Remote job
Security Program Manager - LATAM
Job details
About this role
Role overview Customer-facing security program lead that blends virtual CISO advisory with technical account management. The role partners with clients from kickoff through audit, assessing posture, designing control programs mapped to frameworks like SOC 2 and ISO 27001, and translating those programs into concrete policies, configurations, and integrations. It suits someone who enjoys explaining why a control exists, not just checking the box.
Responsibilities - Run initial consultation calls with new clients to assess current security posture, infrastructure stack, compliance requirements, and objectives. - Develop high-level security programs combining technical, operational, and administrative safeguards grounded in recognized frameworks. - Customize and refine each program against the client's specific use cases, then liaise with auditors to keep the program and evidence aligned with their expectations. - Maintain working expertise across frameworks such as NIST, SOC 2, ISO 27001, and CMMC, and across infrastructure stacks including AWS, Azure, GCP, Kubernetes, Docker, and Terraform. - Translate security concepts into practical implementations, partnering with internal teams to produce policies, procedures, configurations, and software integrations. - Feed client learnings back to the internal engineering team to inform integrations and product improvements.
Requirements - 4 or more years in an information security, compliance, or audit role such as security operations, GRC, virtual CISO, security advisory, IT or compliance auditing, or a security-adjacent customer success or IT support position. - Working knowledge of major compliance frameworks including SOC 2, ISO 27001, HIPAA, GDPR, and PCI, with the ability to map controls to real infrastructure and operations. - Technical account management experience, or comparable client-facing or stakeholder-facing experience with strong project management instincts. - Comfort translating between technical and non-technical audiences in a high-volume, high-interruption, relationship-oriented setting. - Startup and business fluency, whether gained in-house or through consulting, to help companies find a compliance approach that fits where they actually are.
Nice to have - Audit-side experience that informs how programs are designed and evidenced. - Familiarity with cloud and infrastructure-as-code tooling across multiple providers.
Benefits and work setup Remote-first organization with global hiring through direct engagement or an employer-of-record partner. Benefits include comprehensive health and wellness coverage, 20 days of PTO plus 8 floating holidays, team off-sites in locations such as Amsterdam and Italy, and competitive compensation with equity. Compensation is benchmarked by geographic pay band, with the posted range reflecting a US national baseline.