Avant

Security Manager

Avant$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in information security, including 1-2 years in a security management or GRC role.
  • Knowledgeable about NIST, ISO 27001, GDPR, and CCPA/CPRA requirements.
  • Familiarity with vulnerability scanning and penetration testing methodologies.
  • Experience using endpoint management and device security tools.
  • Understanding of SaaS/vendor risk assessments and their processes.
  • Emerging knowledge of AI security and governance risks.
  • Strong communication skills for explaining technical risk to non-technical stakeholders.

Responsibilities

  • Oversee employee security practices and device compliance to internal policies.
  • Maintain visibility into endpoint configurations and security measures.
  • Manage identity and access controls including MFA and offboarding.
  • Conduct security awareness training and phishing simulations.
  • Evaluate new software and AI tools for data security and vendor risk.
  • Perform regular vendor security assessments and maintain a risk register.
  • Coordinate vulnerability scans and penetration testing engagements.

Benefits

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Commuter Benefits
  • 401K Match
  • Unlimited PTO
  • Generous Parental Leave
Full Job Description
Job Type

Full-time

Description

Position Title: Security Manager

Department: Technology

Reports To: VP of IT

Location: Chicago / Remote

Employment Type: Full-Time

About the Role:

We're looking for a hands-on Security Manager to own our organization's day-to-day security posture - across our people, endpoints, software, and vendors. This role sits at the intersection of governance, technical security operations, and emerging AI risk. You'll be the person who knows where our exposure is, who's using what, and whether our controls actually hold up under testing.

We need someone comfortable both setting standards and getting into the weeds - reviewing a vendor's SOC 2 report one hour, scoping a vulnerability scan the next, and evaluating whether a new AI tool an employee wants to use is safe to approve.

What You'll Do:

Employee & Endpoint Security
  • Monitor employee security practices, device compliance, and adherence to internal security policies
  • Maintain visibility into laptops, mobile devices, and endpoints - encryption status, EDR/antivirus coverage, and configuration drift
  • Manage identity and access controls (least privilege, MFA, offboarding, privileged access reviews)
  • Run security awareness training and phishing simulations
  • Software & Shadow IT Oversight
  • Maintain an inventory of software and SaaS tools in use across the organization, including unsanctioned ("shadow IT") applications
  • Evaluate and approve new software and AI tools before adoption, assessing data handling, permissions, and vendor risk
  • Track license and application sprawl as a security (not just cost) issue

AI Security
  • Stay current on AI-specific risks: prompt injection, data leakage through AI tools, model/vendor data retention policies, unsanctioned use of generative AI on sensitive data, and supply-chain risk in AI-powered products
  • Develop and enforce acceptable-use policies for AI tools and copilots
  • Assess AI vendors and features embedded in existing software (e.g., new AI features rolled into SaaS products) for security implications

Third-Party & Vendor Risk
  • Conduct vendor security assessments and due diligence before and during engagements
  • Review vendor security documentation (SOC 2, ISO 27001 certifications, penetration test summaries, security questionnaires)
  • Maintain a third-party risk register and reassess periodically based on criticality and data access

Technical Security Operations
  • Coordinate or perform vulnerability scanning across infrastructure, endpoints, and applications
  • Manage or oversee penetration testing engagements (internal team or external vendors), track findings through remediation
  • Perform cyber risk assessments across systems, business units, and processes
  • Support incident response: detection, triage, containment, and post-incident review

Governance, Risk & Compliance
  • Maintain and mature the security program in alignment with frameworks such as NIST CSF/800-53, ISO 27001, SOC 2
  • Ensure practices support compliance with data privacy regulations including GDPR and CCPA/CPRA
  • Own or contribute to security policies, standards, and audit readiness
  • Report on security posture, risk, and metrics to leadership


Requirements

  • 4+ years in information security, with at least 1-2 years in a security management, GRC, or senior analyst role
  • Working knowledge of NIST, ISO 27001, GDPR, and CCPA/CPRA requirements
  • Although we outsource these functions, familiarity with vulnerability scanning tools (e.g., Nessus, Qualys, Tenable); with penetration testing methodology (internal team or managing external testers); and with Security Operations functions (SOC) and how to work with our MSSP to mitigate and remediate events
  • Experience with endpoint management/MDM tools and understanding of laptop/device security controls
  • Familiarity with SaaS/vendor risk assessment processes
  • Emerging understanding of AI security risks and governance - you don't need to be an ML engineer, but you should be able to speak intelligently about the risks generative AI and AI-embedded tools introduce
  • Strong communication skills - able to translate technical risk into business terms for non-technical stakeholders
  • Comfortable balancing policy/governance work with hands-on technical review

Nice to Have
  • Relevant certifications: CISSP[RM1.1], CISM, Security+, GSEC, CEH, or similar
  • Experience building or maturing a security program from an early stage
  • Prior experience in a regulated industry (finance, healthcare, or similar)


Benefits
• Medical Insurance
• Dental Insurance
• Vision Insurance
• Commuter Benefits
• 401K Match
• Unlimited PTO
• Generous Parental Leave

The information contained in this job description is intended to convey information about the essential functions and requirements of the position. It is not an exhaustive list of the skills, efforts, duties, responsibilities or working conditions associated with the opportunity. In addition, the employee should be able to communicate effectively and in a constructive manner with management, peers, and coworkers.

About Avant

Avant, LLC, formerly AvantCredit, is a private Chicago, Illinois-based company in the financial technology industry. The company was established in 2012 by serial entrepreneur Albert "Al" Goldstein, John Sun, and Paul Zhang. Initially structured as a mid-prime lender, the company issued its first personal unsecured loan in early 2013 using its proprietary technology to determine an individual's creditworthiness. Avant's technology applies algorithms, machine-learning protocols, and analytical tools in addition to the standard consumer data pulled to determine a customized rate, amount and length at which money can be borrowed. The company began providing access to loans in just 16 states in 2013. Avant currently issues loans in 46 states, and in October 2013, the company expanded beyond US borders to Canada and the United Kingdom. From 2012 to 2015 the company saw substantial growth with over $1 billion in loans originated through Avant's website and $1.4 billion in contributions by investors, including August Capital, Tiger Global and Victory Park Capital.
Learn more about Avant
Industry
Founded
2012

Similar Jobs

More Jobs at Avant

  • Avant
    Security Manager
    $100K — $120K *
    Chicago, IL 60629 (Cook County)
    Information Technology
    In-Person
  • Avant
    Manager, Sales Operations
    $95K — $115K *
    Chicago, IL 60629 (Cook County)
    Business Services
    In-Person

More Information Technology Jobs

Find similar Security Manager jobs: