Security Program Manager
Oneleet
| Company | Oneleet |
| Category | Security |
| Location | Beaverton |
| Remote | Remote |
| Employment | Not stated |
| Level | Manager |
| Salary | USD 75k–140k |
| Posted | 6 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
ABOUT ONELEET
Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.
Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.
WHO WE’RE LOOKING FOR:
We value passionate self-starters with a growth mindset and a bias for action and personal accountability. If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you’ll fit right in.
We’re especially drawn to:
- Rebels with a cause — frustrated with the status quo and eager to disrupt it.
- Opinionated (but not obstinate) builders — decisive yet collaborative, who help us move fast.
- Clear communicators — who own their ideas and follow through.
Our mission is simple: make effective cybersecurity painless. We believe cybersecurity should empower, not burden. This belief unites our team and drives every decision we make.
If you’re ready to challenge the status quo and help shape the future of cybersecurity, we’d love to meet you.
The Security Program Manager is part vCISO & part account manager. You will work with our customers from the start to assess their current security/compliance framework, provide guidance and recommendations for improvements, and work with clients to implement recommendations. You're passionate about security, and enjoy sharing your knowledge with not only our customers but your colleagues.
KEY RESPONSIBILITIES
- Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.
- Provide guidance and recommendations for improving client security posture
- Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.
- Collaborate with clients to customize and refine the security program to match their specific use cases.
- Communicate with clients and stakeholders to ensure smooth and efficient security program creation
- Liaise with auditors to ensure clients' security programs align with auditors' expectations
- Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.
- Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs.
- Be highly technical, learn new technologies quickly, and translate security concepts into implementations.
- Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.
REQUIREMENTS
SECURITY/COMPLIANCE EXPERIENCE
- 4+ years in a role involving information security, compliance, or audit (security operations, GRC, vCISO, security advisory, IT/Compliance auditing, or a security-adjacent customer success/IT support role). You’ll need to understand security and operations well enough that compliance becomes the natural byproduct of genuine security, not just checking boxes against the checklist. You should know why the box exists.
- Working and broad knowledge of security best practices, major compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI), and how controls map to real infrastructure and operations. Audit-side insight is particul
982,094 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →