×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Lead; Remote

Remote / Online - Candidates ideally in
Palo Alto, Santa Clara County, California, 94306, USA
Listing for: Allocate Holdings Inc.
Remote/Work from Home position
Listed on 2026-01-25
Job specializations:
  • IT/Tech
    Cybersecurity, IT Project Manager, Information Security, IT Consultant
Job Description & How to Apply Below
Position: Information Security Lead (Remote)

About Allocate

We founded Allocate with the simple mission of making investing in top‑tier private alternatives within the technology sector more accessible for a broader set of investors. We believe that the mark of healthy and efficient markets requires the financial inclusion of all qualified market participants. However, despite significant demand, investing in private technology‑focused alternatives is more complex than ever as discovery, investment diligence and selection, access, and deal execution all serve as substantial roadblocks.

With Allocate, investors can find, invest (through Allocate SPV feeders), and track highly vetted opportunities through our turnkey digital platform in a single easy‑to‑use interface.

Job Description

Allocate is looking for an Info Sec Lead to own and evolve our information security program as we scale. As a fintech company handling sensitive investor data and financial transactions, security and compliance are foundational to everything we do. This role will consolidate security responsibilities currently distributed across our Product and Engineering leadership, allowing them to focus on their core functions while you build out a mature security practice.

You’ll be responsible for policy enforcement, compliance management (SOC
2), vendor security assessments, and developing our security roadmap, including migration to a Zero Trust architecture. You’ll also oversee our relationship with our IT managed service provider and handle some basic IT functions. This is a high‑impact role with both leadership and IC aspects and significant growth potential; the right person could eventually build out and lead an entire Info Sec team here at Allocate.

Essential

Responsibilities and Duties:

Governance, Risk, and Compliance (GRC)
  • Own and evolve the GRC program in partnership with Legal and our CCO
  • Lead all efforts to achieve and maintain critical compliance certifications (SOC 2, potentially ISO 27001)
  • Manage external SOC2 audits and coordinate with third‑party auditors (currently 4‑6 week intensive periods annually)
  • Conduct quarterly user access reviews and maintain comprehensive access control documentation
  • Lead responses to due diligence questionnaires (DDQs) for information security matters
Policy Enforcement & Management
  • Develop, maintain, and enforce clear, practical security policies across all departments
  • Work cross‑functionally with IT and HR to ensure consistent policy adherence
  • Monitor compliance with laptop MDM requirements, 2FA, policy attestations, and security training
  • Manage policy updates and communicate changes effectively to the organization
  • Review logs, access permissions, and information sharing practices to identify compliance gaps
Strategy & Planning
  • Develop and execute a comprehensive information security roadmap aligned with business objectives
  • Lead the organization’s migration to a Zero Trust security approach
  • Drive cultural change around data protection practices across all business units
  • Plan for and implement security improvements to support company growth
Endpoint Security & IT Infrastructure
  • Select, implement, and manage endpoint detection and response (EDR) solutions
  • Lead rollout of security technologies across all employee devices
  • Establish continuous monitoring protocols for endpoint security
  • Manage BYOD policies and company device distribution
  • Implement virtual office network capabilities for Allocate devices
IT Operations & Vendor Management
  • Oversee relationship with our managed IT service provider
  • Act as a security‑focused intermediary for IT requests, ensuring appropriate access controls
  • Manage general IT operations, including email, machine compliance, and onboarding/offboarding
  • Manage support ticket flow and ensure sensitive information is properly protected
  • Evaluate and implement ticket management systems for security‑sensitive support requests
Third‑Party Security
  • Conduct vendor security reviews, risk assessments, and ongoing monitoring
  • Evaluate SaaS tools and API connectors for security implications
  • Lead the due diligence evaluation of our vendors
  • Manage vendor access and integration security
  • Research, evaluate, and select security tools to build a mature,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary