Slang AI Careers

Compliance and IT Security Manager

Overview

We're looking for a Compliance & IT Security Manager to own and advance our compliance programs, security posture, and core IT functions. This is a senior individual contributor role, not a people management position. You'll be the person responsible for making sure our compliance obligations are met, our security controls are effective, and the systems our team relies on every day are well run and secure as the company grows.

Your primary focus is compliance. You'll own our SOC 2 program end to end, from evidence collection to auditor coordination, along with our risk registry and security policies. Alongside that, you'll own the day-to-day IT functions that keep the company running: administering Google Workspace, managing identity and access across our SaaS tools, configuring SSO, and supporting staff through their full lifecycle. The ideal candidate is someone who can move between coordinating a SOC 2 audit and configuring SSO for a new SaaS tool, and who treats compliance as an ongoing discipline.


Key Responsibilities

Compliance & Security

  • Own and maintain the company's security and compliance programs, including SOC 2 audit readiness, evidence gathering, and coordination with external auditors
  • Manage and keep current all company security policies, ensuring they reflect evolving business needs, regulatory requirements, and industry best practices
  • Maintain and update the company's risk registry, tracking identified risks, mitigations, and remediation timelines
  • Plan and execute all regularly scheduled compliance activities, including backup recovery tests, access reviews, business continuity exercises, and tabletop drills
  • Scope, schedule, and coordinate annual penetration tests based on our active production web services and applications, and manage remediation of findings
  • Maintain the company's vendor registry and perform security reviews on both existing and prospective vendors, including evaluating SOC 2 reports, data processing agreements, and security questionnaires
  • Monitor and respond to security events and alerts, triaging issues and coordinating incident response when needed
  • Manage and improve compliance automation workflows in Drata, reducing manual evidence collection and improving audit efficiency
  • Evaluate and recommend security tooling improvements as the company's infrastructure and threat landscape evolve
  • Develop and deliver security awareness training for staff on topics such as phishing, credential hygiene, and data handling

IT & Identity

  • Administer the company's Google Workspace environment, including user management, organizational units, and security configurations such as DLP policies, context-aware access controls, and authentication requirements
  • Own staff account provisioning and deprovisioning across dozens of SaaS platforms via Rippling and Google Workspace, ensuring timely onboarding and thorough offboarding
  • Set up and maintain Single Sign-On (SSO) connections between Rippling and SaaS tools, troubleshooting authentication issues as they arise
  • Own staff onboarding and offboarding from an IT and security perspective, including device provisioning through Rippling, MDM compliance, endpoint security configurations, and timely access revocation
  • Conduct periodic access audits to verify that user permissions are appropriate and that former staff have been fully deprovisioned across all systems
  • Respond to IT help requests via Slack, assisting staff with technical issues, access problems, and general troubleshooting, escalating and documenting as appropriate


Basic Qualifications

  • 7+ years of experience across IT administration, security, and compliance, or a closely related field
  • Bachelor's or Master's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field
  • Nationally recognized cybersecurity certifications such as CompTIA Security+, CompTIA PenTest+, CASM, CISSP, or equivalent
  • Direct experience working through SOC 2 audits, including evidence collection, control mapping, and auditor coordination
  • Hands-on experience administering a cloud productivity and collaboration suite such as Google Workspace or Microsoft 365, including user management, organizational units, security settings, and policy enforcement
  • Experience with identity and access management, including SSO configuration and provisioning and deprovisioning across multiple SaaS platforms
  • Experience with an identity or IT management platform such as Okta, OneLogin, Rippling, JumpCloud, or similar
  • Experience maintaining a risk registry and driving risk remediation processes
  • Familiarity with compliance automation platforms such as Drata, Vanta, or similar
  • Experience coordinating penetration tests and managing remediation of findings
  • Strong written communication skills, particularly for policy authoring, security documentation, and audit evidence
  • Ability to work independently and manage multiple compliance, security, and IT workstreams simultaneously

Nice to Haves

  • CISM (Certified Information Security Manager) from ISACA
  • Hands-on experience hardening a cloud productivity suite, including DLP, context-aware or conditional access, and security key enforcement
  • Experience administering MDM solutions such as Kandji, Jamf, Rippling, or Microsoft Intune
  • Experience leading IT initiatives such as a password manager migration, hardware security key (YubiKey) rollout, or corporate VPN deployment
  • Experience building or improving incident response plans and runbooks
  • Familiarity with zero trust architecture principles
  • Experience with endpoint detection and response (EDR) tools such as CrowdStrike or SentinelOne
  • Background in vendor risk management programs, including maintaining vendor registries and reviewing third-party SOC 2 reports
  • Experience delivering security awareness training programs
  • Familiarity with cloud security concepts across GCP, AWS, or Azure
  • Scripting skills (Python, Bash) for automating security and compliance workflows
  • Prior experience at a fast-growing startup where you owned the security and IT functions

Location

New York / Hybrid or Remote (USA). Employees in the NYC area are expected in-office Tuesday through Thursday. Can be fully remote within the US.


Our Vision

Calling a business shouldn’t feel like a robot-hostage situation, where you’re forced to listen to horrible music and can't reach a human, while enduring a soulless voice uttering "I'm sorry I didn't quite get that" on repeat for eternity. (shudder) That’s why we started Slang AI We use the latest AI and audio wizardry to make transacting via voice so enjoyable it’s more human than human. By 2030, we will save businesses and consumers 1 billion minutes of precious time while transforming voice channels into the preferred mode of communication (it's faster and easier than text).

We have backgrounds building product at companies like Spotify, Buzzfeed, the New York Times, and OpenTable —shipping experiences that have reached hundreds of millions of users. Now, we’re using our backgrounds to start a new culture, one that puts product and human-centered design above all else while fostering constant learning and growth. Sound like something you’d like to be part of? Get on board.


Our Values 

Overachiever Fever. We’re overachievers (we don’t know any other way)

AI Native. We don't just sell AI. We are Al.

Humility Ability. We approach each other with curiosity and openness (know-it-alls not welcome!)

Be A Good Host. We build for hospitality. We should embody it.



About Slang AI

Slang AI is redefining customer engagement through conversational AI, making every interaction seamless and efficient. Our mission is to transform the restaurant industry by providing the ultimate voice AI solution for consistently outstanding customer experiences.


At Slang AI, we believe how we build matters just as much as what we build. We foster a culture rooted in hospitality, ownership, and clarity, where every “Slangsta” feels valued, supported, and connected to the broader impact of our work in the AI-powered future of restaurants.

Executive

NYC - Remote

Share on:

Terms of servicePrivacyCookiesPowered by Rippling