Givebutter is a free, end-to-end online fundraising platform on a mission to provide organizations with smarter tools to raise money for more than 35,000 good causes. The company��
Security and Compliance Manager
Location
California + 7 moreAll locations: California | Colorado | New York | Minnesota | Tennessee | Texas | Utah | Washington
Posted
21 days ago
Salary
$170K - $185K / year
Seniority
Lead
Job Description
Security and Compliance Manager
Givebutter
• Codify and execute the security roadmap for the organization, prioritizing the further hardening of critical systems (payment infrastructure, donor data stores, authentication flows, API integrations) and ensuring compliance with applicable laws (e.g., data privacy and security). • Partner directly with PDE leadership to embed security controls into the development lifecycle: threat modeling, secure code review, vulnerability management, and CI/CD pipeline security tooling (SAST, DAST, SCA) • Own the security incident response plan end-to-end: detection, containment, investigation, notification, remediation, and post-incident review • Work with IT to drive identity and access management improvements, including role-based access controls, MFA enforcement, endpoint security, and session management • Develop a deep understanding of fraud vectors in the fundraising and payments space—stolen cards, synthetic identities, friendly fraud, campaign abuse—and help us build systems that adapt as threats evolve. • Manage vendor security risk assessments for third-party tools, integrations, and sub-processors, with continuous monitoring rather than annual check-ins • Own the penetration testing program: vendor relationships, testing cadence, findings translation into engineering tickets, and remediation tracking to closure • Develop and deliver security awareness training for all employees, with targeted modules for PDE, CX, and leadership audiences • Lead SOC 2 Type II certification end-to-end: gap analysis, control design, evidence collection, remediation tracking, auditor coordination, and ongoing maintenance • Build the roadmap toward ISO 27001 certification as the security program matures • Serve as primary owner of our GRC platform (Vanta): driving task completion, monitoring compliance gaps, triaging findings, and ensuring remediation owners are accountable • Manage all external auditor and certification body relationships • Build and maintain evidence repositories that support continuous (not just point-in-time) compliance • Prepare board-ready compliance status reports and risk summaries quarterly • With the General Counsel’s guidance, own all required licenses, registrations, and regulatory filings across US jurisdictions, including state charitable fundraising platform registrations and other licenses • Manage the Trust Center: content accuracy, access approvals, and customer-facing compliance documentation
Job Requirements
- 7+ years of experience in information security, security engineering, GRC, or a related field, with at least 4 years in a fintech, payments, or financial services environment
- Have hands-on experience hardening production systems at a growth-stage company, not just writing policies about them
- Possess deep working knowledge of SOC 2, PCI DSS, and at least one additional framework (NIST CSF, CIS Controls, ISO 27001)
- Understand modern AI-era threat vectors and can articulate a defensive strategy against them
- Have technical fluency: you can read a cloud infrastructure diagram, understand why a GitHub permissions model matters, evaluate a pen test report, and translate all of it into actionable guidance for engineering teams
- Have managed GRC tools hands-on (Vanta, Drata, Secureframe, or similar) and driven remediation workflows to closure, not just monitored dashboards
- Have led external audits end-to-end: auditor relationships, evidence collection, findings remediation, and board-level reporting
- Can build programs, not just maintain them: you thrive in environments where the playbook doesn't exist yet and you need to write it
- Communicate complex security and regulatory topics in plain language to non-technical stakeholders
- Have strong judgment about when to escalate, when to act independently, and when to push back.
Benefits
- Remote Work: Work remotely from one of our 10 hubs (Austin, Denver, Indianapolis, Los Angeles, San Francisco, New York, Salt Lake City, Minneapolis, Seattle, and Nashville).
- Health Insurance: We offer Medical, Dental, and Vision insurance covered 100% for employees as well as HSA and FSA accounts.
- Dependent Care Coverage: We offer coverage for dependents, with 50% of Medical, Dental, and Vision premiums covered for all eligible dependents.
- Mental Health: Givebutter health insurance plans come with access to a TalkSpace membership.
- 401k: We offer a 3% 401k match for all eligible employee's.
- Vacation and Holidays: Givebutter offers a Flexible PTO policy with uncapped vacation days and company-recognized holidays.
- Wellness Week: Givebutter closes for one week each summer to prioritize rest and recharge for the entire team.
- Parental Leave: We offer 12 weeks of paid leave for all parents and comprehensive leave planning management through Aidora.
- Family Care Support: Access a company-paid UrbanSitter membership plus care credits to book trusted, background-checked caregivers for childcare, senior care, pet care, and household support when you need it most.
- Home Office Stipend: Upgrade your home office with company-sponsored expenses, including high-quality laptops, monitors, and modern technology.
- Coworking Stipend: Enjoy a monthly stipend that gives you the freedom to work from coworking spaces or cafés whenever you need connection, community, or a change of scenery.
- Charitable Giving: Employees are encouraged to donate up to $50/month to any verified nonprofit they wish to support on Givebutter.
- Professional Development: We offer learning and development reimbursement opportunities.
- Love What You Do: We are a mission-driven company serving the charitable sector. Feel good about the work you're doing and the company you work for.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity
CapptaAlcance novos horizontes conectando seu negócio a nossa Plataforma White Label de Tecnologia e Serviços Financeiros 🚀
• Experiência comprovada com segurança de sistemas e infraestrutura; • Habilidades "hands-on" para configurar e manter ferramentas de segurança, incluindo firewall, WAFs, sistemas de detecção e prevenção de intrusões (IDS/IPS), antivírus, api gateway e monitoramento de redes; • Monitoramento e investigação de alertas em ferramentas como SIEM e EDR; • Análise de eventos e tentativa de exploração de aplicações e infraestrutura; • Gestão e tratamento de vulnerabilidades (identificação, priorização e acompanhamento de correções); • Análise de código sob a perspectiva de segurança; • Participação em processos de due diligence de segurança em fornecedores; • Apoio na resposta a incidentes e investigação de possíveis comprometimentos; • Habilidade para desenvolver e documentar políticas, diretrizes e manuais de segurança; • Proposição de melhorias em processos e controles.
Vice President, Information Security
LifeMDLifeMD is a rapidly growing telehealth company that delivers virtual primary care and treatment services nationwide. Founded in 1987 and headquartered in New York, New York, LifeMD
• Lead all aspects of enterprise information security, including threat detection, incident response, vulnerability management, and continuous monitoring. • Establish and mature a comprehensive Governance, Risk, and Compliance (GRC) framework aligned to healthcare industry standards (e.g., NIST, HITRUST, ISO 27001). • Continuously assess enterprise risk posture, prioritizing cybersecurity risks in alignment with clinical, operational, and financial risk frameworks. • Design and implement strategies to protect sensitive patient data, including Protected Health Information (PHI), Personally Identifiable Information (PII), and clinical data. • Ensure compliance with healthcare data security and privacy regulations, including HIPAA and HITECH, as well as state-specific privacy laws. • Oversee data governance, encryption, identity management, and secure data exchange across clinical systems (EHR/EMR), patient platforms, and third-party partners. • Own and manage IT risk, compliance, and IT General Controls (ITGC) programs in support of SOX and healthcare regulatory requirements. • Partner with internal audit, compliance, legal, and finance teams to ensure audit readiness and timely remediation of control deficiencies. • Maintain compliance with standards such as HIPAA, HITRUST, SOC 2, PCI-DSS (as applicable), and other healthcare-specific regulatory frameworks. • Lead security architecture across enterprise infrastructure, including cloud, hybrid, and on-premise environments supporting clinical and digital health platforms. • Drive secure cloud transformation initiatives, ensuring appropriate controls across IaaS, PaaS, and SaaS environments. • Partner with engineering, IT, and DevOps teams to implement DevSecOps practices and secure software development lifecycle (SDLC). • Lead enterprise incident response strategy, including preparedness, detection, containment, and recovery from cyber incidents. • Build, lead, and scale a high-performing information security organization, including security operations, risk, IT compliance functions. • Serve as a key advisor to executive leadership, the Board, and Audit/Compliance Committees on cybersecurity risk and strategy. • Drive enterprise-wide security awareness and training programs to foster a culture of security and compliance.
Freelance WordPress, Security, HIPAA Compliance Consultant
Insight Therapy SolutionsWe're changing the world one person at a time.
• Audit WordPress setup, hosting, plugins, forms, integrations, tracking tools, and user access. • Identify HIPAA, privacy, and security gaps related to PHI handling, encryption, access control, backups, logging, and third-party vendors. • Assess risks involving CRMs, analytics tools, email platforms, payment tools, APIs, and form builders. • Review overall website security posture and identify vulnerabilities or misconfigurations. • Provide a concise audit report with findings, risk levels, and prioritized remediation steps.
EIC Information Security Operations Engineer Intern
Cushman & WakefieldWe will never settle for the world that’s been built, but relentlessly drive it forward. #BetterNeverSettles
Role Description The selected candidate works within the Security Operations Center to improve, tune, and enhance security alerts, responses, and remediation of detected issues. The engineer will also work within the Incident Management process to remove threats and vulnerabilities within the organization. This role collaborates with other Information Security and IT Operational teams to maintain a secure environment and incident response capabilities. - Serves as the regional point of contact for security escalations/requests and escalates requests to Security architecture as needed. - Responsible for the identification and assessment of enterprise risks. - Identifies, evaluates, and tests appropriate security products, tools, and systems to ensure alignment with the CushWake global security posture. - Articulates security policies, guidelines, and standards to customers and developers. - Works independently within an established framework. - Develops techniques and procedures for conducting IS and cyber security risk assessments and compliance audits. - Implements IS and cyber security policies and takes measures against intrusion, frauds, attacks, or leaks. - Continues to build knowledge of the organization, processes, and customers. - Partners with Security Architecture on critical scope delivery. - Reviews security INC(s) to ensure proper processes have been followed and to identify additional IoA(s)/IoC(s). - Performs proactive threat hunting using hypothesis and telemetry from endpoints, identities, cloud, and network. - Serves as the security stakeholder for IR/MIM activities until Security Architecture and/or senior leadership can engage. Qualifications - Junior or Senior pursuing a Bachelor’s or Master’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related degree. - Experience in the security domain with exposure to tools such as CrowdStrike, ZScaler, Palo Alto, Mimecast, MS Defender is a plus. - Highly skilled and knowledgeable within the Microsoft environment and toolset. - Energetic and a quick learner. - Good communication skills with a positive attitude. - A willingness to learn new technology. - Experienced in incident response lifecycle and SLAs. - Any Security Certification is an added advantage. Requirements - Experience responding to security incidents in enterprise environments, with a deep understanding of the Incident Response cycle. - Deep understanding of Cybersecurity concepts, principles, and best practices. - Knowledge of Security frameworks and standards (e.g., NIST). - Comprehensive understanding of technical architectures including networking, application and system architecture, web technology, and common internet and ICS protocols. - Knowledge of Windows and MAC operating systems and their security features. - Understanding compliance requirements. - Experience with administrating or architecting solutions in: - Zscaler - CrowdStrike - Mimecast - Wiz - MS Defender - Emphasis on Identity, setting up and analyzing Conditional Access Policies. - Experienced operating as an administrator across security platforms and executing changes per the Security Architecture group's design. - Direct long-term tracking and analysis of Advanced Persistent Threat (APT) actors, including TTPs, infrastructure, and campaign evolution. - Guide the implementation of threat hunting methodologies using SIEM, EDR, and advanced telemetry. - Sponsor and oversee the use of statistical, spatial, and qualitative threat modeling. - Expert level understanding of standard risk classification schemes including CVSS. - Strong organization skills and effective communication on risk with experience presenting to an executive audience. - Mastery of cybersecurity core concepts & terminology, including the vulnerability management lifecycle. - Composure and clear thinking during high-pressure situations. - Capable of performing technical and business risk analysis on cybersecurity issues. - Ability to analyze problems, ask questions, and come up with potential solutions within the confines of our security standards. - Ability to work in multiple areas but track through issue resolution. Benefits - Health, vision, and dental insurance. - Flexible spending accounts. - Health savings accounts. - Retirement savings plans. - Life and disability insurance programs. - Paid and unpaid time away from work. - Competitive pay, which may vary depending on eligibility factors such as geographic location, date of hire, total hours worked, job type, business line, and applicability of collective bargaining agreements.



