InfoSec Lead

OrbitalNew York City, NY
Hybrid

About The Position

Orbital is seeking a senior, NYC-based InfoSec Lead to take ownership of information security due diligence, compliance, and vendor risk management. This role is crucial for bringing structure and consistency to these functions, which are currently managed by contractors. The primary focus will be on automating manual tasks, such as customer DDQs, enhancing the company's compliance posture, and establishing the Infosec function as a proactive driver of growth. This is a full-time, individual-contributor role that will collaborate closely with the UK-based IT Manager, Engineering, Product, Legal, and external Infosec support. The position is based in the US, with some flexibility for office visits in New York.

Requirements

  • Significant senior in-house or scale-up InfoSec leadership experience, with end-to-end ownership of due diligence, vendor review, and compliance in a fast-moving business.
  • Strong understanding of cloud and cloud security.
  • Previous technical background in IT Security or SWE/DevOps is ideal.
  • Proven track record of scaling due-diligence processes, including identifying and implementing templating, automation, or self-service solutions.
  • Comfortable engaging in technical conversations with engineering teams and understanding product changes.
  • Pragmatic and delivery-focused approach, with the ability to differentiate between genuine risks and distractions.
  • AI-literacy with working familiarity with AI governance (ISO 42001, EU AI Act etc.).
  • Comfortable operating independently as an individual contributor with ownership of the roadmap.
  • Working knowledge of privacy law (GDPR/CCPA/US state privacy laws).

Nice To Haves

  • Experience in IT operations or IT management is helpful.

Responsibilities

  • Own the InfoSec strategy and roadmap, setting the direction for security and compliance scaling with the business.
  • Identify control gaps and weaknesses, prioritize remediation efforts, and track them to completion.
  • Manage the risk program, including risk identification, assessment, and treatment, and maintain the risk register.
  • Oversee third-party risk assurance, including vendor security reviews and customer/vendor due diligence (DDQs).
  • Drive automation for DDQ processes to reduce manual effort as the function matures.
  • Manage existing and future compliance certifications (ISO 27001, SOC2 Type 2), including ISMS management reviews, access control reviews, audit evidence gathering, and remediation tracking.
  • Maintain policy and public-facing security documentation, such as the trust center.
  • Partner with Engineering, Product, and Legal to embed security and compliance requirements into product development and sales processes.
  • Stay informed about product changes to ensure customer-facing security information is accurate.

Benefits

  • Opportunity to shape how security and compliance scale with the business.
  • Genuine cross-functional influence, working closely with Engineering, Product, and Legal.
  • Involvement in a company with genuine momentum, including recent Series B funding and headcount growth.
  • Work alongside a leadership team that views security as a business enabler.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service