Hiring.Camp

Head of Security and IT

Cardlytics

·

Yesterday

Location
CO Remote, United States of America
Workplace
Remote
Type
Full-time
Department
Security
Source
Workday

Description

About Cardlytics
Founded in 2008, Cardlytics (NASDAQ: CDLX) is the industry-leading purchase intelligence and incentives platform. We make commerce smarter and more rewarding for everyone by helping businesses attract, understand, and incentivize consumers through our partners' digital reward programs. Join us on our mission to make commerce smarter and more rewarding for everyone!

About the Position

Cardlytics is looking for a Head of Security & IT to lead the team responsible for protecting and operating the technology that runs our business. This is a hands-on leadership role: you will set strategy and represent the program to executives, our board, and bank partners like Chase and Wells Fargo, while staying close enough to the work to step in when needed. You will lead a team of five covering security engineering, IT engineering, network engineering, security compliance, and end-user support, our identity and access management program, and the resilience of our AWS-hosted production environment.

Cardlytics is subject to strict compliance oversight from public-company (SOX) requirements and publishing partners (including major financial institutions). This role exists to make sure security and IT are never the reason the business slows down — and increasingly, to make sure the company is using AI to work faster and smarter.

You'll have real executive visibility — direct partnership with the CTO, exposure to the board, and a seat at the table on how Cardlytics adopts AI company-wide. It's a lean, high-trust team where your judgment matters more than process for process's sake, and where leadership is actively investing in modernizing how the function operates.

You Will:

  • Security & Compliance Leadership — own the SOX/SOC 2 control environment for engineering and GUARD (our internal security/compliance program); serve as the primary point of contact for external auditors, internal audit, and third-party risk assessments from bank partners.

  • Identity & Access Management — oversee and improve the identity and access management program across Google Workspace, Okta, and ConductorOne; ensure least-privilege access is enforced and evidenced for audit.

  • Cloud & Product Security — maintain the cloud security baseline across our 100% AWS production environment (EKS, Lambda, Terraform, GitHub Actions); partner with Engineering to triage and remediate findings surfaced through Wiz and Expel (our MDR provider covering CloudTrail, GuardDuty, Wiz Defend, SentinelOne, and Databricks).

  • Company-Wide AI Enablement — act as an internal champion for AI adoption beyond engineering — helping non-technical teams identify safe, effective use cases, and modeling how the security/IT function itself uses AI to move faster (e.g., in compliance evidence-gathering, access reviews, and incident response).

  • IT Operations — ensure reliable, secure device management for a hybrid Windows/macOS remote workforce, a healthy BYOD mobile posture, and responsive IT help desk support company-wide.

  • Certificate & Infrastructure Hygiene — ensure SSL/TLS certificate renewal, network resilience, and general network hygiene practices are proactive, not reactive.

  • Team Leadership — manage and develop a 5-person team; set priorities, review work, and be capable of personally covering any team function during absences.

  • Executive Partnership — work closely with the CTO to align security/IT priorities with business strategy; communicate risk and program status clearly to non-technical executives and the board.

You Have:

  • 8+ years in security and/or IT leadership, including 3+ years managing a team directly.

  • Deep, hands-on background in at least two of: security engineering, security architecture, identity & access management, or vulnerability management — you can read technical output and challenge it, even if you're not writing production code day to day.

  • Direct experience owning or heavily supporting SOX and/or SOC 2 compliance programs, including working with external auditors.

  • Experience with modern IAM tooling (Okta, Google Workspace, or similar) and cloud security platforms (Wiz or comparable CNAPP/CSPM).

  • Comfort operating in a fully remote, lean-team environment where you'll rely upon managed/third-party providers rather than building everything in-house.

  • Working knowledge of AWS and IaC concepts (Terraform) sufficient to have informed conversations with engineering — you don't need to write it yourself.

  •  Executive-level communication skills: able to translate technical risk into business terms for a CTO, board, and bank auditors.

  • Genuine enthusiasm for applying AI tools to security, IT, and compliance workflows — and for helping non-technical teams do the same.

  • Experience in fintech, adtech, or another environment with heavy third-party/bank compliance scrutiny— valued, not required.

  • Familiarity with Databricks, EKS, or MDR/managed-SOC relationships (e.g., Expel or similar)— valued, not required..

