Information Security Manager, Compliance

at Wallarm. API & App Security Integrated
  • Remote - Worldwide

Remote

Cybersecurity

Manager

Job description

Description

Short facts about us:

  • We are a global remote-first team of 100+ people on 4 continents and in 10+ countries.

  • We have been protecting our clients since 2016.

  • The company has raised over $10M in investments.

  • More than 200 customers around the world, including Fortune 500, Nasdaq, and high-growth startups choose Wallarm to protect their API and web applications.

  • The company passed Y Combinator, the most prestigious incubator in Silicon Valley, from which Dropbox, Stripe, Docker, etc. came out.

Our product:

Wallarm API security solutions provide proven performance to support innovative companies serving millions of users and billions of API requests per month. Hundreds of Security and DevOps teams globally use Wallarm daily to:

  1. Discover. See every asset across your entire attack surface—from cloud environments to every API endpoint with auto-discovery capabilities.

  2. Protect. A single suite that goes beyond OWASP Top 10 for full coverage for API specific threats, account takeover, malicious bots, L7 DDoS, and more.

  3. Respond. Streamline incident response with complete visibility, smart triggers, and active threat verification.

  4. Test. Automate security testing of your APIs and web assets. Prioritize remediation for every asset, in every environment.

The role:

We are looking for an Information Security Manager to lead and enhance our internal security and compliance strategy. You will be responsible for improving our security posture, maintaining existing certifications such as SOC2, and obtaining PCI DSS and FedRAMP compliance. This role is crucial in ensuring that our security infrastructure meets the highest industry standards while fostering a strong security culture across the company.

In this role you will:

  • Develop and implement security and compliance strategies to align with industry best practices.

  • Maintain and enhance our SOC2 certification, ensuring continuous compliance with security controls.

  • Lead initiatives to achieve and maintain PCI DSS and FedRAMP compliance, including documentation, audits, and process improvements.

  • Oversee the company’s security infrastructure, including cloud security, endpoint protection, identity and access management (IAM), and incident response.

  • Conduct risk assessments, vulnerability management, and threat analysis to mitigate security risks proactively.

  • Lead the Security Operations Center (SOC) and collaborate with DevOps teams to ensure effective security monitoring and incident response.

  • Implement security awareness training programs to educate employees on best security practices.

  • Work with legal, compliance, and regulatory teams to ensure adherence to industry regulations.

  • Lead third-party security assessments and manage security relationships with vendors and partners.

  • Establish and track key security metrics to measure and improve security performance.

  • Stay up to date with emerging security threats, vulnerabilities, and regulatory requirements.

Requirements

Required qualifications:

  • 7+ years of experience in cybersecurity, risk management, and compliance.

  • Deep understanding of SOC2, PCI DSS, and/or FedRAMP compliance requirements.

  • Strong knowledge of cloud security (AWS, GCP, Azure), IAM, endpoint security, and network security principles.

  • Experience leading security audits, risk assessments, and vulnerability management programs.

  • Expertise in incident response, security monitoring, and threat intelligence.

  • Strong technical background in security engineering, DevSecOps, and security automation.

  • Excellent leadership, communication, and stakeholder management skills.

  • Ability to work cross-functionally with engineering, legal, compliance, and executive teams.

Preferred qualifications:

  • Hands-on experience with FedRAMP.

  • Experience working in high-growth tech startups or SaaS environments.

  • Hands-on experience with security tools and platforms such as SIEM, IDS/IPS, WAF, and endpoint security solutions.

  • Knowledge of API security, penetration testing, and security best practices for microservices.

  • Experience in developing and implementing security policies and governance frameworks.

What we offer:

  • Ability to work on a product that makes the Internet safer

  • Completely remote work and flexible working hours

  • Competitive salary and bonuses

  • Paid days off

  • Medical insurance

  • Working equipment

  • Professional development and career growth

Share this job:
Please let Wallarm. API & App Security Integrated know you found this job on Remote First Jobs 🙏

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service 🙏

Apply