Authentic Brands Group

Manager, IT Security and Compliance

Authentic Brands Group$140K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related field.
  • 7+ years of experience in cybersecurity or IT compliance.
  • Strong understanding of security fundamentals like access management and data protection.
  • Experience with applications, SaaS platforms, cloud environments, and API technologies.
  • Ability to perform risk assessments and communicate findings effectively.
  • Familiarity with security frameworks such as NIST CSF or SOC 2.

Responsibilities

  • Lead security and compliance reviews for new technologies.
  • Assess risk for business and technology initiatives with a focus on data protection.
  • Define and implement security controls aligned with business needs.
  • Collaborate with stakeholders to identify requirements early in projects.
  • Support compliance activities including documentation and audit responses.
  • Strengthen security posture through control improvements and remediation planning.
  • Conduct reviews of third-party technology solutions for compliance.

Benefits

  • Direct impact on managing cybersecurity and compliance.
  • High visibility with leadership and multiple stakeholder teams.
  • Opportunity to build scalable processes from scratch.
  • Broad exposure to various technologies and systems.
  • Balancing business enablement with effective risk management.
Full Job Description
Position Justification

As the organization continues to grow and adopt new technologies, the security and compliance function must scale beyond reactive reviews and ad hoc guidance. Business teams are increasingly relying on SaaS platforms, APIs, cloud services, integrations, automation, and AI-enabled tools to support daily operations. Each of these areas can introduce risk if access, data protection, vendor oversight, logging, configuration, and control requirements are not consistently managed.

Establishing a Manager, Security & Compliance role will provide dedicated oversight for security risk management, application and integration reviews, control design, compliance support, and secure technology adoption. This role will help reduce regulatory, audit, operational, and reputational risk by ensuring that security and compliance requirements are built into new initiatives early, documented clearly, and tracked through remediation.

The role will also relieve existing teams of one-off security assessments, strengthen accountability across the control environment, and create a scalable function that supports the business while maintaining appropriate governance over sensitive data and critical systems.
Position Overview

We are seeking a Manager, Security & Compliance to help strengthen the organization's cybersecurity, technology risk, and compliance programs. This role will be responsible for evaluating security risks, designing practical controls, supporting audit and compliance activities, and partnering with business and technology teams to ensure new systems, integrations, and processes are implemented securely.

This is a highly visible, cross-functional role suited for someone who can operate effectively in a fast-moving, lean environment. The successful candidate will work directly with application owners, business leaders, IT, legal, and technology teams to translate security and compliance expectations into clear, practical requirements without unnecessarily slowing down the business.

This role reports to the Director of Cyber Security & Compliance.
What You'll Do
  • Lead security and compliance reviews for new and existing technologies, including SaaS platforms, applications, APIs, cloud services, integrations, automation tools, and AI-enabled solutions.
  • Assess risk across business and technology initiatives, with a focus on data protection, access controls, vendor risk, logging, auditability, and secure configuration.
  • Define and implement practical security controls that align with business needs, regulatory expectations, internal policies, and audit requirements.
  • Partner with application owners and business stakeholders to identify security and compliance requirements early in the project lifecycle.
  • Conduct security and architecture reviews for applications, APIs, integrations, data flows, and third-party platforms.
  • Support compliance activities, including evidence collection, control documentation, risk remediation tracking, user access reviews, and audit response.
  • Strengthen application and network security posture by contributing to secure design, vulnerability management, control improvements, and remediation planning.
  • Review third-party technology solutions and support vendor due diligence from a security and compliance perspective.
  • Establish and maintain guardrails for technology use, including acceptable use, data handling, access management, logging, monitoring, and approval standards.
  • Support incident response and investigations involving applications, integrations, vendor platforms, data exposure, or control failures.
  • Track risks, issues, remediation plans, and control maturity, and provide clear reporting to leadership.
  • Help develop lightweight, scalable processes for reviewing and approving new technologies in a growing organization.
  • Stay current on emerging threats, compliance expectations, cybersecurity frameworks, and industry best practices.
  • Implement and test CI/CD and secure development controls within internally developed applications.
What You Bring
  • Bachelor's degree in Computer Science, Information Security, Information Systems, or a related field.
  • 7+ years of experience in cybersecurity, technology risk, IT audit, compliance, application security, or network security.
  • Strong understanding of security and compliance fundamentals, including access management, authentication, authorization, data protection, logging, vulnerability management, and secure configuration.
  • Experience reviewing applications, APIs, SaaS platforms, cloud environments, or integration-heavy technology ecosystems.
  • Familiarity with application security concepts, including OWASP risks, secure SDLC practices, API security, and data protection requirements.
  • Solid grounding in network security concepts and modern enterprise architectures.
  • Experience designing, documenting, or testing security controls in SaaS, cloud, or API-driven environments.
  • Ability to perform risk assessments and translate findings into practical, business-friendly recommendations.
  • Experience supporting audits, compliance programs, or security governance activities.
  • Strong communication skills and the ability to influence decisions across technical and non-technical teams.
  • Comfortable operating in a lean, fast-paced environment with evolving priorities.
Nice to Have
  • Familiarity with frameworks such as NIST CSF, CIS Controls, SOC 2, ISO 27001, or similar control frameworks.
  • Experience supporting SOC 2, internal audit, external audit, or regulatory compliance programs.
  • Experience with third-party risk management, user access reviews, policy governance, or control testing.
  • Exposure to AI governance, emerging technology risk, or responsible AI initiatives.
  • Experience in a mid-sized or growth-stage company environment.
  • Industry certifications such as CISSP, CISA, CCSP, GIAC, Security+, or similar.
Why This Role Is Unique
  • Direct impact on how the company manages cybersecurity, compliance, and technology risk as it grows.
  • High visibility with leadership, IT, legal, business stakeholders, and application owners.
  • Opportunity to build scalable security and compliance processes from the ground up.
  • Broad exposure across applications, infrastructure, cloud, SaaS platforms, integrations, and emerging technologies.
  • A chance to balance business enablement with real-world risk management, not just enforce policy.
Success in This Role Looks Like
  • New technologies are reviewed consistently, with clear security and compliance requirements defined early.
  • Security is seen as a practical business partner, not a blocker.
  • Risks are identified, documented, prioritized, and tracked through remediation.
  • Controls are practical, scalable, and aligned with audit and compliance expectations.
  • Application, integration, and third-party risks are reduced before they become issues.
  • Strong partnerships exist across security, IT, legal, compliance, and business teams.
  • AI-enabled technologies are governed as part of the broader security and compliance program, rather than managed as a standalone effort.
Primary Location Salary Range:
$140,000 - $150,000

About Authentic Brands Group

Authentic Brands Group (ABG) is a brand development, marketing, and entertainment company, which owns a portfolio of global media, entertainment, and lifestyle brands. The company was founded in 2010 by Jamie Salter, and is headquartered in New York City. ABG's portfolio includes over 50 brands, such as Marilyn Monroe, Elvis Presley, Muhammad Ali, Shaquille O'Neal, and Sports Illustrated. The company's business model is to acquire intellectual property rights to well-known brands, and then monetize them through licensing deals, partnerships, and collaborations. ABG has been recognized as one of the fastest-growing companies in the United States by Inc. Magazine, and has been named one of the most innovative companies in the world by Fast Company.
Learn more about Authentic Brands Group
Size
1,000 employees
Industry
Founded
2010

Similar Jobs

More Jobs at Authentic Brands Group

More Information Technology Jobs

Find similar Manager, IT Security and Compliance jobs: