Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Flodesk.
Flodesk is recognized in the Inc 5000 as one of the world's fastest-growing email marketing companies, built to help entrepreneurs sell online and design emails that people love to get. We're committed to giving small businesses simple and intuitive tools that help them grow, nurture, and monetize their email list.
We’re a remote-first company headquartered in San Francisco with a globally distributed team, including in-person hubs in Da Nang (Vietnam), Barcelona (Spain), and Menlo Park (California). Our team reflects the diversity and creativity of the people we serve. Join our mission to level the playing field for small business owners through good design.
About the role
You'll own Flodesk's security program end to end: the frameworks, controls, and governance that define our long-term security posture. Reporting to the COO/CPO, this is a hands-on, build-it-yourself role that drives SOC 2, ISO 27001 and CCPA auditing readiness, embedding security into how engineering ships product, and keeping day-to-day IT and vendor operations running. You'll write the policies, run point on audits, partner with engineering on the technical foundations — all while setting the strategic direction for where security goes next and representing it confidently, internally and externally.
What you'll do:
Security program ownership [40%]
Own Flodesk's security program: policies, controls, governance, and long-term maturity planning
Collaborate cross-functionally to build security into product, operational, and technology decisions
Maintain and update - privacy-related security practices across data handling, retention, and customer commitments
Lead SOC 2, ISO 27001 and CCPA readiness, including audits, evidence collection, and continuous compliance
Security implementation & compliance support [40%]
Partner with engineering to integrate security into architecture, development workflows, and release processes, and to build and maintain security foundations across cloud infrastructure, applications, data, and internal systems
Evaluate, implement, and maintain security tooling and automation to scale the program
Own Security Incident Management end to end: process, technical capability, and cross-company engagement
Design, implement, and continuously improve controls
Track and report on security posture, program maturity, and compliance status
Defend Flodesk's SaaS platform and its customers by introducing protective mechanisms and security capabilities
IT support & operations [10%]
Own the lifecycle of company hardware from procurement to retirement
Be the first point of contact for IT issues: hardware, software, network connectivity
Run new-hire setup (accounts, device provisioning) and secure access revocation for leavers. Manage domain registrations, DNS, and general IT housekeeping
Software & vendor operations [10%]
Vet new tools before purchase, checking for SSO, 2FA, and integration capabilities
Maintain a central registry of approved software so the org stays on authorized tools
What you bring:
10+ years in information security, with a track record of building or maturing security programs
3+ years in an information security leadership role
Strong foundation in cloud security, identity governance, vulnerability management, and incident response
Proven experience aligning security and privacy practices with GDPR
Comfortable partnering directly with engineering on product security and secure development practices
Clear, confident communicator with technical and non-technical stakeholders alike
Startup DNA: a can-do attitude, flexibility, and the willingness to occasionally roll up your sleeves on the basics, given our startup mindset
Willing to travel on a semiannual basis
Extra points if you have:
Experience securing SaaS products
Experience implementing SOC 2, ISO 27001/2, or similar security/compliance frameworks
Background in reliability, DevOps, or application architecture
Conversational (or better) Vietnamese
What we bring:
$120,000–$220,000 base salary, depending on your location and experience. We prefer to hire near our Menlo Park hub for in-person collaboration with the COO/CPO. Residents in Seattle & San Francisco Bay Area: $160,000–$220,000; all other locations $120,000–$180,000.
Fully paid health insurance for individual coverage
16 weeks paid parental leave for non-birthing parents; 22 weeks paid maternity leave for birthing parents
Unlimited flexible time off
401k match (US employees only)
$1,000 annual stipend for learning and development
Flodesk is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Flodesk is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email
[email protected]
Notice to California-based Candidates and Vietnam-based Candidates for Employment. This Candidate Privacy Notice is intended to provide information about how Flodesk collects and uses personal information to California consumers and candidates located in Vietnam (Vietnam-based candidates) who apply for employment with Flodesk. If you are employed by Flodesk, refer to the Employee Handbook for additional information. For any questions about this notice, please contact
[email protected].
Personal Information Flodesk Collects:
Identifiers Including name, address, email, telephone number, social security number, driver license number, passport number, and other personal identifying information. For California-based candidat