Skip to content

Open nowPosted 13 hours ago

IT, Security, and Compliance Manager

Favorited12 open roles

Pay
$140,000 – $170,000 a year
Where
Santa Monica, CA
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT, Security, and Compliance ManagerFavorited · Santa Monica, CA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Favorited's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Favorited postings stay open a median of 31 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 13 hours ago

Favorited median: 31 days open

The posting

Job Title: IT, Security & Compliance Manager Location: Santa Monica, CA (On-site) Employment Type: Full-time Level: Mid–Senior Company: favorited

ABOUT FAVORITED

At favorited, we believe that digital communities should be more than just spaces to watch content. Our platform is a place to connect, engage, and play, and empowers creators by enhancing audience participation and fostering deeper connections.

Our work culture is intense and isn’t for everyone. But, if you’re a self-starter eager to shape the future of social interaction with a team that holds itself to the highest standards, this is the place for you. We value open, yet respectful communication and real-time feedback to help each other grow quickly. If you’re passionate about gaming and have a knack for gamifying everyday life, you’ll thrive in our fast-moving, collaborative environment.

ABOUT THE ROLE

We’re looking for an IT, Security & Compliance Manager to own and build the systems, processes, and programs that keep favorited secure, compliant, and operationally efficient.

This is a highly hands-on role spanning IT operations, information security, compliance, risk management, and vendor management. You’ll work closely with executive leadership, engineering, operations, and external partners to establish the right technology controls and security practices as the company scales.

You’ll also play a key role in determining which security and compliance certifications favorited should pursue, building the roadmap to achieve them, and ensuring the company maintains the appropriate standards as our customer, creator, and business requirements evolve.

RESPONSIBILITIES

- Own day-to-day IT operations, including systems, applications, access management, devices, identity, and employee technology.

- Develop and maintain favorited’s information security program, policies, standards, and controls.

- Own security and compliance readiness, including identifying appropriate certifications and frameworks for the business.

- Develop and manage a roadmap for certifications such as SOC 2, ISO 27001, or other relevant standards based on business and customer requirements.

- Partner with engineering and infrastructure teams to ensure appropriate security controls, monitoring, access management, and infrastructure practices are in place.

- Manage employee identity and access management, including onboarding, offboarding, permissions, and periodic access reviews.

- Establish and maintain security policies covering areas such as access control, acceptable use, data protection, incident response, and vendor risk.

- Own or coordinate security audits, assessments, penetration tests, and compliance reviews.

- Develop and maintain an effective incident response and security escalation process.

- Manage technology and security vendors, including vendor selection, evaluation, contracts, renewals, and ongoing performance.

- Establish a third-party risk management process for vendors that have access to company systems or data.

- Partner with legal, finance, HR, and leadership on privacy, compliance, and risk-related initiatives.

- Maintain accurate documentation and evidence required for security and compliance programs.

- Conduct regular risk assessments and proactively identify opportunities to strengthen the company’s security posture.

- Educate employees on security best practices, policies, and compliance requirements.

- Help establish scalable IT and security processes that can support favorited as the company grows.

WHAT WE’RE LOOKING FOR

- 5+ years of experience across IT, information security, GRC, compliance, or a related field.

- Experience owning or significantly contributing to IT and security programs within a startup or high-growth technology company.

- Strong understanding of security frameworks, controls, risk management, and compliance requirements.

- Experience building security and compliance programs from the ground up.

- Familiarity with SOC 2, ISO 27001, GDPR, CCPA/CPRA, and other relevant security and privacy frameworks.

- Experience managing security audits and certification processes.

- Strong experience with identity and access management, SaaS administration, endpoint security, and IT operations.

- Experience evaluating and managing IT and security vendors.

- Ability to assess the company’s needs and determine which security certifications and compliance standards are appropriate.

- Strong organizational and project management skills with the ability to manage multiple priorities.

- Excellent communication skills and the ability to work effectively with both technical and non-technical teams.

- Comfortable operating independently and building processes where they don’t yet exist.

- High level of discretion, judgment, and ownership when dealing with sensitive company and user information.

WHAT STANDS OUT

- Experience leading SOC 2 Type II or ISO 27001 certification efforts from planning through completion.

- Experience working in a consumer technology, gaming, social, livestreaming, or SaaS environment.

- Experience supporting companies through rapid growth and increasing security or compliance requirements.

- Familiarity with cloud environments such as AWS or GCP.

- Experience with security and IT tools across identity, endpoint management, vulnerability management, SIEM, and compliance management.

- Experience establishing a security program at a company that previously had limited formal security infrastructure.

- Relevant certifications such as CISSP, CISM, CISA, CRISC, or Security+ are a plus.

- A pragmatic approach to security - someone who understands how to build strong controls without unnecessarily slowing down a fast-moving engineering organization.

SALARY & BENEFITS

Compensation: $140k - $170k base salary

Benefits Include:

- Unlimited PTO to prioritize work-life balance.

- 401(k) plan to invest in your future.

- Comprehensive health insurance to support your well-being.

- Paid company holidays to recharge.

- Competitive salary that values your expertise and contributions.

Where You’ll Work: This is a full-time, on-site position in Santa Monica.

EEOC Statement

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Favorited's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Favorited's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Favorited's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.