Security & Trust Manager

Reco

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security trust, GRC, compliance, or customer-facing security roles at SaaS or cloud companies
  • Hands-on experience completing security questionnaires and leading customer security reviews
  • Working knowledge of compliance frameworks such as SOC 2 and ISO 27001
  • Familiarity with AI governance frameworks like ISO 42001, EU AI Act
  • Experience with IAM tools and concepts including SSO and access reviews
  • Strong technical foundation in cloud security and application security
  • Excellent written and verbal communication skills for diverse audiences
  • Experience with GRC and trust automation tools

Responsibilities

  • Own customer trust operations: manage intake, triage, and completion of security questionnaires
  • Serve as the primary security contact in enterprise sales cycles to remove blockers
  • Build and maintain compliance artifacts like SOC 2 evidence and security whitepapers
  • Lead customer-facing security meetings and audits with technical credibility
  • Manage and mature the GRC program, including risk assessments and audit readiness
  • Partner with Product, Engineering, and Legal to match customer security needs with internal initiatives
  • Drive process improvements like automating workflows and enhancing performance
  • Support internal enterprise security initiatives and manage security policies

Benefits

  • Opportunity to work at a high-impact, individual contributor level
  • Access to innovative and advanced security tools and frameworks
  • Chance to influence and shape Reco's security posture and customer trust initiatives
  • Collaborative work environment with cross-functional teams
  • Professional development opportunities in a rapidly evolving field
Full Job Description
Description

We're looking for a Security and Trust Manager to own Reco's customer-facing security and compliance program while also supporting our internal security operations. This is a high-impact individual contributor role sitting at the intersection of customer trust, GRC, enterprise security, and identity and access management.

On the external side, you'll be the face of Reco security to enterprise customers: owning security questionnaires, audits, and compliance assurance that unblock revenue and build lasting trust. On the internal side, you'll assist enterprise security programs and identity and access controls that protect Reco's own environment. This dual mandate puts you in a unique position: you'll use Reco's own platform to manage the SaaS access risks you're simultaneously explaining to customers.

Responsibilities

Customer Trust and GRC

  • Own Reco's customer trust operations end-to-end: intake, triage, prioritization, and completion of security questionnaires, vendor risk assessments, and RFIs.
  • Serve as the primary security point of contact in enterprise sales cycles; removing security blockers and accelerating deal velocity.
  • Build and maintain Reco's Trust Center and compliance artifacts: SOC 2 evidence, ISO 27001 documentation, security whitepapers, and customer-facing one-pagers.
  • Lead customer-facing security meetings, audits, and diligence calls with technical depth and credibility.
  • Manage and mature Reco's GRC program: frameworks, risk assessments, control monitoring, and audit readiness across SOC 2, ISO 27001, NIST CSF, and applicable regulations.
  • Partner with Product, Engineering, and Legal to translate customer security requirements into internal roadmap inputs.
  • Respond to questions across compliance frameworks including SOC 2, ISO 27001, HIPAA, GDPR, and sector-specific requirements.
  • Drive process improvements: build reusable response libraries, automate questionnaire workflows, and improve SLA performance.

Enterprise Security

  • Support Reco's internal enterprise security posture: endpoint security, MDM, security awareness training, and security policy management.
  • Maintain and improve Reco's internal security policies, standards, and procedures.
  • Contribute to vendor and third-party risk management, ensuring Reco's supply chain meets our own security bar.

Identity and Access Management

  • Partner with IT and Engineering to maintain role-based access controls, audit trails, and access certification processes.
  • Use Reco's own platform to discover, monitor, and remediate identity and SaaS access risks internally.


Requirements

  • 5+ years in security trust, GRC, compliance, or customer-facing security roles at SaaS or cloud companies.
  • Hands-on experience completing enterprise security questionnaires, RFIs, and leading customer security reviews.
  • Working knowledge of SOC 2, ISO 27001, HIPAA, and common compliance frameworks.
  • Familiarity with AI governance frameworks (ISO 42001, EU AI Act).
  • Experience with IAM tools and concepts: SSO (Okta, Azure AD, or equivalent), SCIM provisioning, access reviews, and privilege management.
  • Strong technical foundation: cloud security (AWS, GCP, or Azure), application security, data protection, and access controls.
  • Excellent written and verbal communication -- able to translate complex security topics for both technical and executive audiences.
  • Experience with GRC and trust automation tools (Vanta, Drata, SafeBase, Conveyor, or similar).
  • Collaborative, cross-functional mindset -- comfortable working alongside Sales, Legal, Engineering, and Product.

Similar Jobs

More Jobs at Reco

More Information Technology Jobs

Find similar Security & Trust Manager jobs: