Security & Trust Manager

Reco

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security trust, GRC, compliance, or customer-facing security roles at SaaS or cloud companies.
  • Hands-on experience with enterprise security questionnaires and leading customer security reviews.
  • Knowledge of SOC 2, ISO 27001, HIPAA, and common compliance frameworks.
  • Familiarity with AI governance frameworks, specifically ISO 42001 and EU AI Act.
  • Experience with IAM tools like Okta or Azure AD and security automation tools.

Responsibilities

  • Own customer trust operations: manage security questionnaires and vendor assessments.
  • Act as the primary security contact during enterprise sales, resolving blockers quickly.
  • Create and maintain compliance documentation and Trust Center materials.
  • Lead customer audits and security meetings with technical credibility.
  • Enhance Reco's GRC program, including risk assessments and audit readiness.
  • Collaborate with teams to adapt internal practices based on customer security needs.
  • Streamline processes by creating reusable response libraries and optimizing workflows.

Benefits

  • Opportunity to shape customer-facing security and compliance programs.
  • Unique role connecting internal security with customer trust efforts.
  • Collaborative work environment with cross-functional teams.
  • Impactful position that directly influences company revenue and customer relationships.
  • Growth opportunities in enterprise security practices and governance.
Full Job Description
Description

We're looking for a Security and Trust Manager to own Reco's customer-facing security and compliance program while also supporting our internal security operations. This is a high-impact individual contributor role sitting at the intersection of customer trust, GRC, enterprise security, and identity and access management.

On the external side, you'll be the face of Reco security to enterprise customers: owning security questionnaires, audits, and compliance assurance that unblock revenue and build lasting trust. On the internal side, you'll assist enterprise security programs and identity and access controls that protect Reco's own environment. This dual mandate puts you in a unique position: you'll use Reco's own platform to manage the SaaS access risks you're simultaneously explaining to customers.

Responsibilities

Customer Trust and GRC

  • Own Reco's customer trust operations end-to-end: intake, triage, prioritization, and completion of security questionnaires, vendor risk assessments, and RFIs.
  • Serve as the primary security point of contact in enterprise sales cycles; removing security blockers and accelerating deal velocity.
  • Build and maintain Reco's Trust Center and compliance artifacts: SOC 2 evidence, ISO 27001 documentation, security whitepapers, and customer-facing one-pagers.
  • Lead customer-facing security meetings, audits, and diligence calls with technical depth and credibility.
  • Manage and mature Reco's GRC program: frameworks, risk assessments, control monitoring, and audit readiness across SOC 2, ISO 27001, NIST CSF, and applicable regulations.
  • Partner with Product, Engineering, and Legal to translate customer security requirements into internal roadmap inputs.
  • Respond to questions across compliance frameworks including SOC 2, ISO 27001, HIPAA, GDPR, and sector-specific requirements.
  • Drive process improvements: build reusable response libraries, automate questionnaire workflows, and improve SLA performance.

Enterprise Security

  • Support Reco's internal enterprise security posture: endpoint security, MDM, security awareness training, and security policy management.
  • Maintain and improve Reco's internal security policies, standards, and procedures.
  • Contribute to vendor and third-party risk management, ensuring Reco's supply chain meets our own security bar.

Identity and Access Management

  • Partner with IT and Engineering to maintain role-based access controls, audit trails, and access certification processes.
  • Use Reco's own platform to discover, monitor, and remediate identity and SaaS access risks internally.


Requirements

  • 5+ years in security trust, GRC, compliance, or customer-facing security roles at SaaS or cloud companies.
  • Hands-on experience completing enterprise security questionnaires, RFIs, and leading customer security reviews.
  • Working knowledge of SOC 2, ISO 27001, HIPAA, and common compliance frameworks.
  • Familiarity with AI governance frameworks (ISO 42001, EU AI Act).
  • Experience with IAM tools and concepts: SSO (Okta, Azure AD, or equivalent), SCIM provisioning, access reviews, and privilege management.
  • Strong technical foundation: cloud security (AWS, GCP, or Azure), application security, data protection, and access controls.
  • Excellent written and verbal communication -- able to translate complex security topics for both technical and executive audiences.
  • Experience with GRC and trust automation tools (Vanta, Drata, SafeBase, Conveyor, or similar).
  • Collaborative, cross-functional mindset -- comfortable working alongside Sales, Legal, Engineering, and Product.

Similar Jobs

More Jobs at Reco

More Information Technology Jobs

Find similar Security & Trust Manager jobs: