About the job
The impact you'll make:
As the Information Security Team Lead, you will spearhead the daily operations and enhancement of Elliptic's information and cyber security initiatives. Your role will involve driving the adoption of SSDLC v2.0, strengthening our cloud and SaaS security frameworks, and ensuring readiness for external audits and customer due diligence. Collaborate closely with Engineering, Platform, Legal, Procurement, and Customer teams to mitigate risks while facilitating delivery and revenue, including the implementation of Enterprise Tier security features.
Your responsibilities will include:
Programme Ownership and Execution
Lead the execution of the InfoSec roadmap and performance metrics. Transform strategic objectives into actionable quarterly plans with quantifiable results.
Establish necessary gates, controls, and reporting mechanisms for SSDLC v2.0 across build and deployment pipelines.
Direct the baselining of CSPM/SSPM and the targeted reduction of misconfigurations and vulnerabilities.
Risk Management, Assurance, and Audit Preparedness
Oversee ISMS processes in compliance with ISO 27001. Organize evidence collection for customer audits and external assurances (e.g., penetration testing, TPOs).
Lead or contribute to risk management forums. Ensure prompt remediation, risk acceptance, and tracking of exceptions.
Cloud and SaaS Security Enhancements
Collaborate with the Platform team to fortify AWS (IAM, KMS, network segmentation, Security Hub, GuardDuty, logging).
Enhance endpoint security, identity and access management, vulnerability management, and logging throughout the organization.
Leadership and Team Collaboration
Provide daily guidance to TISO, Analysts, and cross-functional contributors.
Foster a pragmatic, developer-friendly security culture through enablement, playbooks, and training.
Vendor Management and Data Governance
Manage vendor security due diligence with defined SLAs and documentation trails. Assist data protection and BC/DR control owners.
Required Qualifications:
Demonstrated experience leading security initiatives in a cloud-native product environment.
Deep understanding of security frameworks and compliance standards.
Strong communication skills with the ability to collaborate effectively across teams.

