Jobs and Careers
CL
Information Security Officer
ClearlinkUnited StatesRemotefull_timeVerifiedPosted 1 Jul 2025
About the role
Who We're Looking For - Information Security Officer
As the Information Security Officer (ISO) at Clearlink, you will be responsible for establishing, maintaining, and continuously improving our organization's information security program. You will ensure that our systems, networks, and data are protected from internal and external threats by designing and implementing security strategies and protocols. The ISO will work closely with leadership and cross-functional teams to align security initiatives with business goals while ensuring compliance with industry regulations and best practices.
The Impact You Will Make
- Lead the company’s compliance efforts for SOC 2, ISO 27001, and PCI frameworks
- Apply deep knowledge of security compliance standards to guide implementation and governance
- Work cross-functionally to ensure appropriate security controls are in place and properly documented
- Manage brand security requirements to support onboarding of new partners and maintain existing partnerships
- Respond to security-related due diligence requests, contractual obligations, and regulatory expectations
- Gather and organize technical evidence needed for compliance and audits
- Oversee documentation of policies, processes, and controls
- Lead audit readiness activities and ensure timely execution across departments
- Develop and Implement Security Strategies
Lead the development and implementation of a company-wide information security strategy, aligning it with business objectives. - Identify, evaluate, and manage security risks across the organization, and implement measures to mitigate potential threats.
- Ensure compliance with relevant legal, regulatory, and contractual requirements (e.g., GDPR, ISO 27001, SOC 2, HIPAA). Develop and maintain security policies, standards, and procedures.
- Design and deliver security awareness programs to educate employees on security risks, policies, and practices.
- Develop and manage the company’s incident response plan, including detection, containment, mitigation, and post-incident analysis. Lead the investigation of security breaches.
- Conduct regular security audits, vulnerability assessments, and penetration tests. Work with external auditors to ensure that the company's security program meets required standards.
- Collaborate with DevOps, IT, and software development teams to integrate security into the development lifecycle (DevSecOps). Ensure security best practices are embedded in infrastructure and application design.
- Evaluate, deploy, and manage security technologies such as firewalls, intrusion detection/prevention systems (IDS/IPS), encryption solutions, and endpoint protection systems.
- Assess and monitor third-party vendors for security risks and ensure that data security requirements are incorporated into contracts and service level agreements (SLAs).
- Develop and manage the information security budget, allocating resources efficiently to achieve security objectives.
What You Bring
- 5+ years of experience in information security, compliance, or risk management roles
- Proven experience leading organizations through SOC 2, ISO 27001, and PCI compliance efforts
- Strong working knowledge of information security frameworks (SOC 2, ISO 27001, PCI-DSS, NIST, etc.) and control implementation
- Hands-on experience with security audits, evidence collection, and documentation management
- Familiarity with security tools, cloud environments (e.g., AWS, Azure), and technical controls (e.g., access management, logging, encryption)
- Extensive experience gathering and managing technical evidence for audits, including working with logs, configurations, and policy documentation, as well as leveraging audit management software and automation tools to streamline evidence collection and compliance tracking
- Demonstrated ability to collaborate cross-functionally with engineering,
- Experience managing external client/partner security requirements, including due diligence processes, security reviews, and contractual obligations
- Excellent written and verbal communication skills, with the ability to clearly explain security concepts to non-technical stakeholders
- Strong organizational and project management skills; able to manage multiple initiatives simulta
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s