Senior Information Security Manager
AffiniPayAbout the role
It's a new day with a new opportunity at 8am!
This is a hands-on leadership role for someone who thrives on elevating security practices from tactical execution to an integrated, metrics-driven, cross-functional program. You'll help modernize how we detect, respond to, and mitigate risk, leveraging AI-enabled platforms like CrowdStrike, Vanta, and Snyk, while also identifying new opportunities to integrate AI to improve security efficiency, reduce alert fatigue, and increase visibility. This role is essential to our company-wide AI adoption effort and directly contributes to AffiniPay’s Value Creation Plan (VPC).
About us:
Founded in 2005, 8am™ (formerly AffiniPay) is the professional business platform built to help legal, accounting, and other client-focused professionals run stronger, more profitable businesses. Today, more than 250,000 professionals across the U.S. trust 8am to help them work smarter, serve clients better, and unlock their full potential. We have been recognized as one of Inc 5000’s fastest growing companies in the U.S. for 13 years in a row, and as a result, our teams continue to grow as well!
What You’ll Do
- Own the implementation, configuration, and operationalization of information security platforms (e.g., CrowdStrike, Security Hub, GuardDuty, Vanta, DataGrail)
- Ensure CrowdStrike and similar tools are correctly configured and deployed, in partnership with the Information Security Engineer, to achieve intended coverage and effectiveness
- Lead monitoring, tuning, and stakeholder engagement for suspicious findings or platform alerts, ensuring clear triage and response workflows
- Oversee the security posture for access controls, logging, and backups, ensuring relevant data is collected and ingested into NG SIEM or other detection pipelines
- Track the effectiveness of tooling, identify opportunities to improve alert fidelity, and eliminate coverage gaps
- Evaluate opportunities to increase automation and efficiency through AI capabilities within existing tools (e.g., CrowdStrike, Vanta, Snyk) and recommend adoption of new platforms that align with our AI growth goals
- Lead experimentation or pilot efforts to improve security signal triage, anomaly detection, and risk prediction through AI/ML-powered capabilities
- Own the identification, evaluation, and documentation of security-related risks across infrastructure, applications, and third-party services
- Develop and maintain actionable risk treatment plans in collaboration with stakeholders, balancing mitigation, acceptance, and investment tradeoffs
- Partner with the VP of Information Security to maintain visibility into top risks, contribute to executive-level risk dashboards, and align controls to actual exposure
- Ensure that AffiniPay’s cloud environments (AWS, Terraform-managed infrastructure) meet commercial security best practices and evolving compliance obligations
- Partner with Infrastructure, DevOps, and DevX to assess and remediate gaps in governance, process documentation, or control ownership
- Drive alignment around security configurations, automation guardrails, and baseline control requirements across brands
- Own security control operations for frameworks, including SOC 2 Type 2, PCI DSS 4.0, and other in-scope privacy obligations
- Ensure evidence collection, documentation, and audit support are proactively maintained
- Maintain clear ownership of control domains, including logging, monitoring, asset management, backup validation, encryption, and vendor risk support
- Build and maintain repeatable, data-driven security metrics and KPIs at the team, department, and executive levels
- Identify or implement tools and workflows to assist in automated data gathering, reporting, and visualization
- Use metrics to support risk reduction decisions, program transparency, and budget justification for future investment
- Contribute to company-wide AI metrics by helping establish security-specific AI adoption benchmarks, efficiency gains, or automation outcomes related to platform usage and team productivity
- Support incident response preparation through tabletop exercises, playbook development, and role clarity across functions
- Partner with Engineering and business stakeholders to triage alerts, classify severity, and coordinate cross-team responses
- Maintain ownership of detection platforms and ensure findings are actionable, prioritized, and communicated to the appropriate teams
- Provide guidance, support, and tactical leadership to Information Security Engineers and Compliance staff
- Serve as a point of contact across departments, building trust and driving execution without escalation
- Help build bench strength and resili
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s