Vice President, Infrastructure and Security
floatme · Austin
Job description
About the role
FloatMe is looking for a Vice President, Infrastructure and Security to own and elevate its infrastructure strategy and security program. This senior, hands‑on position is ideal for a security leader who wants to grow toward a CISO role while actively configuring security tooling and guiding compliance.
Key responsibilities
- Steer the architecture of cloud, device, code, application, AI, and network infrastructure with a security‑first mindset.
- Set direction for infrastructure design, security integrations, and partnership architectures across IT, data, and security teams.
- Serve as the primary security contact for bank and fintech partners, handling questionnaires, third‑party risk assessments, and due‑diligence requests.
- Own the end‑to‑end SOC 2 Type II program, including scoping, control design, evidence collection, and auditor management.
- Maintain compliance with GLBA, PCI DSS, and other financial‑services regulatory frameworks.
- Manage core security tools such as SIEM, EDR, WAF, IAM, secrets management, and vulnerability scanning solutions.
- Oversee regular penetration testing, vulnerability assessments, and drive remediation to closure.
- Lead incident‑response activities, including triage, containment, forensics, post‑incident review, and breach notifications.
- Build and run security awareness training and phishing simulation programs.
- Partner with product, engineering, finance, and legal to embed security into all deliverables.
- Develop and maintain a multi‑year security roadmap and report risk posture to executive leadership.
Required profile
- Hands‑on security leader who can switch between tactical execution and strategic planning.
- Owner‑mindset with a drive to deliver results without relying solely on policy management.
- Strong communication skills to interact with internal teams and external partners.
- Experience in fast‑moving fintech or similar regulated environments.
Required skills
- Cloud infrastructure design and management.
- Device, code, application, AI, and network security.
- SOC 2 Type II compliance.
- GLBA and PCI DSS regulatory knowledge.
- SIEM, EDR, WAF, IAM, secrets management, and vulnerability scanning tools.
- Penetration testing and vulnerability assessment.
- Incident response, forensics, and breach notification processes.
- Security awareness training and phishing simulation.
- Third‑party risk assessment and security questionnaire handling.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 3 weeks ago
Expires 1 month from now
23 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
floatme
Austin