes where they don't yet exist.
- High level of discretion, judgment, and ownership when dealing with sensitive company and user information.
What Stands Out- Experience leading SOC 2 Type II or ISO 27001 certification efforts from planning through completion.
- Experience working in a consumer technology, gaming, social, livestreaming, or SaaS environment.
- Experience supporting companies through rapid growth and increasing security or compliance requirements.
- Familiarity with cloud environments such as AWS or GCP.
- Experience with security and IT tools across identity, endpoint management, vulnerability management, SIEM, and compliance management.
- Experience establishing a security program at a company that previously had limited formal security infrastructure.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, or Security+ are a plus.
- A pragmatic approach to security - someone who understands how to build strong controls without unnecessarily slowing down a fast-moving engineering organization.
Salary & BenefitsCompensation: $140k - $170k base salary
Benefits Include:- Unlimited PTO to prioritize work-life balance.
- 401(k) plan to invest in your future.
- Comprehensive health insurance to support your well-being.
- Paid company holidays to recharge.
- Competitive salary that values your expertise and contributions.
Where You'll Work: This is a full-time, on-site position in Santa Monica.