Hazelcast Logo

Hazelcast

Senior Manager, Security & IT Ops

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Leads company-wide security governance, compliance, internal IT, risk management, audits, access controls, vendor security, cloud technology standards, incident preparedness, and AI governance. Manages a small team and service providers while remaining hands-on with security and IT operations. Owns SOC 2 Type II and ISO 27001 programs, supports customer security assurance, and establishes ownership, service, and sourcing frameworks across the company.
The summary above was generated by AI
We need a hands-on security and internal IT leader who will set direction and step in to do the work. This person will lead company-wide security governance and compliance and make sure employees have reliable, secure technology. The role reports to the executive responsible for all post-sales operations.
This role will manage a small team and may also oversee contractors or outside service providers.
Responsibilities include setting priorities, coaching and developing team members, managing performance, and building the capabilities needed as the function grows.
Day-to-day, this person will create practical policies and safeguards, raise important risks, and directly manage identity, privileged access, critical software, and internal systems when no clear owner exists.
The role will name primary and backup owners, make technical and business responsibilities clear, and recommend investments. Finance, Procurement, Legal, and business leaders will keep formal approval authority for contracts and spending.
This is primarily an internal role, with customer contact when security expertise is helpful. Engineering owns secure product design and fixes. Cloud SRE and Engineering own customer-production reliability, monitoring, deployments, infrastructure-as-code, upgrades, and on-call work. Customer-facing teams own
routine customer delivery.

WHAT YOU’LL DO
  • Set the company's security direction. Own the security plan, information security management system (ISMS), risk register, policies, control ownership, exceptions, annual policy updates, leadership reporting, and ongoing improvement of the company's security and regulatory standing.
  • Keep audits and compliance work on track. Be the main contact for external auditors and lead annual SOC 2 Type II and ISO 27001 work from readiness through final reports. Keep Secureframe, evidence, findings, corrective actions, and quarterly reviews of user access, firewall settings, and risk controls current.
  • Find risks and make sure they are addressed. Run regular security risk assessments, identify weaknesses in business processes, and work with IT, Cloud SRE, and Engineering Operations on practical fixes. Track security patches and bug fixes against required compliance deadlines.
  • Protect access to company systems. Manage access when people join, change roles, or leave. Apply role-based access, least privilege, separation of duties, and regular reviews; keep clear records of root, administrator, service, and shared accounts; and handle critical access work until a lasting owner or automated process is in place.
  • Manage vendor security risk. Assess new and existing vendors, keep administrator and backup-owner records current, track ownership changes, and rate risk based on the sensitivity of company and customer data. Work with the appropriate business teams on due diligence, renewals, use, and exit planning.
  • Make internal IT dependable and easy to use. Create clear ways for employees to ask for help, set response expectations, document how systems are managed, maintain ownership and transition plans, and track service quality. Personally handle or oversee important administrative work until a lasting owner is in place.
  • Guide internal cloud and technology spending. Set clear security and ownership expectations for internal AWS, Google Cloud, Azure, Kubernetes, VPN/SASE, domains, DNS, shared operational channels, logging, and monitoring. Review costs, unused resources, commitments, and whether work belongs with an internal team or a service provider.
  • Prepare the company for incidents and disruptions. Maintain clear response plans, escalation paths, communications, exercises, follow-up actions, and alerting practices for security and internal IT incidents. Work with Engineering and Cloud SRE on customer-impacting events and review the Business Continuity Plan annually against customer commitments.
  • Help customers understand and trust our security. Work with Sales and Legal on customer and prospect security or vendor questionnaires, and join customer conversations about assurance, risk, incidents, or escalations when security leadership is needed.
  • Contribute to the AI Governance Committee. Participate as a contributing member and bring security, privacy, responsible-use, access, vendor-risk, and operational perspectives to reviews of proposed AI tools and current uses. Help the committee create practical guidance, record decisions and exceptions, and check that agreed actions are completed. Business and technical owners remain accountable for their AI solutions.
  • Show meaningful progress in the first year. Within 12 months, establish an approved security plan, clear control ownership, a dependable audit rhythm, an internal IT service model, an ownership register, a privileged-account inventory, internal-cloud standards, and agreed transition or sourcing plans for important gaps.


