brightfin

brightfin

Vice President of Information Security

United States · Exec

Sponsorship not specifiedDetected 27 days ago
AWSGCPAzurePenetration TestingIncident ResponseComplianceSalesContract ManagementHIPAALeadership

About the role

  • Our customers include large healthcare systems, financial institutions, and global enterprises - organizations where data security and trust are non-negotiable.
  • This is the first dedicated security leadership hire at Brightfin.
  • Ensure compliance with applicable data privacy regulations (GDPR, CCPA, HIPAA where applicable)

Responsibilities

  • This is a builder role - you'll design the program, hire a small team, and grow it as we scale.
  • Design and run brightfin's Information Security Management System (ISMS), aligned to NIST CSF and ISO 27001 principles
  • Maintain and mature security policies, standards, and procedures across the organization
  • Build a security-conscious culture without creating friction for a fast-moving engineering team
  • Own the security review process for enterprise deals - respond to RFPs, security questionnaires, and customer audits
  • Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. brightfin is an

Requirements

  • 6+ years in information security, with at least 3 in a leadership role
  • Experience running the security side of enterprise sales cycles - responding to security questionnaires, hosting customer calls

Nice to have

  • CISSP, CISM, CISA, CRISC, or equivalent
  • Experience at a ServiceNow ecosystem company or enterprise IT management platform
  • Familiarity with HIPAA and financial services security requirements
  • Prior experience reporting to a board or audit committee
  • Startup or high-growth company background - you've built things, not just managed them
  • What this role is not
  • This is not a steady-state security manager role at a mature company with an established program.
  • The right person is energized by that.

Compensation

  • We strongly believe in work-life balance and taking time for yourself.
  • 401K with employer match
  • The above is intended to describe the general content of and requirements for the performance of this job.
  • Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.
  • Candidates are subject to a background check.

Benefits

  • brightfin offers a comprehensive health, dental and vision benefits package.
  • Paid time off.

Company info

  • planning, tabletop exercises, and live incident management
  • Customer and sales enablement
  • Serve as the security point of contact for enterprise prospects and customers; attend calls as needed to build trust
  • Develop and maintain a security trust portal and standard documentation package
  • Build and maintain a risk register; report on risk posture to the executive team and board quarterly
  • Manage third-party and vendor security risk, including contract review and ongoing monitoring
  • Product and engineering security
  • Partner with the engineering team on secure SDLC practices - code scanning, dependency management, penetration testing
  • Drive cloud security posture management for our AWS/Azure/GCP environments
  • Risk and compliance
  • Lead the company's incident response program: planning, tabletop exercises, and live incident management

Equal opportunity

  • Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. brightfin is an equal opportunity employer.
  • equal opportunity employer.

This listing is sourced directly from brightfin's careers page and normalized into a canonical job model.