WeaveGrid is looking for a mission-driven, highly independent, action-oriented information security and information technology professional to oversee its InfoSec and IT functions. You will oversee the company’s IT vendor(s), security and compliance, and drive AI and technology adoption within the business. Key responsibilities include: Own and execute WeaveGrid's information security and IT program end-to-end — this is a high-impact, hands-on IC role. Maintain cloud security posture across AWS (IAM governance, configuration review, cloud-native security tooling) Own the corporate security control environment — EDR, email security, identity governance, network monitoring, DLP Oversee strategy and day-to-day management of our IT services contractor(s). Ensure operational excellence and intervene as needed to ensure timely responses to internal stakeholders. Serve as the internal technical owner of the corporate IT environment and escalation point for security-intersecting IT issues Manage SOC 2 Type II compliance across all five Trust Service Criteria, including auditor relationships and evidence collection Support CCPA and privacy compliance by monitoring and managing data subject access requests and the associated overarching process, applicable website technologies, and ad hoc privacy requests, in partnership with the Legal team. Own application security for our web and mobile products, including coordinating annual penetration tests and driving remediation with Engineering. Run the vulnerability management program — prioritization, tracking, and reporting. Manage incident response — maintain the IR plan, run tabletop exercises, and handle real incidents through to post-mortem. Maintain and test BC/DR plans in coordination with Engineering and Operations. Conduct and document quarterly access reviews across critical systems. Review security terms in vendor and customer contracts; complete customer security questionnaires; run vendor risk assessments. Help administer the personnel security program (security awareness training, onboarding/offboarding controls) in partnership with the People team. Lead the company’s Information Security & IT Committee — evaluating tools, defining acceptable use, and managing data exposure risk across sanctioned tools, including AI platforms Drive AI and new technology adoption within WeaveGrid, engaging internal and external stakeholders as applicable
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed