Manager, IT Security and Compliance
Who We Are
For more information, visit corporate.authentic.com. Follow Authentic on LinkedIn, Instagram and WeChat.
Why Authentic
You’ll be able to access the resources and scale, while leveraging innovative technology and nimble environment. What we’re saying is, this isn’t your average day job. If you’re hungry to drive ideas into action and own your career, let’s chat. Our team is rapidly innovating to evolve and define the future of our brands. With the help of some of the brightest minds in retail, marketing, licensing, legal and more, we are building the intersection of digital and experiential marketing to help achieve that mission. We reimagine, evolve and transform brands! At Authentic, we foster an inclusive workplace where diversity of thought and expertise drive competitive advantage. Our global teams are built by go-getters who contribute unique perspectives and push the boundaries of creativity and innovation. Headquartered in New York City, Authentic has offices in major metropolitan cities including Los Angeles and Miami, as well as Toronto, Mexico City, London, and Shanghai.
Position Justification
As the organization continues to grow and adopt new technologies, the security and compliance function must scale beyond reactive reviews and ad hoc guidance. Business teams are increasingly relying on SaaS platforms, APIs, cloud services, integrations, automation, and AI-enabled tools to support daily operations. Each of these areas can introduce risk if access, data protection, vendor oversight, logging, configuration, and control requirements are not consistently managed.
Establishing a Manager, Security & Compliance role will provide dedicated oversight for security risk management, application and integration reviews, control design, compliance support, and secure technology adoption. This role will help reduce regulatory, audit, operational, and reputational risk by ensuring that security and compliance requirements are built into new initiatives early, documented clearly, and tracked through remediation.
The role will also relieve existing teams of one-off security assessments, strengthen accountability across the control environment, and create a scalable function that supports the business while maintaining appropriate governance over sensitive data and critical systems.
Position Overview
We are seeking a Manager, Security & Compliance to help strengthen the organization’s cybersecurity, technology risk, and compliance programs. This role will be responsible for evaluating security risks, designing practical controls, supporting audit and compliance activities, and partnering with business and technology teams to ensure new systems, integrations, and processes are implemented securely.
This is a highly visible, cross-functional role suited for someone who can operate effectively in a fast-moving, lean environment. The successful candidate will work directly with application owners, business leaders, IT, legal, and technology teams to translate security and compliance expectations into clear, practical requirements without unnecessarily slowing down the business.
This role reports to the Director of Cyber Security & Compliance.
What You’ll Do
- Lead security and compliance reviews for new and existing technologies, including SaaS platforms, applications, APIs, cloud services, integrations, automation tools, and AI-enabled solutions.
- Assess risk across business and technology initiatives, with a focus on data protection, access controls, vendor risk, logging, auditability, and secure configuration.
- Define and implement practical security controls that align with business needs, regulatory expectations, internal policies, and audit requirements.
- Partner with application owners and business stakeholders to identify security and compliance requirements early in the project lifecycle.
- Conduct security and architecture reviews for applications, APIs, integrations, data flows, and third-party platforms.
- Support compliance activities, including evidence collection, control documentation, risk remediation tracking, user access reviews, and audit response.
- Strengthen application and network security posture by contributing to secure design, vulnerability management, control improvements, and remediation planning.
- Review third-party technology solutions and support vendor due diligence from a security and compliance perspective.
- Establish and maintain guardrails for technology use, including acceptable use, data handling, access management, logging, monitoring, and approval standards.
- Support incident response and investigations involving applications, integrations, vendor platforms, data exposure, or control failures.
- Track risks, issues, remediation plans, and control maturity, and provide clear reporting to leadership.
- Help develop lightweight, scalable processes for reviewing and approving new technologies in a growing organization.
- Stay current on emerging threats, compliance expectations, cybersecurity frameworks, and industry best practices.
- Implement and test CI/CD and secure development controls within internally developed applications.
What You Bring
- Bachelor’s degree in Computer Science, Information Security, Information Systems, or a related field.
- 7+ years of experience in cybersecurity, technology risk, IT audit, compliance, application security, or network security.
- Strong understanding of security and compliance fundamentals, including access management, authentication, authorization, data protection, logging, vulnerability management, and secure configuration.
- Experience reviewing applications, APIs, SaaS platforms, cloud environments, or integration-heavy technology ecosystems.
- Familiarity with application security concepts, including OWASP risks, secure SDLC practices, API security, and data protection requirements.
- Solid grounding in network security concepts and modern enterprise architectures.
- Experience designing, documenting, or testing security controls in SaaS, cloud, or API-driven environments.
- Ability to perform risk assessments and translate findings into practical, business-friendly recommendations.
- Experience supporting audits, compliance programs, or security governance activities.
- Strong communication skills and the ability to influence decisions across technical and non-technical teams.
- Comfortable operating in a lean, fast-paced environment with evolving priorities.
Nice to Have
- Familiarity with frameworks such as NIST CSF, CIS Controls, SOC 2, ISO 27001, or similar control frameworks.
- Experience supporting SOC 2, internal audit, external audit, or regulatory compliance programs.
- Experience with third-party risk management, user access reviews, policy governance, or control testing.
- Exposure to AI governance, emerging technology risk, or responsible AI initiatives.
- Experience in a mid-sized or growth-stage company environment.
- Industry certifications such as CISSP, CISA, CCSP, GIAC, Security+, or similar.
Why This Role Is Unique
- Direct impact on how the company manages cybersecurity, compliance, and technology risk as it grows.
- High visibility with leadership, IT, legal, business stakeholders, and application owners.
- Opportunity to build scalable security and compliance processes from the ground up.
- Broad exposure across applications, infrastructure, cloud, SaaS platforms, integrations, and emerging technologies.
- A chance to balance business enablement with real-world risk management, not just enforce policy.
Success in This Role Looks Like
- New technologies are reviewed consistently, with clear security and compliance requirements defined early.
- Security is seen as a practical business partner, not a blocker.
- Risks are identified, documented, prioritized, and tracked through remediation.
- Controls are practical, scalable, and aligned with audit and compliance expectations.
- Application, integration, and third-party risks are reduced before they become issues.
- Strong partnerships exist across security, IT, legal, compliance, and business teams.
- AI-enabled technologies are governed as part of the broader security and compliance program, rather than managed as a standalone effort.
Primary Location Salary Range:
$140,000 - $150,000
Fraud Alert: Unauthorized Job Offers and Impersonations
We have been made aware of fraudulent job offers and interview requests being sent by individuals falsely claiming to represent Authentic. These scams are often initiated via email, employment websites and social media, and may include fake interview requests, offer letters or attempts to collect personal and financial information.
Please note:
- All legitimate Authentic job postings can be found only on our official website (authentic.com) or through our verified LinkedIn page (https://www.linkedin.com/company/weareauthentic).
- Authentic does not conduct interviews over Teams or Zoom without prior email correspondence from a verified @authentic.com email address.
- We will never ask you for sensitive personal information, payment or banking details as part of the hiring process.
If you believe you've been contacted by someone impersonating an Authentic team member, please report it immediately by emailing peopleandculture@authentic.com.
Authentic is an equal-opportunity employer and we value and embrace the diversity and inclusion of all Team Members. We do not discriminate on the basis of gender, gender identity, sexual orientation, race, national origin, disability, age, marital status, protected veteran status, or other legally protected status.
For individuals with disabilities or religious obligations who would like to request an accommodation, please contact talent@authentic.com
To access Authentic' s Privacy Policy, which contains information regarding data collected from job applicants and how we use it, please click here: https://authentic.com/pages/privacy-policy
Apply for this job
*
indicates a required field

.jpeg?1677767411)