Senior Information Security Manager

Auto Import

<meta><h5 style="font-family:" basel="" grotesk",arial,sans-serif;line-height:1.6;font-size:15pt;font-weight:600;letter-spacing:0px;margin-top:10px;margin-bottom:4px;padding-left:0px;"=""><b><strong style="white-space:pre-wrap;">About this opportunity</strong></b></h5><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><span style="font-size:11pt;white-space:pre-wrap;">The Senior Information Security Manager is a hands-on, high-impact role reporting to the SVP of Technology. You will own</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Kalkomey’s</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">security posture end-to-end, spanning application security, identity, compliance, incident response, and vendor risk. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><span style="font-size:11pt;white-space:pre-wrap;">This role is deeply embedded within engineering. You will partner directly with Product, Engineering, and Platform teams to build security into how software is developed and deployed, reviewing code, influencing architecture, and</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">ensuring security is built into how we ship. When security is done well, it makes delivery faster and more predictable. When something needs to stop, you stop it and own the call. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><span style="font-size:11pt;white-space:pre-wrap;">This is a player-coach role with a strong IC focus. We are looking for someone with deep hands-on experience who is ready to step into broader ownership, not someone who has moved away from</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">the work. You should be comfortable shipping code, working closely with engineers, and making pragmatic decisions that balance risk and velocity. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><span style="font-size:11pt;white-space:pre-wrap;">You will also play a key role in how we adopt and scale AI across the organization. This includes evaluating the security implications of AI-assisted development,</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">establishing</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">practical guardrails, and enabling teams to use AI tools effectively without introducing unnecessary risk. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><span style="font-size:11pt;white-space:pre-wrap;">This is a builder role in a maturing environment. You will shape how we approach security, design systems that scale through automation and self-service, and create clarity where processes are still evolving. If you are someone who enjoys operating close to</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">the work</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">while building for the future, this role will be a strong fit. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><br></p><p data-caption="true" style="line-height:1.38;font-family:" basel="" grotesk",arial,sans-serif;font-size:14pt;margin:0px="" 0px="" 20px;padding:0px;color:rgb(113,111,108);font-weight:400;"=""><b><strong style="white-space:pre-wrap;">You must reside in one of these US states</strong></b><span style="white-space:pre-wrap;">: AZ, CO, FL, GA, IL, IN, KY, MA, MD, MI, MN, NC, NV, OR, PA, RI, TX, VA, VT, WI, or one of these provinces in Canada: Ontario </span></p><h5 style="font-family:" basel="" grotesk",arial,sans-serif;line-height:1.6;font-size:15pt;font-weight:600;letter-spacing:0px;margin-top:10px;margin-bottom:4px;padding-left:0px;"=""><b><strong style="white-space:pre-wrap;">What you'll do:</strong></b></h5><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:13pt;white-space:pre-wrap;">Security Ownership and Accountability</strong></b><span style="color:rgb(46,64,87);font-size:13pt;white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Serve as the single-threaded owner of</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Kalkomey’s</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">security posture. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:10.5pt;white-space:pre-wrap;">Establish and enforce practical security standards that empower teams to move quickly and securely, with clear guidance on when risk-based tradeoffs require</span><span style="white-space:pre-wrap;"> </span><span style="font-size:10.5pt;white-space:pre-wrap;">additional</span><span style="white-space:pre-wrap;"> </span><span style="font-size:10.5pt;white-space:pre-wrap;">scrutiny.</span><span style="color:rgb(36,36,36);font-size:10.5pt;white-space:pre-wrap;"> </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Escalate material risks clearly and early to executive leadership. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Lead incident response with authority and composure. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own quarterly security reporting to the executive team and board. </span></li></ul><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:13pt;white-space:pre-wrap;">Embedded Engineering Partnership</strong></b><span style="color:rgb(46,64,87);font-size:13pt;white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Work directly inside the engineering development process:</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">attend engineering leadership meetings and architecture reviews,</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">review PRs for security concerns, and block releases when</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">warranted. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Instill a defensive security mindset across the engineering team. That means walking engineers through real attack vectors in their own code, threat modeling with the team, and</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">demonstrating</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">how an attacker would get in. Coaching through showing, not through policy decks. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own static code analysis, dependency scanning (Dependabot), and security-focused CI/CD pipeline integration. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Understand containerized and ephemeral deployment patterns. Calibrate security controls to the actual architecture, not theoretical enterprise frameworks. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Partner closely with the Director of Platform Engineering. Cloud infrastructure architecture is his domain; security posture of that infrastructure is yours. This is a partnership, not a boundary. </span></li></ul><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:13pt;white-space:pre-wrap;">Endpoint and Identity Security</strong></b><span style="color:rgb(46,64,87);font-size:13pt;white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own endpoint security tooling (EDR, device control, monitoring) and evaluate the current stack for friction-to-value ratio. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Oversee MDM, device compliance, and identity access controls. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Ensure</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">timely</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">vulnerability</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">remediation and patch management. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own the security posture of onboarding/offboarding processes. </span></li></ul><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:13pt;white-space:pre-wrap;">Risk, Compliance, and Audit</strong></b><span style="color:rgb(46,64,87);font-size:13pt;white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own SOC 2 program operations, ongoing audit readiness, and remediation tracking. