FREE ACCESS
5,000–10,000 jobs/day

See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security and Compliance Manager
GivebutterSecurity & Compliance Manager responsible for enhancing security and compliance at Givebutter. Leading security roadmap, certifications, and incident responses in a growth-stage fintech.
Posted 5/8/2026full-timeRemote • California, Colorado, Minnesota, New York, Tennessee, Texas, Utah, Washington • 🇺🇸 United StatesSeniorLead💰 $170,000 - $185,000 per yearWebsite
Tech Stack
Tools & technologiesCloud
About the role
Key responsibilities & impact- Codify and execute the security roadmap for the organization, prioritizing the further hardening of critical systems (payment infrastructure, donor data stores, authentication flows, API integrations) and ensuring compliance with applicable laws (e.g., data privacy and security).
- Partner directly with PDE leadership to embed security controls into the development lifecycle: threat modeling, secure code review, vulnerability management, and CI/CD pipeline security tooling (SAST, DAST, SCA)
- Own the security incident response plan end-to-end: detection, containment, investigation, notification, remediation, and post-incident review
- Work with IT to drive identity and access management improvements, including role-based access controls, MFA enforcement, endpoint security, and session management
- Develop a deep understanding of fraud vectors in the fundraising and payments space—stolen cards, synthetic identities, friendly fraud, campaign abuse—and help us build systems that adapt as threats evolve.
- Manage vendor security risk assessments for third-party tools, integrations, and sub-processors, with continuous monitoring rather than annual check-ins
- Own the penetration testing program: vendor relationships, testing cadence, findings translation into engineering tickets, and remediation tracking to closure
- Develop and deliver security awareness training for all employees, with targeted modules for PDE, CX, and leadership audiences
- Lead SOC 2 Type II certification end-to-end: gap analysis, control design, evidence collection, remediation tracking, auditor coordination, and ongoing maintenance
- Build the roadmap toward ISO 27001 certification as the security program matures
- Serve as primary owner of our GRC platform (Vanta): driving task completion, monitoring compliance gaps, triaging findings, and ensuring remediation owners are accountable
- Manage all external auditor and certification body relationships
- Build and maintain evidence repositories that support continuous (not just point-in-time) compliance
- Prepare board-ready compliance status reports and risk summaries quarterly
- With the General Counsel’s guidance, own all required licenses, registrations, and regulatory filings across US jurisdictions, including state charitable fundraising platform registrations and other licenses
- Manage the Trust Center: content accuracy, access approvals, and customer-facing compliance documentation
Requirements
What you’ll need- 7+ years of experience in information security, security engineering, GRC, or a related field, with at least 4 years in a fintech, payments, or financial services environment
- Have hands-on experience hardening production systems at a growth-stage company, not just writing policies about them
- Possess deep working knowledge of SOC 2, PCI DSS, and at least one additional framework (NIST CSF, CIS Controls, ISO 27001)
- Understand modern AI-era threat vectors and can articulate a defensive strategy against them
- Have technical fluency: you can read a cloud infrastructure diagram, understand why a GitHub permissions model matters, evaluate a pen test report, and translate all of it into actionable guidance for engineering teams
- Have managed GRC tools hands-on (Vanta, Drata, Secureframe, or similar) and driven remediation workflows to closure, not just monitored dashboards
- Have led external audits end-to-end: auditor relationships, evidence collection, findings remediation, and board-level reporting
- Can build programs, not just maintain them: you thrive in environments where the playbook doesn't exist yet and you need to write it
- Communicate complex security and regulatory topics in plain language to non-technical stakeholders
- Have strong judgment about when to escalate, when to act independently, and when to push back.
Benefits
Comp & perks- Remote Work: Work remotely from one of our 10 hubs (Austin, Denver, Indianapolis, Los Angeles, San Francisco, New York, Salt Lake City, Minneapolis, Seattle, and Nashville).
- Health Insurance: We offer Medical, Dental, and Vision insurance covered 100% for employees as well as HSA and FSA accounts.
- Dependent Care Coverage: We offer coverage for dependents, with 50% of Medical, Dental, and Vision premiums covered for all eligible dependents.
- Mental Health: Givebutter health insurance plans come with access to a TalkSpace membership.
- 401k: We offer a 3% 401k match for all eligible employee's.
- Vacation and Holidays: Givebutter offers a Flexible PTO policy with uncapped vacation days and company-recognized holidays.
- Wellness Week: Givebutter closes for one week each summer to prioritize rest and recharge for the entire team.
- Parental Leave: We offer 12 weeks of paid leave for all parents and comprehensive leave planning management through Aidora.
- Family Care Support: Access a company-paid UrbanSitter membership plus care credits to book trusted, background-checked caregivers for childcare, senior care, pet care, and household support when you need it most.
- Home Office Stipend: Upgrade your home office with company-sponsored expenses, including high-quality laptops, monitors, and modern technology.
- Coworking Stipend: Enjoy a monthly stipend that gives you the freedom to work from coworking spaces or cafés whenever you need connection, community, or a change of scenery.
- Charitable Giving: Employees are encouraged to donate up to $50/month to any verified nonprofit they wish to support on Givebutter.
- Professional Development: We offer learning and development reimbursement opportunities.
- Love What You Do: We are a mission-driven company serving the charitable sector. Feel good about the work you're doing and the company you work for.
ATS Keywords
✓ Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
security roadmap executionthreat modelingsecure code reviewvulnerability managementCI/CD pipeline securitypenetration testingidentity and access managementfraud detectioncompliance monitoringrisk assessment
Soft Skills
communicationjudgmentleadershipprogram buildingcollaborationtraining developmentproblem-solvingstakeholder engagementindependent actionescalation management
Certifications
SOC 2 Type IIISO 27001PCI DSSNIST CSFCIS Controls