openashbyhqclaspgroup
Manager of Information Security
Clasp Group
LocationRemote
WorkplaceFull
EmploymentFullTime
Posted2026-08-18T21:46:12.843+00:00
Last observed2026-08-26 21:51:09.050905
Job idclaspgroup-clasp-group:ashbyhq:01461ef9-7278-435d-a9f2-4d729b8787c6
MANAGER OF INFORMATION SECURITY Team: Information Security Reports to: CTO Location: Remote (US, EST/CST hours) Manages: IT/TechOps (1) ABOUT US Clasp is a Forbes Fintech 50, SHRM-backed company tackling two hard problems at once: helping employers attract and retain talent in critical fields, and easing the student debt crisis. We're at a Series B inflection point, growing fast, with enterprise customers and partner banks who hold us to a high security bar. WHY THIS ROLE We're an AI-first company with a genuinely strong technical team and solid foundations already in place including a running SOC 2 program, a modern GCP infrastructure, a well-managed macOS/Windows fleet, and an engineering culture that ships. Your mission is to take ownership of the information security program, lead our Information Technology team, and pair with engineering leadership and AI Labs on the deep technical work. This is the rare security role reporting to the CTO where you get real ownership on day one without inheriting a mess. If you're the kind of security leader who'd rather stand up a SIEM, harden a Terraform pipeline, and build your own tooling than manage a stack of vendors, this role was built for you. WHAT YOU'LL OWN - SOC 2, Vanta & governance. Run our SOC 2 program end to end, own evolution of our Information Security policies, own our Vanta instance, run events such as business continuity drills, and represent information security in our Risk + Compliance committee. - IT/TechOps. Lead and collaborate with our IT/TechOps team across corporate IT and security: laptop procurement, MDM, onboarding/offboarding, SaaS vendor management and hardening, incident response, data loss protection, and more. Together you'll set direction and grow the function and the team as we scale. - Vendor diligence & security questionnaires. Own third-party security reviews, and be the front line for inbound customer and partner-bank security questionnaires - SIEM, Vulnerability Management & IDS. Configure our SIEM, build the alerting that gives us real signal without noise, and manage vendor relationships for real proactive visibility and risk reductions. - Cloud & access security (GCP). Pair with technical leaders to advance our cloud posture, IAM (JIT privilege escalation, group-based access), and platform hardening. - AppSec & secure SDLC. Partner with engineering to advance secure SDLC in a rapidly changing agentic world. Ensure dependency and vulnerability scanning is effective, CI/CD and pipelines are hardened, and new features have robust threat modeling. - AI security agents. Work with the CTO and AI Labs to run build vs buy analysis for all categories of agentic security work: detection/triage, evidence collection, questionnaire drafting, access reviews and more. Additionally, ensure all other deployed agents operate securely.. HOW WE THINK ABOUT SECURITY IN THE AGE OF AI The security landscape in 2026 is changing fast. We want to implement best-of-breed vendors and roll up our sleeves to engineer in-house solutions when it makes the most sense. We don’t want to just throw head count or complex solutions at a problem that can instead be automated and configured in depth to be more resilient than brittle commercial solutions. You'll be hands-on and genuinely exhilarated to work closely with our technical teams to build and maintain internal security capabilities across SIEM, IDS, and more. WHAT WE'RE LOOKING FOR - CISSP certification. - 5+ years on a security team. - Startup experience — you've worked somewhere scrappy, not only at large/mega companies. - Compliance in the room — you've been at a company that achieved SOC 2 or ISO 27001. - A technical foundation — a semi-technical degree (Information Systems or similar) or a few years of hands-on technical work (scripting, web development, automation, data analysis, etc.). - AI builder's instinct — comfortable scripting, prototyping, and using AI and modern tooling to solve problems efficiently. - Stro
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.