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own the compliance tooling stack (Drata,</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Safebase) and</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">maintain</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">audit evidence. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Lead third-party vendor security reviews and contract security assessments, including evaluating vendors for state contract compliance. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Maintain a current risk register with prioritized mitigation plans. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Coordinate annual penetration testing and remediation. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own state contract security requirements: SAM.gov registration, data residency, and agency-specific security</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">asks. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Produce quarterly</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">boz`ard-ready security and compliance reporting. </span></li></ul><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:13pt;white-space:pre-wrap;">Incident Response and Monitoring</strong></b><span style="color:rgb(46,64,87);font-size:13pt;white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own incident response plan and execution. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Ensure monitoring coverage across endpoints, identity systems, and cloud infrastructure. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Conduct post-incident reviews with corrective action plans. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Validate readiness through tabletop exercises. </span></li></ul><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:13pt;white-space:pre-wrap;">AI Security and Enablement</strong></b><span style="color:rgb(46,64,87);font-size:13pt;white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Evaluate security implications of AI coding agents, LLM-powered workflows, and agentic tool use across the organization. Understand how context windows, tool access, and agent autonomy create new attack surfaces. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Set and</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">maintain</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">AI/LLM usage policy and data boundaries. Define what goes into a prompt and what stays out. Make the policy short, clear, and enforceable. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Use</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">AI</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">yourself. Apply disciplined agent workflows (research, plan, implement) to your own security and compliance work, including offensive security: reconnaissance, vulnerability scanning, pen test preparation.</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Model what good AI usage looks like in practice, not just in policy. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Stay current on AI security risks: prompt injection, data exfiltration, context poisoning, supply chain risks from AI-generated code, and the evolving threat landscape around agentic systems. </span></li></ul><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:13pt;white-space:pre-wrap;">Operational Leverage and Self-Service Enablement</strong></b><span style="color:rgb(46,64,87);font-size:13pt;white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Own the Rippling IT relationship end-to-end. Maximize its capabilities for endpoint management, MDM, onboarding/offboarding, and device</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">compliance</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">so these functions run on automation, not headcount. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Build AI-powered self-service tools (Slack chatbots, automated triage, knowledge bases) that resolve common IT requests without human intervention. Design the system so most issues never reach you. Handle tier 1/2/3 support when needed, but that should be the exception, not the operating model. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Use AI agents to automate repetitive security and IT tasks: vendor assessment prep, compliance evidence collection, runbook generation, ticket triage. Build workflows, not queues. The goal is a function that scales through tooling and engineering discipline, not through adding people. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Maintain concise documentation and runbooks. Documentation is a deliverable, not a side project. </span></li></ul><h5 style="font-family:" basel="" grotesk",arial,sans-serif;line-height:1.6;font-size:15pt;font-weight:600;letter-spacing:0px;margin-top:10px;margin-bottom:4px;padding-left:0px;"=""><b><strong style="white-space:pre-wrap;">What you'll need:</strong></b></h5><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">5-8 years in information security, application security, or security engineering roles. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Experience owning security operations in a SaaS or cloud-based product company, not just consulting or compliance. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Hands-on experience with EDR, IAM, vulnerability management, incident response, and penetration testing coordination. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Demonstrated experience working embedded with engineering teams: PR reviews, CI/CD security integration, shift-left practices. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">You have written</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">production</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">code. Not as a hobby. You have shipped software in a team environment and can read a codebase, trace a vulnerability through it, and explain the fix to the engineer who owns it. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Familiarity with SOC 2, NIST, CIS, or ISO frameworks in a practitioner capacity, not just an auditor capacity. Current on the modern engineering security toolchain: dependency scanning, SAST/DAST, container security,</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">secrets</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">management. You should already know what</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Dependabot</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">is and why it matters. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Hands-on experience using AI coding agents and LLM-powered workflows in your own work. You do not need to be a prompt engineer, but you need to have shipped real work with these tools and formed your own opinions about context management, agent reliability, and security implications. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">A clear-eyed perspective on security in a product engineering environment: comfortable enforcing standards and equally comfortable recognizing when a control creates more friction than the risk it mitigates. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Ability to partner effectively across teams without direct authority. Influence through technical credibility and clear communication. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Strong written and verbal communication skills.