brightfin
Vice President of Information Security
United States · Exec
Sponsorship not specifiedDetected 27 days ago
AWSGCPAzurePenetration TestingIncident ResponseComplianceSalesContract ManagementHIPAALeadership
About the role
- Our customers include large healthcare systems, financial institutions, and global enterprises - organizations where data security and trust are non-negotiable.
- This is the first dedicated security leadership hire at Brightfin.
- Ensure compliance with applicable data privacy regulations (GDPR, CCPA, HIPAA where applicable)
Responsibilities
- This is a builder role - you'll design the program, hire a small team, and grow it as we scale.
- Design and run brightfin's Information Security Management System (ISMS), aligned to NIST CSF and ISO 27001 principles
- Maintain and mature security policies, standards, and procedures across the organization
- Build a security-conscious culture without creating friction for a fast-moving engineering team
- Own the security review process for enterprise deals - respond to RFPs, security questionnaires, and customer audits
- Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. brightfin is an
Requirements
- 6+ years in information security, with at least 3 in a leadership role
- Experience running the security side of enterprise sales cycles - responding to security questionnaires, hosting customer calls
Nice to have
- CISSP, CISM, CISA, CRISC, or equivalent
- Experience at a ServiceNow ecosystem company or enterprise IT management platform
- Familiarity with HIPAA and financial services security requirements
- Prior experience reporting to a board or audit committee
- Startup or high-growth company background - you've built things, not just managed them
- What this role is not
- This is not a steady-state security manager role at a mature company with an established program.
- The right person is energized by that.
Compensation
- We strongly believe in work-life balance and taking time for yourself.
- 401K with employer match
- The above is intended to describe the general content of and requirements for the performance of this job.
- Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.
- Candidates are subject to a background check.
Benefits
- brightfin offers a comprehensive health, dental and vision benefits package.
- Paid time off.
Company info
- planning, tabletop exercises, and live incident management
- Customer and sales enablement
- Serve as the security point of contact for enterprise prospects and customers; attend calls as needed to build trust
- Develop and maintain a security trust portal and standard documentation package
- Build and maintain a risk register; report on risk posture to the executive team and board quarterly
- Manage third-party and vendor security risk, including contract review and ongoing monitoring
- Product and engineering security
- Partner with the engineering team on secure SDLC practices - code scanning, dependency management, penetration testing
- Drive cloud security posture management for our AWS/Azure/GCP environments
- Risk and compliance
- Lead the company's incident response program: planning, tabletop exercises, and live incident management
Equal opportunity
- Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. brightfin is an equal opportunity employer.
- equal opportunity employer.
Apply directly at brightfin →Create a free account for alerts like thisView brightfin immigration profile
This listing is sourced directly from brightfin's careers page and normalized into a canonical job model.