Remote
Founding Information Security Lead
About this role
Flodesk is recognized in the Inc 5000 as one of the world's fastest-growing email marketing companies, built to help entrepreneurs sell online and design emails that people love to get. We're committed to giving small businesses simple and intuitive tools that help them grow, nurture, and monetize their email list. We’re a remote-first company headquartered in San Francisco with a globally distributed team, including in-person hubs in Da Nang (Vietnam), Barcelona (Spain), and Menlo Park (California).
Our team reflects the diversity and creativity of the people we serve. Join our mission to level the playing field for small business owners through good design. About the role You'll own Flodesk's security program end to end: the frameworks, controls, and governance that define our long-term security posture. Reporting to the COO/CPO, this is a hands-on, build-it-yourself role that drives SOC 2, ISO 27001 and CCPA auditing readiness, embedding security into how engineering ships product, and keeping day-to-day IT and vendor operations running.
You'll write the policies, run point on audits, partner with engineering on the technical foundations — all while setting the strategic direction for where security goes next and representing it confidently, internally and externally. What you'll do: Security program ownership [40%] Own Flodesk's security program: policies, controls, governance, and long-term maturity planning Collaborate cross-functionally to build security into product, operational, and technology decisions Maintain and update - privacy-related security practices across data handling, retention, and customer commitments Lead SOC 2, ISO 27001 and CCPA readiness, including audits, evidence collection, and continuous compliance Security implementation & compliance support [40%] Partner with engineering to integrate security into architecture, development workflows, and release processes, and to build and maintain security foundations across cloud infrastructure, applications, data, and internal systems Evaluate, implement, and maintain security tooling and automation to scale the program Own Security Incident Management end to end: process, technical capability, and cross-company engagement Design, implement, and continuously improve controls Track and report on security posture, program maturity, and compliance status Defend Flodesk's SaaS platform and its customers by introducing protective mechanisms and security capabilities IT support & operations [10%] Own the lifecycle of company hardware from procurement to retirement Be the first point of contact for IT issues: hardware, software, network connectivity Run new-hire setup (accounts, device provisioning) and secure access revocation for leavers.