  • A security or compliance certification (CISSP, CISM, or equivalent) — valued, not required. 

Technical Environment

We primarily use macOS and Google Workspace (Docs, Sheets, Slides). While our preferred platform is macOS, we support both macOS and Windows. Familiarity with or willingness to work within this environment is required.

Core Values

Our shared values are the driving force behind everything we do. Across all roles, we are looking for teammates who embody these values:

  • Customer and partner first

  • Act with urgency and focus

  • Integrity with our partners and data

  • Accountability even when challenged

  • Empowerment over hierarchy

  • Growth over comfort

Benefits and Perks

  • Flexible paid time off plus company holidays

  • Medical, dental, and vision insurance begins on your first day

  • 401(k) retirement plan with company match, plan also includes a student loan debt repayment option

  • Employee Stock Purchase Plan

  • Educational assistance for continuing education

  • Lifestyle Spending Account for physical, emotional, and financial wellness (like gym memberships, home down payments, art classes, park passes, and more!)

  • Complimentary Calm app subscriptions to support employee mental health and wellbeing

As an equal opportunity employer, Cardlytics is committed to diversity, equity, and inclusion. Our people bring our products and organization to life, and every unique perspective makes us better. If you can do the job and you’re excited about growing with us as we scale our best-in-class advertising platform, we’d love to hear from you. If you need accommodation in the recruiting process due to a disability, please email [email protected] or inform your recruiter.

Skills

AWSTerraformDatabricksGitHubSOCSOXComplianceSOC 2CISSP

Similar Jobs

30

Head of Security

Brinks · Brussels Head Office, Belgium

3 days ago

Head of Security

RevenueCat · Remote

5 days ago

Head of Security

Tremendous · United States +1 · Remote

1 week ago

Head of Security

Profound · New York, New York · Onsite

1 week ago

Head of Security

Pivotal Health · Santa Monica, CA +2 · Hybrid

3 weeks ago

Head of Security

Kontigo · San Francisco, California, US · Remote

1 month ago

Head of Security

Tatari · San Francisco, California, United States +2

2 months ago

Head of Security

Tatari · New York, New York, United States +2

2 months ago

Head of Security

Tatari · Los Angeles, California, United States +2

2 months ago

Head of Security

Revenuecat · Americas +1 · Remote

2 months ago

Head of Security

Edenpeople · United Kingdom - Swindon - Station Square (PPS)

3 months ago

Head of Security

Defuse Labs · Global - Remote · Remote

3 months ago

Head of Security

Fresha · London · Onsite

3 months ago

Head of Security

Stedi · USA · Remote

3 months ago

Head of Security

Protege · Remote · Remote

3 months ago

Head of Security Team - NEW

Deutsche Telekom IT Solutions · Budapest, Hungary · Remote

Yesterday

Head of Security Engineering (DevSecOps & CISO)

Smarkets · London · Hybrid

4 days ago

Head of Security & Infrastructure

Parker Bridge · Hybrid

1 week ago

Head of Security Assurance.Information Security Group-ISG

Mashreq · Bengaluru, Karnataka, India · Remote

1 week ago

Head Of Security - Base44

Wix.com · Tel Aviv, Israel

1 week ago

Head of Security Architecture and Assurance, Charles River Development, Vice Presdient

Statestreet · Dublin 2, Ireland

2 weeks ago

Global Head of Security Detection and Response

Ing · Madrid (Hubs Spain)

2 weeks ago

Head of Security GRC

DriveWealth · AMER-US-Remote; Austin, Texas, United States; Dallas, Texas, United States; Denver, Colorado, United States; Miami, Florida, United States; San Francisco, California, United States; Seattle, Washington, United States · Remote

3 weeks ago

Head of Security Engineering

January · New York City · Hybrid

3 weeks ago

Head of Security & AI Governance

Flip · Los Angeles +1 · Onsite

3 weeks ago

Head of Security & Compliance

Aerospike · Mountain View, CA +1 · Remote, Hybrid

1 month ago

SVP, Head of Security Technology

Berkley · Wilmington, DE, US

1 month ago

Head of Security & Compliance

Casca · San Francisco, US

1 month ago

Head of Security & Compliance

Casca · San Francisco · Onsite

1 month ago

Head of Security Engineering

Harvey · New York · Hybrid

1 month ago