Skip to content

Open nowPosted 11 days ago

InfoSec Lead

Orbital19 open roles

Pay
$180,000 – $225,000 a year
Where
New York
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInfoSec LeadOrbital · New York
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Orbital's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Orbital postings stay open a median of 31 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 11 days ago

Orbital median: 31 days open

The posting

Orbital is the AI platform for real estate legal work.

Real estate shapes the world around us: our homes, our workplaces and our cultural landmarks. It’s the infrastructure that powers everyday life and is the world's largest asset class. Yet behind every single deal, real estate and legal teams work hard to navigate decades-old complexity; manually connecting documents, hidden obligations, geo-spatial context, and multiple parties into a path forward. We connect the legal and physical record, so that path is clearer than ever before. Our mission is to make real estate transactions faster, clearer, and less manual.

Here, you'll be part of changing how the deals behind the largest asset class get transacted, and will help shape the future of real estate.

A bit about us:

🚀 We’re building at the forefront of AI technology, without losing the deeply human expertise our clients depend on.

🏢 Orbital is built with former practising real estate lawyers and 250+ years of combined legal expertise. We're purpose-built for the complexity of real estate: accelerating due diligence, drafting and negotiation, and deal coordination with legal-grade precision.

💰 We've just raised a $60m Series B, led by Brighton Park Capital, to accelerate our global expansion – $75m raised to date.

🤝 We're trusted by 5,000+ real estate professionals, spanning UK Magic Circle and US Am Law 100 firms, to household names like M&S. Leading firms like BCLP, Orrick, Goodwin, Womble Bond Dickinson and Clifford Chance rely on Orbital to remove the busywork, freeing legal and real estate teams to focus on sharp judgment, standout client service, and closing deals faster.

💡 Working at Orbital means joining a bold, ambitious team, with the trust to take ownership and make a real impact from day one.

THE ROLE

Orbital has been scaling fast, and we’re scaling or security and compliance with it. We're hiring a senior, NYC-based InfoSec Lead to own our information security due diligence, compliance, and vendor risk end-to-end - bringing structure and consistency to work that's currently covered on a contractor basis.

Now is the time to bring this function in-house, focusing on automating manual tasks (such as customer DDQs), enhancing our compliance stance, and ultimately securing the Infosec function as a proactive enabler of our growth.

This is a full-time InfoSec role, working alongside our UK-based IT Manager. Whilst experience in IT operations or IT management is helpful, the Infosec Lead and IT Manager report independently to our Head of Operations and own separate (but naturally interconnected) remits.

You’ll also work closely with Engineering, Product, Legal and our external Infosec support, to keep security and compliance embedded in how the business runs, not bolted on after the fact.

Based in the US, with ideally some flexibility to come to the New York office.

WHAT YOU'LL OWN

INFOSEC & COMPLIANCE DELIVERY

You will:

- Own our InfoSec strategy and roadmap: set the direction for how security and compliance scale with the business, not just an executor; identify control gaps and weaknesses, prioritize remediation, and track it through to completion.

- Own our risk program: run risk identification, assessment and treatment, keep the risk register current. You're making the call on what's an acceptable risk.

  • Own third party risk assurance, in both directions: run vendor security reviews for vendors we bring on (or are renewing with) and own customer & vendor due diligence (DDQs) when we’re the ones being assessed.
  • Pull in support required from the rest of the business and jump on client calls when needed to resolve DDQs.
  • Drive automation on the DDQ side specifically, so it doesn’t eat a disproportionate share of your time as the function matures.
  • Own our existing and future compliance certifications: you’ll be responsible for maintaining compliance with existing standards (ISO 27001 and SOC2 Type 2) and pursuing future certifications relevant to us. Management of the compliance program will be end-to-end, and involve ISMS management reviews, quarterly access control reviews, audit evidence gathering, scheduling and remediation tracking.
  • This also includes keeping policy & public-facing security documentation (eg. our trust centre) current - so certification is a continuously-run capability rather than a periodic scramble.

- Partner cross-functionally: work with Engineering, Product, and Legal to embed security and compliance requirements into how we build and sell, and stay close enough to product changes that customer-facing security information is always accurate.

WHAT WE'RE LOOKING FOR

- Significant senior in-house or scale-up InfoSec leadership experience: you've owned due diligence, vendor review, and compliance work end-to-end inside a fast-moving business, not just advised from the outside.

- Strong understanding of cloud & cloud security, and ideally previous technical background in IT Security or SWE / DevOps.

- A track record of scaling due-diligence processes, not just running them manually, you know how to spot what can be templated, automated, or self-served, and you make that happen rather than just wishing for it.

- Comfortable being close to engineering: you don't need to write code, but you're happy sitting in technical conversations, understanding product changes, and knowing enough about IT systems to weigh in sensibly on security-sensitive changes.

- Pragmatic and delivery-focused: you know the difference between a genuine risk and a distraction, and you keep due diligence and audit work moving at commercial pace rather than becoming a bottleneck.

- AI-literacy with working familiarity with AI governance (ISO 42001, EU AI Act etc).

- Comfortable operating independently: this is an individual-contributor role to start, with real ownership of the roadmap rather than a narrow, audit-only remit.

- Working knowledge of privacy law is important (GDPR/CCPA/US state privacy laws) to partner with our legal function.

WHY THIS MIGHT NOT BE FOR YOU

- You want to run day-to-day IT operations or manage IT staff. That sits with our IT Manager, not this role.

- You prefer tasks defined and handed to you. This is a role for an independent decision maker... you're expected to identify what needs doing, set the plan, and drive it to closure yourself, not wait to be briefed.

- You feel more comfortable with a narrowly-defined, audit-only remit. This role sits close to Engineering, Product, and Legal, and is expected to actively reduce manual DDQ overhead over time, not just process tickets.

WHY JOIN ORBITAL

- Shape how security and compliance scale with the business... the processes and playbooks here are still being built.

- Genuine cross-functional influence: you'll be close to Engineering, Product, and Legal, not sitting outside them.

- Genuine momentum: $60m Series B, doubling headcount, expanding across two continents.

- Work alongside a leadership team that treats security as a business enabler, not just a risk function.

🔒 Security is everyone’s responsibility at Orbital. We ask all team members to follow our security policies, complete regular awareness training, and handle sensitive data with care in line with ISO 27001 standards. Spot something unusual? Reporting risks or incidents quickly helps us maintain the strong culture of security and compliance we all depend on.

💡 At Orbital, we’re committed to building a diverse and inclusive team. We especially welcome applications from people who are traditionally underrepresented in tech. Even if you don’t meet every single requirement, or if the right role isn’t listed yet, we’d still love to hear from you.

💰 This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on several factors, which may include job-related knowledge, skills, experience, and business requirements.

Everyone who works with Orbital goes through background screening before they start. It's part of how we keep Orbital secure, for the people who work here and for the client information we're trusted with.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Orbital's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Orbital's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Orbital's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.