Information Security Specialist

Remote $151k–$170k middle 4 months ago full-time quality 8.6/10

Role in brief

peoplefirstjobs.com is hiring its first dedicated Information Security Specialist to manage AI governance, vulnerability management, and incident response. This role involves improving compliance and overall security posture. Candidates with experience in information security, compliance frameworks like SOC 2 and ISO 27001, and cloud security fundamentals should apply.

information securitycybersecurityAI governancevulnerability managementcomplianceincident responsesecurity toolingvendor risk assessmentcloud securitycommunication

About the role

This role is for an Information Security Specialist, serving as the first dedicated InfoSec hire for the organization. The primary responsibilities include developing and maintaining an AI governance framework, overseeing vulnerability management from scanning to remediation, and leading incident response efforts. The specialist will also manage and fine-tune security tools such as EDR, SIEM, and DLP.

The position involves supporting and enhancing the company's compliance posture, specifically with SOC 2 and ISO 27001, through evidence collection and audit support. A key part of the role is conducting security reviews for third-party vendors and SaaS integrations, evaluating data handling and privacy commitments. Success in this role means establishing robust security policies, standards, and runbooks that are practical for the environment.

Additionally, the Information Security Specialist will partner with Platform Security and Engineering on application security topics and drive security awareness initiatives, including phishing simulations and AI literacy education. Monitoring and assessing emerging threats, including AI-driven attack vectors, is also a core responsibility for this remote position.

The starting salary for this role ranges from $151,000 to $170,000, depending on experience.

Skills that matter here

  • AI governance: This role will develop and maintain a framework for securely deploying AI tools.
  • vulnerability management: The specialist will own the vulnerability management program, including scanning, triaging, and remediation.
  • compliance: The role involves supporting and improving compliance with frameworks like SOC 2 and ISO 27001.
  • incident response: The specialist will lead security incident response, from investigation to root cause analysis.
  • security tooling: This position requires managing and tuning various security tools such as EDR, SIEM, and DLP.
  • vendor risk assessment: The role includes conducting security reviews of third-party vendors and SaaS integrations.

Who this role suits

  • You have at least four years of experience in information security or a related technical field.
  • You approach AI with a pragmatic and enabling mindset.
  • You are a self-starter comfortable with remote-first operations and SaaS environments.
  • You possess strong written communication skills and experience with compliance frameworks.

From the employer

What you’ll do

  • AI Governance & Enablement — Develop and maintain a practical framework for evaluating, approving, and securely deploying AI tools across the organization.
  • Vulnerability Management — Own our vulnerability management program — scanning, triaging, coordinating remediation, and tracking resolution across infrastructure, applications, and endpoints.
  • Compliance — Support and improve our compliance posture (SOC 2, ISO 27001), including evidence collection, control monitoring, and audit support.
  • Incident Response — Lead security incident response — investigate alerts, coordinate containment, document root causes, and drive improvements.
  • Security Tooling — Manage and tune security tooling (EDR, SIEM/logging, DLP, email security, identity and access management controls).
  • Vendor & Third-Party Risk — Conduct security reviews of third-party vendors, SaaS integrations, and AI services — evaluating data handling, model training policies, and privacy commitments.
  • Policy & Standards — Develop and maintain security policies, standards, and runbooks that are practical and right-sized for our environment.
  • Application Security Partnership — Partner with Platform Security and Engineering on application security topics.
  • Security Awareness — Drive security awareness initiatives — phishing simulations, training programs, AI literacy education, and ongoing guidance for the team.
  • Threat Intelligence — Monitor and assess emerging threats (including AI-driven attack vectors).

Who you are

  • 4+ years of experience in information security, cybersecurity, or a related technical discipline.
  • A pragmatic, enabling mindset toward AI.
  • Hands-on experience with compliance frameworks (SOC 2, ISO 27001).
  • Strong knowledge of cloud security fundamentals (AWS, GCP, or similar).
  • Experience with security tooling — EDR, SIEM, vulnerability scanners, DLP, and email security platforms.
  • Solid understanding of incident response processes.
  • Familiarity with SaaS environments and remote-first operations.
  • Strong written communication skills.
  • Self-starter mentality.
  • Experience evaluating AI/ML tools for data privacy and security risks is a strong plus.
  • Experience in vendor risk assessment and third-party security reviews.
  • Security certifications (CISSP, CISM, CompTIA Security+, or similar) are a plus but not required.

What you'll get

  • Compensation & Benefits: Starting salary for this role is $151,000 to $170,000 depending on experience.
  • Inclusive benefits package supports your well-being and growth, including 100% coverage of medical, dental, vision, mental health, and supplemental insurance premiums for you and your family.
  • 16 weeks paid parental leave.
  • Unlimited PTO.
  • Stipends for remote work and wellness.
  • Professional development budget.

Questions about this role

What is the remote work policy for this role?

This is a fully remote position.

What is the seniority level for this position?

This is a middle-seniority role.

What are the key compliance frameworks this role will work with?

The role requires hands-on experience with SOC 2 and ISO 27001 compliance frameworks.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to peoplefirstjobs.com.