</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Comfortable briefing an executive, coaching an engineer, and writing a vendor risk assessment with equal clarity. </span></li></ul><p data-caption="true" style="line-height:1.38;font-family:" basel="" grotesk",arial,sans-serif;font-size:14pt;margin:0px="" 0px="" 20px;padding:0px;color:rgb(113,111,108);font-weight:400;text-align:left;"=""><b><strong style="white-space:pre-wrap;">Bonus Points</strong></b><span style="color:rgb(46,64,87);white-space:pre-wrap;"> </span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Experience with state or government contract compliance requirements: data residency, SAM.gov, agency security assessments. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Experience managing or</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">optimizing</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">an MSP/Rippling IT relationship. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Background in Ruby on Rails application security or familiarity with Rails-specific vulnerability patterns. </span></li></ul><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="font-size:11pt;white-space:pre-wrap;">Genuine interest in hunting, fishing, boating, or other outdoor sports and activities. </span></li></ul><h5 style="font-family:" basel="" grotesk",arial,sans-serif;line-height:1.6;font-size:15pt;font-weight:600;letter-spacing:0px;margin-top:10px;margin-bottom:4px;padding-left:0px;"=""><b><strong style="white-space:pre-wrap;">Competencies</strong></b></h5><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Security Ownership &</strong></b><span style="white-space:pre-wrap;"> </span><b><strong style="font-size:11pt;white-space:pre-wrap;">Accountability:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Owns the company’s security posture end-to-end. Establishes standards, manages risk, and ensures security outcomes align with business needs. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Engineering</strong></b><span style="white-space:pre-wrap;"> </span><b><strong style="font-size:11pt;white-space:pre-wrap;">Partnership:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Works directly with engineering teams to embed security into development workflows. Reviews code, influences architecture, and drives shift-left practices. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Execution & Delivery:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Delivers security initiatives with speed and precision. Balances risk, velocity, and practicality to support continuous delivery. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Technical Judgment:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Applies strong judgment to security decisions, balancing real-world risk with business impact. Avoids over-engineering while</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">maintaining</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">effective controls. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">AI Fluency & Security Application:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Leverages AI tools to improve workflows, automate tasks, and scale operations. Evaluates risks of AI usage and</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">establishes</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">practical, enforceable guidelines. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Operational Excellence & Automation:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Builds scalable systems, automation, and self-service models that reduce manual work.</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Designs</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">processes that scale without adding headcount. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Incident Response & Risk</strong></b><span style="white-space:pre-wrap;"> </span><b><strong style="font-size:11pt;white-space:pre-wrap;">Management:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Leads incident response with clarity and urgency.</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Identifies</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">risks early and ensures effective mitigation strategies are in place. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Cross-Functional</strong></b><span style="white-space:pre-wrap;"> </span><b><strong style="font-size:11pt;white-space:pre-wrap;">Collaboration:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Partners across Product, Engineering, Platform, and leadership teams to drive alignment and execution. Influences without relying on authority. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Communication:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Communicates risks, tradeoffs, and decisions clearly to both technical and non-technical audiences. Provides executive-level visibility when needed. </span></p><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;text-align:left;"=""><b><strong style="font-size:11pt;white-space:pre-wrap;">Ownership & Initiative:</strong></b><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">Takes full ownership of outcomes and proactively drives improvements. Operates independently while</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">maintaining</span><span style="white-space:pre-wrap;"> </span><span style="font-size:11pt;white-space:pre-wrap;">alignment with leadership. </span></p><h5 style="font-family:" basel="" grotesk",arial,sans-serif;line-height:1.6;font-size:15pt;font-weight:600;letter-spacing:0px;margin-top:10px;margin-bottom:4px;padding-left:0px;"=""><b><strong style="white-space:pre-wrap;">What we offer:</strong></b></h5><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;"=""><span style="white-space:pre-wrap;">In addition to a competitive salary and annual bonus, we offer these great benefits:</span></p><ul data-pattern="discCircleSquare" data-depth="1" style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;margin:8px="" 0px;line-height:1.6;padding:0px="" 0px="" 32px;list-style-type:disc;"=""><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">We are a fully distributed company – unless specifically indicated in the job description, this is a work from home position </span></li><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">Employer matched 401(k)   </span></li><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">Medical/Dental/Vision insurance with generous employer contributions (including HSA)   </span></li><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">Maternity and Paternity leave and benefits   </span></li><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">Three weeks of paid vacation, 12 paid holidays, a paid community service day, and a flexible work schedule   </span></li><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">Annual wellness allowance, as well as a paid mental health day once a year for when you need it   </span></li><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">Automatic WFH contribution to each paycheck   </span></li><li style="font-size:11pt;margin:3px 0px;letter-spacing:0.25px;line-height:1.6;"><span style="white-space:pre-wrap;">Employee Assistance Program (EAP)   </span></li></ul><p style="font-family:" basel="" grotesk",arial,sans-serif;font-size:11pt;font-weight:400;line-height:1.6;letter-spacing:0.25px;margin:4px="" 0px;padding:0px;"=""><span style="white-space:pre-wrap;">Kalkomey is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Kalkomey is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email pops@kalkomey.com</span></p>

Back to blog