Portfolio Jobs
We couldn’t be more proud to partner with these companies securing the way people live and work.
IT
Remote
| Position: Principal, Information Security | ||
| ||
| Job Id: 364 | ||
| # of Openings: 1 | ||
| | ||
| Role: Principal, Information Security About interos.ai interos.ai is the standard for supply chain risk intelligence. Our Resilience platform, powered by an 11B buyer-supplier knowledge graph and 250M+ businesses scored across six risk factors, Cyber, Catastrophic, ESG, Restrictions, Geopolitical, and Finance, is run by Fortune 1000 market leaders and trusted by major Federal departments. As the only AI-powered SaaS platform that comprehensively assesses risk across these domains, interos.ai helps customers understand their exposure through our proprietary iScore® and assists both real-time and anticipatory opportunities to mitigate supply chain risk. Our second-generation platform, iQ, is the industry’s first fully productized predictive analytics platform for supply chain risk. iQ orchestrates ERP and Resilience platform insights to deliver AI-driven suggestions for supply chain risk management, helping organizations quantify financial exposure, stay ahead of geopolitical volatility and shifting tariffs, and communicate risk in the language CFOs use every day. We are not afraid to challenge conventions, explore new ideas, and iterate quickly. Our work is meaningful, the problems are complex, and the pace requires focus, curiosity, and adaptability. We are looking for people who are humble in how they collaborate, hungry to succeed, and smart in how they work. People who thrive here are energized by broad exposure, comfortable navigating ambiguity, open to feedback, proactive in taking ownership, and motivated by making a real impact. About the role We are hiring an Information Security Lead to be a hands-on player and coach that leads the Information Security & Compliance function at interos.ai. You will build, run, and continuously improve our security posture across security engineering, security operations, and GRC. You will have high visibility, broad scope, and meaningful influence at a small, fast paced start up. You will have freedom and agency to meaningfully make interos.ai more secure. Each day and week will look different. You might lead an incident response investigation, review architecture proposals, write a polished response to a customer security questionnaire, or reconfigure Defender settings to minimize a recently discovered risk. You operate across the full security spectrum, not just one lane. This role is roughly: 55% security engineering (engineering, configuration, answering questions from the org, & risk management), 20% GRC (SOC2, CMMC, compliance posture), 25% security operations (incident response, monitoring, DR tabletop exercises, red team/purple team exercises). The daily rhythm looks like 70% hands-on engineering, 10% strategic planning, and 20% cross-team collaboration. WHAT YOU'LL DO Own and operate the security tooling stack end to end, including identity and Zero Trust management; endpoint management; network security controls; vulnerability management; and security monitoring and logging • Lead incident response from initial triage through containment, investigation, root cause analysis, and post-mortem documentation • Own disaster recovery planning and lead DR and incident response tabletop exercises to validate business continuity and incident readiness • Plan and lead red team / purple team exercises to validate security controls and stress-test incident response readiness • Manage third-party penetration testing engagements, tracking findings by severity, coordinating remediation with Engineering, and overseeing the retest cycle • Work closely with the Engineering and Platform team on architecture and design reviews, providing security guidance on new features, integrations, and infrastructure changes • Harden cloud and on-premises environments, managing IAM policies, endpoint protection, and network security controls • Work with contractors and external security partners to maintain SOC2 and CMMC compliance posture, including managing the control environment, coordinating evidence collection, and tracking remediation across teams • Handle customer-facing and vendor-facing security questionnaires independently, translating interos.ai’s security posture into clear, polished written responses • Review customer and prospect contracts for security terms, including DPAs and security addendums, partnering with Legal on redlines during deals and renewals • Write and maintain scripts and automations for security workflows, leveraging AI-supplemented tooling where appropriate • Keep leaders informed of Security Risks, including facilitating monthly Security review meetings and our Quarterly Security, Risk, & Compliance Committee meetings with executive leadership team. • Serve as the organization’s go-to technical security advisor, staying current on emerging incidents, trends, and threat analysis • Conduct vendor risk management on third-party tools and services prior to internal adoption, including the fast-growing category of AI and LLM tools • Partner with engineering leadership to evaluate AI and LLM security risks, contribute to responsible AI usage policies, and implement controls for AI tools and integrations used across the platform WHAT YOU BRING • 8+ years of experience in information security, with demonstrated breadth across security engineering, incident response, compliance, and infrastructure security • A track record of operating independently in a fast-paced SaaS environment, making judgment calls without waiting for escalation • Working knowledge of compliance frameworks including SOC2 and CMMC with experience owning or significantly contributing to audit readiness • Strong written communication skills, with the ability to write polished security questionnaire responses and communicate clearly with customers, vendors, and internal stakeholders • Scripting capability (PowerShell, Python, or equivalent) to automate security workflows, not expected to be a full-time developer • Comfort with modern SaaS infrastructure, cloud environments, and identity and access management systems • Cross-functional influence, you are as comfortable advising an engineering team on a design review as you are briefing an executive on risk posture • Proven ability to take full ownership in ambiguous environments, working independently to identify priorities, solve problems, and drive outcomes with lean resources. • Strong risk judgment, with the ability to separate signal from noise and advise the business on security issues that create meaningful exposure. • Balanced, business-minded approach to security, weighing risk, urgency, customer commitments, and company priorities to recommend practical paths forward. BONUS POINTS • Experience creating AI Agents to automate and assist with tasks • Hands-on experience with the Microsoft security stack: Defender, Entra ID, Intune, and M365 security capabilities • Experience evaluating AI/LLM security risks, including prompt injection, model misuse, data exposure, and agentic AI threats • Experience with vulnerability management tooling such as Rapid7 or similar platforms • Relevant certifications such as CISSP, GCIH, GCIA, CCSP, AWS Certified Security Specialty, AWS Certified Solutions Architect, or CAISP • Familiarity with CMMC and FedRAMP requirements or experience supporting federal customers WHAT WE OFFER • Comprehensive health, dental, and vision insurance • 401(k) with employer match • Flexible Time Off (FTO) + 10 paid holidays • Opportunity to help shape an early, fast-growing market • A flexible, remote-first work environment that empowers you to perform at your best, wherever you are • An incredible culture built on trust, accountability, and collaboration across time zones and teams OUR CORE VALUES Technical Skill: We hold a performance-driven standard across everything we build and deliver. We value depth of expertise, strong judgment, and the ability to turn complex challenges into clear, effective solutions. Will: We show up hungry, humble, and smart. We take ownership, seek growth, and elevate one another through curiosity, accountability, and collaboration. Thrill: We stay connected and bring energy to the work. Meaningful relationships and celebrating wins together fuel great outcomes. ADDITIONAL INFORMATION Work Environment, Location, and Travel This role can be remote-first within the United States, with optional access to our Arlington, VA HQ. Occasional travel may be required for team summits, customer engagements, or industry events. Compensation Base Salary Range: $184,000 - $230,000 USD (depending on experience and location) Variable Compensation: Eligible for annual performance bonus Equity: Stock options included as part of total compensation package EQUAL OPPORTUNITY EMPLOYER interos.ai is proud to be an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees regardless of race, religion, gender identity, sexual orientation, age, disability, or veteran status. ACCESSIBILITY & ACCOMMODATIONS We are committed to providing reasonable accommodations for candidates throughout the hiring process. If you need assistance, please contact us at hr@interos.ai. | ||
| Apply for this Position |