- Salary
- $120k – $220k
- Location
- Remote
- Workplace
- Remote
- Department
- Product
- Seniority
- Lead
- Source
- Greenhouse
Description
Flodesk is one of the world’s fastest-growing email marketing companies, built to help creators sell online and design emails that people love to get. Our commitment to small business owners is to create simple and intuitive tools that help them grow, nurture, and monetize their email list.
We’re a remote-first company headquartered in San Francisco, California, with a globally distributed team—including an in-person office in Da Nang, Vietnam and Menlo Park. Our team reflects the diversity and creativity of the people we serve. Join our mission to level the playing field for small business owners through good design.
About the role
You'll own Flodesk's security program end to end: the frameworks, controls, and governance that define our long-term security posture. Reporting to the COO/CPO, this is a hands-on, build-it-yourself role that drives SOC 2, ISO 27001 and CCPA auditing readiness, embedding security into how engineering ships product, and keeping day-to-day IT and vendor operations running. You'll write the policies, run point on audits, partner with engineering on the technical foundations — all while setting the strategic direction for where security goes next and representing it confidently, internally and externally.
What you'll do:
Security program ownership [40%]
- Own Flodesk's security program: policies, controls, governance, and long-term maturity planning
- Collaborate cross-functionally to build security into product, operational, and technology decisions
- Maintain and update - privacy-related security practices across data handling, retention, and customer commitments
- Lead SOC 2, ISO 27001 and CCPA readiness, including audits, evidence collection, and continuous compliance
Security implementation & compliance support [40%]
- Partner with engineering to integrate security into architecture, development workflows, and release processes, and to build and maintain security foundations across cloud infrastructure, applications, data, and internal systems
- Evaluate, implement, and maintain security tooling and automation to scale the program
- Own Security Incident Management end to end: process, technical capability, and cross-company engagement
- Design, implement, and continuously improve controls
- Track and report on security posture, program maturity, and compliance status
- Defend Flodesk's SaaS platform and its customers by introducing protective mechanisms and security capabilities
IT support & operations [10%]
- Own the lifecycle of company hardware from procurement to retirement
- Be the first point of contact for IT issues: hardware, software, network connectivity
- Run new-hire setup (accounts, device provisioning) and secure access revocation for leavers. Manage domain registrations, DNS, and general IT housekeeping
Software & vendor operations [10%]
- Vet new tools before purchase, checking for SSO, 2FA, and integration capabilities
- Maintain a central registry of approved software so the org stays on authorized tools
What you bring:
- 10+ years in information security, with a track record of building or maturing security programs
- 3+ years in an information security leadership role
- Strong foundation in cloud security, identity governance, vulnerability management, and incident response
- Proven experience aligning security and privacy practices with GDPR
- Comfortable partnering directly with engineering on product security and secure development practices
- Clear, confident communicator with technical and non-technical stakeholders alike
- Startup DNA: a can-do attitude, flexibility, and the willingness to occasionally roll up your sleeves on the basics, given our startup mindset
- Willing to travel on a semiannual basis
Extra points if you have:
- Experience securing SaaS products
- Experience implementing SOC 2, ISO 27001/2, or similar security/compliance frameworks
- Background in reliability, DevOps, or application architecture
- Conversational (or better) Vietnamese
What we bring:
- $120,000–$220,000 base salary, depending on your location and experience. We prefer to hire near our Menlo Park hub for in-person collaboration with the COO/CPO. Residents in Seattle & San Francisco Bay Area: $160,000–$220,000; all other locations $120,000–$180,000.
- Fully paid health insurance for individual coverage
- 16 weeks paid parental leave for non-birthing parents; 22 weeks paid maternity leave for birthing parents
- Unlimited flexible time off
- 401k match (US employees only)
- $1,000 annual stipend for learning and development