About this role
Responsibilities
- Own and mature preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments.
- Translate broad security objectives into concrete technical requirements, controls, tooling, and implementation plans.
- Evaluate, select, configure, and deploy security platforms and tooling across areas such as DLP, insider threat, endpoint security, IAM, vulnerability management, access controls, and security monitoring.
- Continuously assess Backstory’s security posture, identify gaps and vulnerabilities, prioritize risk, and drive remediation through completion.
- Partner closely with IT, Engineering, DevOps, and Product to integrate security controls into new technologies, infrastructure, and business initiatives.
- Build metrics and reporting that provide clear visibility into the effectiveness of our security controls and overall security posture.
- Partner with Security Operations to ensure preventative controls provide the visibility and protection needed to investigate and respond to potential threats.
- Develop, maintain, and test incident response playbooks, business continuity processes, and disaster recovery plans.
- Partner with CISO, CIO and CTO on security compliance initiatives and work directly with auditors to provide evidence, explain controls, and remediate findings.
- Translate requirements from frameworks and regulations including SOC 2, ISO 27001, ISO 42001, GDPR, CCPA/CPRA and EU AI Act into practical technical controls.
- Provide technical direction and mentorship to security engineers, analysts, IT partners, and external contractors.
- Serve as a trusted security advisor across the organization, translating complex threats and vulnerabilities into actionable recommendations for both technical and non-technical stakeholders.
- Take ownership of ambiguous security challenges from strategy and evaluation through implementation, measurement, and continuous improvement.
Qualifications
- 7+ years of progressive experience in information security, with meaningful hands-on experience implementing enterprise security controls.
- 2+ years of technical leadership, team lead, or people management experience.
- Deep understanding of cloud, SaaS, endpoint, identity, network, and data security, including traditional and Agentic AI environments and workloads.
- Strong hands-on experience implementing security tooling and controls rather than solely defining policy or overseeing implementation.
- Experience across areas such as DLP, IAM, endpoint security, vulnerability management, insider threat, access management, and security monitoring.
- Strong understanding of modern cloud infrastructure, security architecture, and risk management.
- Experience operating in a modern Mac, Linux, cloud, SaaS, and open-source-heavy environment.
- Experience automating security controls and workflows through scripting (e.g., Python) and infrastructure as code security (e.g., Terraform, policy as code, CI/CD pipeline guardrails).
- Working knowledge of security frameworks including NIST, CIS, ISO 27001, SOC 2, and Zero Trust.
- Experience participating in security audits, working directly with auditors, gathering technical evidence, and remediating findings.
- Deep knowledge on securing third-party API and OAuth integrations; scoping, token lifecycle management, and revocation across SaaS and data platforms.
- Ability to translate complex technical threats and vulnerabilities into actionable solutions with Engineering, Product, IT, and non-technical stakeholders.
- Strong analytical and problem-solving skills with the ability to independently evaluate security challenges and determine the right technical approach.
- Experience working within U.S.-based technology environments and familiarity with enterprise security expectations.
- Comfortable operating autonomously in a fast-moving environment where priorities and requirements will continue to evolve.