WHAT YOU HAVE
  • Experience leading across a company. You have owned a company-wide security, compliance, internal IT, or technology-risk program in a cloud or software company. You can influence leaders and lead a small team, contractors, or service providers while staying close to the work.
  • Hands-on audit and compliance experience. You have directly led ISO 27001 and SOC 2 Type II work, external audits, evidence gathering, policy reviews, findings, corrective actions, control reviews, and customer assurance.
  • Sound risk and resilience judgment. You understand privacy and data protection, business-process and vendor risk, vulnerability and patch management, incident response, business continuity, and compliance deadlines.
  • Technical confidence. You can work comfortably with identity, business software, AWS, Google Cloud, Azure, Kubernetes, networking, firewalls, VPN/SASE, domains, DNS, logging, monitoring, and privileged access.
  • Ability to bring order to unclear work. You have stepped into work with no clear owner, protected continuity, documented what matters, clarified responsibilities, and moved work to the right internal team or service provider.
  • Clear and inclusive communication. You can explain risks and choices to executives, auditors, technical and business teams, customers, and prospects, and can work with Sales and Legal on security questionnaires.
  • Education or equivalent experience. A bachelor's degree in Computer Science, Information Security, Information Systems, or a related discipline, or equivalent practical experience, is preferred.
  • Helpful credentials and experience. CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor, or a similar certification is helpful. Experience in a distributed company, responsible AI governance, technology cost management, or vendor commercial management is also valuable.


BENEFITS
  • Unlimited PTO
  • Medical/Dental/Vision Insurance
  • HSA/FSA
  • Basic & Supplemental Life & AD&D insurance
  • Short & Long-term Disability Insurance
  • 401k
  • EAP (Employee Assistance Program)


About
The world's largest leading companies trust Hazelcast and its unified real-time data platform to take instant action on streaming data. With a stream processing engine and fast data store integrated into a single solution, businesses can simplify real-time architectures for next-gen applications and AI/ML departments to drive new revenue, mitigate risk, and operate efficiently - at a low TCO. To learn more about Hazelcast, or to join our community of CXOs, architects, and developers at brands such as HSBC, JPMorgan Chase, Volvo, New York Life, Domino's, and others, visit hazelcast.comEqual Opportunities at HazelcastWe welcome people from all backgrounds, ethnicities, races, religions, gender, sexual identities, abilities, and personal circumstances, in a spirit of inclusivity and belonging.We are proud to be an equal opportunities employer, and believe we see strength in diversity. If you require any accommodation to assist you in the interview process, please submit this with your application.We offer competitive salaries with a flexible, empathetic and highly collaborative working environment. If you are motivated by the prospect of a career with a forward-thinking tech company, we'd love to hear from you.

Similar Jobs

An Hour Ago
Remote or Hybrid
19-19 Hourly
Entry level
19-19 Hourly
Entry level
eCommerce • Legal Tech • Professional Services • Software • Data Privacy
Conduct outbound consultation calls with clients about credit card processing, assess merchant needs, recommend cost-effective solutions, and convert leads into merchant account applications. Provide customer service, manage client relationships, communicate by phone and email, follow up on pricing quotes, and support other customer service teams. The role requires learning point-of-sale systems and credit card terminals while using consultative sales, negotiation, and problem-solving skills.
Top Skills: Credit Card TerminalsPoint-Of-Sale Systems
3 Hours Ago
In-Office or Remote
152K-213K Annually
Expert/Leader
152K-213K Annually
Expert/Leader
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
Lead FP&A for global Value Services supporting Customer Success, Professional Services, Support, and related teams. Partner with the CCO, manage a team of three, own budgeting, forecasting, financial modeling, performance reporting, executive presentations, ad-hoc analysis, process improvements, headcount and spend controls to optimize margins and support strategic initiatives.
Top Skills: AnaplanChatgptCopilotGeminiExcelPowerPoint
5 Hours Ago
In-Office or Remote
Senior level
Senior level
Artificial Intelligence • Fintech • Software • Financial Services
Own enterprise new-logo acquisition and expansion while personally closing complex, high-value deals and carrying an individual quota. Hire, coach, and develop Enterprise AEs and SDRs; establish forecasting, pipeline, conversion, and sales operating cadences. Partner with Marketing, Product, Customer Success, Partnerships, Legal, and Finance, while presenting performance and strategic recommendations to executives and the board.
Top Skills: ChallengerChorusCommand Of The MessageForce ManagementGongHubspotLinkedin Sales NavigatorMeddpiccOutreachSalesloftZoominfo

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account