Manager of Information Security

Clasp

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

About the Company

Clasp is a Forbes Fintech 50, SHRM-backed company tackling two hard problems at once: helping employers attract and retain talent in critical fields, and easing the student debt crisis. We're at a Series B inflection point, growing fast, with enterprise customers and partner banks who hold us to a high security bar.

Responsibilities

  • Run the SOC 2 program end to end and own the evolution of Information Security policies
  • Lead the IT/TechOps team covering laptop procurement, MDM, onboarding/offboarding, and SaaS management
  • Own third-party security reviews and respond to customer/partner-bank security questionnaires
  • Configure SIEM, manage vulnerability management, and IDS to provide proactive visibility
  • Partner with engineering to advance cloud posture (GCP), IAM, and platform hardening
  • Advance secure SDLC, including dependency scanning, CI/CD hardening, and threat modeling
  • Work with AI Labs to build or buy agentic security solutions for detection, triage, and access reviews

Requirements

  • CISSP certification
  • 5+ years of experience on a security team
  • Startup experience in a fast-paced environment
  • Experience with SOC 2 or ISO 27001 compliance
  • Technical foundation in scripting, web development, automation, or data analysis
  • Ability to prototype and use AI/modern tooling to solve problems efficiently
  • Strong communication skills for interacting with customers, banks, and auditors

Preferred Qualifications

  • Experience in Fintech, lending, or other regulated industries
  • Hands-on depth in GCP security (or AWS)
  • Experience standing up a SOC 2 program from scratch
  • Experience fielding diligence from partner banks or enterprise customers

Benefits

  • Competitive cash and equity compensation
  • Health benefits (health, dental, & vision)
  • Student loan repayment benefits
  • 401k matching
  • Commuter benefits
  • Flexible PTO policy

Skills & tools

SOC 2GCPSIEM

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01CISSP certification
  2. 025+ years security experience
  3. 03Startup experience
  4. 04SOC 2 or ISO 27001 experience
  5. 05Technical foundation in scripting or automation
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches