Job Closed

This listing is no longer active.

TrueML logo
TrueML

TrueML is a fintech company building software to create positive experiences for consumers seeking financial health.

Information Security Manager

Security EngineerSecurity EngineerOtherRemoteMid LevelTeam 51-200Since 2013H1B No SponsorCompany SiteLinkedIn

Location

Indiana

Posted

112 days ago

Salary

$150K - $190K / year

Seniority

Mid Level

Bachelor Degree9 yrs expEnglishAWSSIEM

Job Description

Information Security Manager

TrueML

Job Title: Manager of Application Security Why TrueML? TrueML is a mission-driven financial software company that aims to create better customer experiences for distressed borrowers. Consumers today want personal, digital-first experiences that align with their lifestyles, especially when managing finances. TrueML’s approach uses machine learning to engage each customer digitally and adjust strategies in real-time in response to their interactions. The TrueML team includes inspired data scientists, financial services industry experts, and customer experience fanatics who are building technology to serve people in a way that recognizes their unique needs and preferences as human beings and endeavors to ensure nobody gets locked out of the financial system. Your Role We are seeking a talented, motivated Information Security Manager to lead our application security program. This role is critical in protecting our platform, customer data, and internal systems from evolving cyber threats. The ideal candidate will have a strong background in app security architecture, risk management, compliance, and team leadership within a fast-paced technology environment. The ideal candidate will have excellent communication skills and the ability to collaborate effectively with cross-functional teams. Key Responsibilities Strategy and Leadership: Develop, implement, and maintain a comprehensive application security strategy aligned with business objectives and industry best practices. Lead and mentor the app security team, fostering a culture of security awareness and continuous improvement across the organization. Report to leadership on the status of the application security program, including risk posture, incidents, and performance metrics. Evaluate and recommend new application security technologies and tools to enhance the organization's security posture. Appication Security Operations and Architecture: Oversee the day-to-day security operations, including monitoring, threat detection, incident response, and vulnerability management. Design, implement, and manage security controls for our cloud-based SaaS platform (AWS), corporate network, and endpoints. Conduct regular application security assessments, penetration tests, and vulnerability scans, and manage the remediation of identified issues. Risk and Compliance: Maintain an application security risk management framework, identifying, analyzing, and treating risks. Ensure compliance with relevant regulatory requirements and industry standards (e.g., ISO 27001, NIST, PCI DSS, GDPR). Maintain and enforce application security policies, standards, and procedures. Liaise and coordinate internal and external security audits. Qualifications Education: Bachelor's degree in Computer Science, Information Security, or a related field; or equivalent practical experience. 5+ years of experience in application security, with at least 2+ years in a management or leadership role, preferably at a SaaS company. Proven experience designing and securing cloud-native environments (e.g., microservices, containers, serverless). Strong knowledge of, vulnerability analysis, network security, infrastructure security, identity and access management, logging and monitoring,  incident response, application security, and data protection technologies. Proven experience developing and managing an enterprise-level information security program. Relevant security certifications such as CISSP, CISM, or CISA. Technical Skills: • Familiarity with common exploitation techniques, attack vectors, and defensive strategies.• Experience with SIEM tools, vulnerability scanners, penetration testing and threat model methodologies.• Understanding of generative AI and its usage within security and engineering as well as best practices.• Identity Management and Cloud Security. Soft Skills: • Exceptional communication and interpersonal skills to articulate complex security concepts to technical and non-technical audiences. • Strong leadership, organizational, and project management abilities.• Excellent problem-solving and decision-making skills. Must be authorized to work in the US without sponsorship. SPONSORSHIP IS NOT AVAILABLE.

Job Requirements

  • Incident Response:
  • Lead the security incident response team, managing all phases of the incident lifecycle from detection and containment to eradication and recovery. Conduct post-incident reviews to identify root causes and implement preventative measures.
  • Team Leadership:
  • Manage, mentor, and develop the application security team. Assist in managing the security budget and resources effectively. Work with team members to define what success looks like, sets goals, defines metrics and tracks progress.

Related Categories

Related Job Pages

More Security Engineer Jobs

SLED Cybersecurity Sales Specialist

HPE

Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world.

Security Engineer112 days ago

Role Description As a SLED Cybersecurity Sales Specialist, you are an expert in security solutions and the full suite of security offerings across State, Local Government, and Education (SLED) verticals. You are responsible for leading the pursuit of cybersecurity opportunities while collaborating closely with Account Managers and broader sales teams. You drive proactive pipeline-building initiatives and use deep security expertise to prospect, qualify, negotiate, and close complex security deals. You apply advanced subject-matter knowledge to solve complex business challenges and are recognized as a trusted security expert by both internal teams and customers. You frequently contribute to the development of new ideas, methods, and best practices. KEY RESPONSIBILITIES - Create, drive, and manage a robust security sales pipeline. - Capture leads outside of direct specialization and leverage closed-loop lead management. - Maintain strong awareness of competitors within accounts. - Identify new opportunities and expand existing ones. - Support Account Managers with security expertise. - Establish consultative relationships up to C-level executives. - Collaborate with external partners. - Direct and coordinate supporting sales activities. Qualifications - Bachelor’s degree or equivalent experience. - 8–12 years of advanced sales experience. - 3–5 years of cybersecurity-specific sales experience. - 5+ years selling into Government and Education preferred. Requirements - Expert in cybersecurity solutions and competitive positioning. - Strong consultative and enterprise selling skills. - MEDDPICC experience. - Salesforce expertise. - High-value software and services sales experience. Benefits - Health & Wellbeing: Comprehensive suite of benefits that supports physical, financial, and emotional wellbeing. - Personal & Professional Development: Specific programs catered to helping you reach any career goals you have. - Unconditional Inclusion: A commitment to inclusivity and celebrating individual uniqueness.

United States
$194.5K - $456.5K / year
Job Closed
Gainwell Technologies logo

SAP S4 Security GRC Consultant

Gainwell Technologies

Gainwell Technologies is an Equal Opportunity Employer, where all qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical condition), age, sexual orientation, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

Security Engineer112 days ago
Full TimeRemoteTeam 10,001+H1B Sponsor

• Design, implement, and maintain SAP security roles and profiles. • Ensure compliance with SAP security policies and procedures. • Perform regular system audits to detect deviations from security policies. • Collaborate with internal teams to ensure SAP security during the implementation of new SAP modules or functionality. • Provide guidance and training on SAP security issues to other team members. • Develop and maintain documentation related to SAP security controls and procedures. • Stay updated on the latest security threats and SAP technologies to provide informed recommendations.

India
Job Closed
Fluent, Inc logo

AWS Cloud Security Engineer

Fluent, Inc

Simplify the way you find customers with Fluent. Enabling advertisers to identify, win, and build their customer base.

Security Engineer112 days ago
OtherRemoteTeam 201-500H1B No Sponsor

• Design, implement, and maintain security controls across AWS services (EC2, S3, RDS, EKS, ECS, Lambda, API Gateway) • Configure and optimize AWS security services including GuardDuty, CloudTrail, CloudWatch, Security Hub, and AWS Config • Implement VPC security architecture, network segmentation, security groups, and NACLs • Manage CloudFront and ALB security configurations including WAF rules • Secure containerized workloads and serverless architectures • Design and implement least-privilege IAM policies, roles, and permission boundaries • Manage AWS Identity Center (SSO) and integration with Okta • Conduct access reviews and support user provisioning while maintaining security standards • Implement secure service-to-service authentication patterns • Monitor and respond to security alerts from GuardDuty, CloudTrail, and AWS security services • Investigate and remediate security findings from Wiz cloud security platform • Perform threat analysis and security incident investigation • Develop security incident response playbooks for cloud threats • Implement and maintain security controls for Databricks workspaces on AWS • Support SOC 2 and other compliance audit requirements • Maintain security documentation and audit trail evidence • Enforce security policies and compliance standards across AWS accounts • Partner with Engineering, DevOps, and IT teams to integrate security into cloud operations • Automate security processes using Infrastructure as Code • Document security architectures, procedures, and runbooks • Provide security guidance on AWS best practices • Coordinate with external security vendors, testers, and auditors as needed

United States
$130K - $170K / year
Job Closed
Zafran Security logo

GRC and Product Security Lead

Zafran Security

Zafran's Threat Exposure Management Platform integrates with your security tools to reveal, remediate, and mitigate risk

Security Engineer112 days ago
OtherRemoteTeam 11-50H1B No Sponsor

• Own and manage Zafran’s security compliance program, including SOC 2, ISO 27001, and other relevant frameworks • Lead the response to customer security questionnaires and vendor security assessments, ensuring timely and accurate completion • Build and maintain Zafran’s internal security controls framework and evidence collection processes • Establish and manage continuous compliance monitoring and validation initiatives • Develop and maintain security policies, standards, and procedures that support both compliance and business objectives • Manage relationships with external auditors and assessors during compliance audits • Drive security awareness training and secure development practices across the organization • Support customer-facing security conversations during sales cycles and onboarding • Monitor regulatory changes and emerging compliance requirements relevant to SaaS platforms • Build scalability into GRC processes through automation and tooling improvements

United States
Job Closed