Lead Flodesk's end-to-end security program, focusing on frameworks, controls, and governance. Drive SOC 2, ISO 27001, and CCPA readiness, embedding security into engineering and IT operations. Requires 10+ years of experience, strong cloud security, and leadership skills.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Flodesk is one of the world’s fastest-growing email marketing companies, built to help creators sell online and design emails that people love to get. Our commitment to small business owners is to create simple and intuitive tools that help them grow, nurture, and monetize their email list.
We’re a remote-first company headquartered in San Francisco, California, with a globally distributed team—including an in-person office in Da Nang, Vietnam. Our team reflects the diversity and creativity of the people we serve. Join our mission to level the playing field for small business owners through good design
About the role
You'll own Flodesk's security program end to end: the frameworks, controls, and governance that define our long-term security posture. Reporting to the COO/CPO, this is a hands-on, build-it-yourself role that drives SOC 2, ISO 27001 and CCPA auditing readiness, embedding security into how engineering ships product, and keeping day-to-day IT and vendor operations running. You'll write the policies, run point on audits, partner with engineering on the technical foundations — all while setting the strategic direction for where security goes next and representing it confidently, internally and externally.
What you'll do:
Security program ownership [40%]
- Own Flodesk's security program: policies, controls, governance, and long-term maturity planning
- Collaborate cross-functionally to build security into product, operational, and technology decisions
- Maintain and update - privacy-related security practices across data handling, retention, and customer commitments
- Lead SOC 2, ISO 27001 and CCPA readiness, including audits, evidence collection, and continuous compliance
- Partner with engineering to integrate security into architecture, development workflows, and release processes, and to build and maintain security foundations across cloud infrastructure, applications, data, and internal systems
- Evaluate, implement, and maintain security tooling and automation to scale the program
- Own Security Incident Management end to end: process, technical capability, and cross-company engagement
- Design, implement, and continuously improve controls
- Track and report on security posture, program maturity, and compliance status
- Defend Flodesk's SaaS platform and its customers by introducing protective mechanisms and security capabilities
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
- Own the lifecycle of company hardware from procurement to retirement
- Be the first point of contact for IT issues: hardware, software, network connectivity
- Run new-hire setup (accounts, device provisioning) and secure access revocation for leavers. Manage domain registrations, DNS, and general IT housekeeping
- Vet new tools before purchase, checking for SSO, 2FA, and integration capabilities
- Maintain a central registry of approved software so the org stays on authorized tools
- 10+ years in information security, with a track record of building or maturing security programs
- 3+ years in an information security leadership role
- Strong foundation in cloud security, identity governance, vulnerability management, and incident response
- Proven experience aligning security and privacy practices with GDPR
- Comfortable partnering directly with engineering on product security and secure development practices
- Clear, confident communicator with technical and non-technical stakeholders alike
- Startup DNA: a can-do attitude, flexibility, and the willingness to occasionally roll up your sleeves on the basics, given our startup mindset
- Willing to travel on a semiannual basis
- Experience securing SaaS products
- Experience implementing SOC 2, ISO 27001/2, or similar security/compliance frameworks
- Background in reliability, DevOps, or application architecture
- Conversational (or better) Vietnamese
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
- $120,000–$220,000 base salary, depending on your location and experience. We prefer to hire near our Menlo Park hub for in-person collaboration with the COO/CPO. Residents in Seattle & San Francisco Bay Area: $160,000–$220,000; all other locations $120,000–$180,000.
- Fully paid health insurance for individual coverage
- 16 weeks paid parental leave for non-birthing parents; 22 weeks paid maternity leave for birthing parents
- Unlimited flexible time off
- 401k match (US employees only)
- $1,000 annual stipend for learning and development
Notice to California-based Candidates and Vietnam-based Candidates for Employment. This Candidate Privacy Notice is intended to provide information about how Flodesk collects and uses personal information to California consumers and candidates located in Vietnam (Vietnam-based candidates) who apply for employment with Flodesk. If you are employed by Flodesk, refer to the Employee Handbook for additional information. For any questions about this notice, please contact People@flodesk.com.
Personal Information Flodesk Collects:
Identifiers Including name, address, email, telephone number, social security number, driver license number, passport number, and other personal identifying information. For California-based candidates: Characteristics of protected classifications under California or federal law including demographic information and other personal information obtained during the application process, such as gender, race, national origin. Professional or employment-related information, such as salary/compensation and benefits packages, other relocation or job preferences, prior background, experience, skills, and other information in support of your application, reference information. Any other information you provide as a part of recruitment, job application, or interview process.
Purposes for Collecting Personal Information:
To consider qualifications, skills, and interest for employment. To communicate with you during the recruitment and interview process. To provide compensation, including payroll, and administer stock options and benefits, including medical, dental, vision, commuter, and retirement benefits. To provide human resources services and conduct performance evaluations. To monitor work eligibility including work-related licenses, credentials, training, and eligibility to work in the United States or in Vietnam. To improve recruitment and interview processes and ensure a safe and efficient working environment. To comply with applicable legal or regulatory requirements as Flodesk may transfer or store internationally your information, including to or in the United States, European Union and Vietnam and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.
For Vietnam-based candidates:
By clicking "Submit Application", You confirm that you have read the Privacy Notice and agree to allow Flodesk to process your personal data for this application, including cross-border transfer. You have the right to withdraw your consent or request data deletion at any time by contacting people@flodesk.com
Similar Jobs
Explore other opportunities that match your interests