Posted 5d ago

Information Security Officer

@ UniUni
United States or Canada
RemoteFull Time
Responsibilities:lead security, build program, manage compliance
Requirements Summary:Lead security program across cloud, data, and governance; ensure ISO 27001 and SOC 2 Type II; hands-on security leadership in a cloud-native environment.
Technical Tools Mentioned:AWS, IAM, GuardDuty, Security Hub, CloudTrail, Config, SAML 2.0, OpenID Connect, MFA, SSO, SAST, DAST, SCA, secrets scanning, EDR, Intune, SLA, ISO 27001, SOC 2
Save
Mark Applied
Hide Job
Report & Hide
Job Description

Role Snapshot

Reports to: Chief Technology & Product Officer (CTPO)

Location: North America (remote with periodic travel to UniUni hubs)

Scope: Worldwide operations with focus on North America


The Role

We are hiring an Information Security Officer to lead UniUni's security and governance function end to end. This is a hands-on leadership role reporting directly to the CTPO. You will own the security program across cloud infrastructure, application security, data security and governance, corporate IT, compliance, and risk, and you will be the senior accountable owner for our ISO 27001 certification and SOC 2 Type II attestation.


You will work closely with engineering, platform, IT, legal, and executive leadership, and you will be UniUni's primary security voice in front of customers, auditors, and investors. You will build and lead a small, high-leverage team and set the bar for how security operates as the business scales.


Key Responsibilities


Cloud Security

Set the security posture of our AWS environments, including IAM, network segmentation, encryption, logging, secrets management, and workload protection.

Drive cloud security baselines aligned to CIS Benchmarks and the AWS Well-Architected Security Pillar, and enforce them through infrastructure as code and platform guardrails.

Lead continuous monitoring and threat detection across cloud workloads using native AWS services (GuardDuty, Security Hub, CloudTrail, Config) and complementary third-party tooling.

Run vulnerability management for cloud infrastructure, including patching cadence, remediation SLAs, and exception governance.


Application Security

Embed secure development practices into the SDLC, including threat modeling, secure code review, SAST, DAST, SCA, and secrets scanning in CI/CD.

Partner with engineering leaders to triage and remediate application vulnerabilities without slowing delivery.

Run the open source software program, including license compliance, vulnerability tracking, and remediation.

Manage the external penetration testing program, from scoping and vendor selection through findings triage and remediation verification.

Set and evolve standards for authentication, authorization, session management, and API security across internal and customer-facing applications.

Deliver enterprise SSO (SAML 2.0 and OpenID Connect) for customer-facing products in support of contractual security commitments.



Data Security and Governance

Own the data security program end to end, covering data classification, encryption in transit and at rest, key and secrets management, and protections against unauthorized access, exfiltration, and misuse.

Maintain and evolve the data classification framework across UniUni's regional and shared data warehouse environments, and drive schema-level classification into operational use by engineering and analytics teams.

Govern access to production databases, data warehouses, and analytics platforms, including approval workflows, periodic access reviews, and audit trails.

Implement and operate data loss prevention controls across endpoints, email, SaaS, and cloud storage, calibrated to the sensitivity of the data and the realities of how the business operates.

Set and enforce data residency, retention, and minimization standards in line with customer commitments and regulatory obligations across the jurisdictions in which UniUni operates.

Partner with engineering, data, and product teams on privacy by design, including data flow mapping, data sharing agreements, and the secure handling of personal information for shippers, drivers, and end recipients.

Lead the response to data subject requests, data incidents, and breach notification obligations under applicable privacy laws.


Compliance and Governance

Maintain and continuously improve UniUni's ISO 27001 certification, including surveillance audits, internal audits, risk assessments, and management reviews.

Sustain UniUni's SOC 2 Type II attestation, owning control operation, evidence collection, auditor relationships, and remediation.

Own the information security policy framework, including authoring, approval workflows, annual reviews, and employee attestations.

Operate the risk management program, including the risk register, risk treatment plans, and executive risk reporting.

Lead customer-facing security activities, including security questionnaires, contract reviews, and security clauses in vendor and customer agreements.

Support regulatory compliance efforts relevant to our business, including the DOJ Data Security Program, Canadian PIPEDA, and applicable US state privacy laws.


IT Security and Operations

Partner with IT to operate and mature endpoint security, including EDR, MDM (Intune), disk encryption, and device compliance.

Govern identity and access across SaaS and corporate systems, including SSO adoption, MFA enforcement, privileged access controls, and joiner-mover-leaver processes.

Own the SaaS inventory and run periodic access reviews, with particular attention to shadow IT and uncontrolled data flows.

Lead security awareness training and phishing simulation programs.

Run the incident response program, including the IR plan, tabletop exercises, on-call rotation, and post-incident reviews.

Contribute to business continuity and disaster recovery planning in partnership with engineering and operations.


Leadership and Stakeholder Engagement

Build and lead a small security team, with hiring underway across two tracks: Compliance and GRC, and Application and Platform Security.

Serve as UniUni's senior security voice with customers, prospects, auditors, regulators, and investors.

Report on security program status, KPIs, and risks to the CTPO and the executive team on a regular cadence.

Represent security considerations in cross-functional decisions across product, infrastructure, vendor selection, and business expansion.



Required Qualifications

10+ years in information security, with at least 3 years owning a security program or a major security domain.

Demonstrated ownership of ISO 27001 certification maintenance and SOC 2 audit execution in a cloud-native organization.

Deep hands-on experience securing AWS environments at scale, including IAM, networking, logging, and workload protection.

Strong application security background across secure coding practices, common vulnerability classes, and modern AppSec tooling (SAST, DAST, SCA, secrets scanning).

Demonstrated experience building data security and governance programs, including data classification, encryption, DLP, access governance for data stores, and privacy-aligned data handling.

Practical experience with SAML 2.0 and OpenID Connect, and a track record of rolling out enterprise SSO and MFA.

Experience operating core IT security controls, including EDR, MDM, and SaaS access governance.

Track record of leading incident response, including coordination with engineering, legal, and executive stakeholders.

Ability to translate security risk into business terms for non-technical executives, customers, and investors, in writing and in person.


Preferred Qualifications

Background in logistics, supply chain, or high-volume transactional businesses.

Experience in an organization with worldwide cross-border data flows and a focus on North America.

Familiarity with the DOJ Data Security Program and bulk data transfer rules.

Hands-on experience with the Microsoft security stack (E5, Defender, Entra, Purview, Intune), and the perspective to evaluate it against alternatives such as CrowdStrike.

Relevant certifications such as CISSP, CCSP, CISM, or ISO 27001 Lead Auditor or Lead Implementer.

Prior experience taking a late-stage company through IPO-readiness security maturation.



What You Will Find at UniUni

A direct reporting line to the CTPO and regular exposure to the CEO, CFO, and the rest of the executive team.

A security program with real executive commitment, a live ISO 27001 certification, and an active SOC 2 Type II attestation.

Meaningful autonomy to shape the program and the team, balanced by the discipline and cadence of a late-stage operating company.

A growing business with the operational complexity, customer scrutiny, and learning opportunities that come with scale.



How We Work


We value direct, precise, and accurate communication. We prefer honest and defensible language over favorable framing. We write concise documentation, our meeting minutes stand up to auditor review, and we make decisions with our customers and our long-term credibility in mind.


Equal Opportunity

UniUni is an equal opportunity employer. We evaluate candidates on the basis of qualifications, experience, and demonstrated ability, and we do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected characteristic.