Full-Time

Security Program Manager

Oneleet

Oneleet

11-50 employees

Full-coverage cybersecurity platform and roadmap

Compensation Overview

$75k - $140k/yr

Remote in USA

Remote

Remote in the United States; must be eligible to work in the U.S. (E-Verify for U.S.-based candidates).

Category
Business & Strategy (1)
Required Skills
Kubernetes
Microsoft Azure
Docker
AWS
Terraform
Google Cloud Platform

Get referred to Oneleet

See people who can refer or advise you

Requirements
  • 4+ years in a role involving information security, compliance, or audit (security operations, GRC, vCISO, security advisory, IT/Compliance auditing, or a security-adjacent customer success/IT support role). You’ll need to understand security and operations well enough that compliance becomes the natural byproduct of genuine security, not just checking boxes against the checklist. You should know why the box exists.
  • Working and broad knowledge of security best practices, major compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI), and how controls map to real infrastructure and operations. Audit-side insight is particularly relevant.
  • Technical Account Management experience, or client facing or stakeholder facing experience with strong project management instincts. This is a high-volume, high-interruption, relationship-oriented role that requires you to translate between technical and non-technical people. Startup and business fluency matters, whether gained internally or in consulting with startups, for helping companies find a compliance path that truly fits where they are today.
  • Ability to understand client infrastructure and map security controls to meet compliance goals and the bigger picture of holistic security and compliance.
  • Strong analytical skills to evaluate environments and determine appropriate safeguards.
  • Excellent verbal and written communication skills.
  • Self-driven with the ability to work independently, comfortable with ambiguity, and able to adapt approach client-by-client in a fast-moving startup environment.
  • Willingness to go the extra mile to meet tight deadlines and deliver results.
Responsibilities
  • Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.
  • Provide guidance and recommendations for improving client security posture
  • Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.
  • Collaborate with clients to customize and refine the security program to match their specific use cases.
  • Communicate with clients and stakeholders to ensure smooth and efficient security program creation
  • Liaise with auditors to ensure clients' security programs align with auditors' expectations
  • Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.
  • Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs.
  • Be highly technical, learn new technologies quickly, and translate security concepts into implementations.
  • Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.
Desired Qualifications
  • One or more of the following certifications: CISA, CISSP, CISM
  • Exposure to a “Lead Auditor” scope (cross-framework, whole-program view) rather than a single specialty area
  • Prior experience in customer success, IT support, or technical support background (useful for pace/responsiveness this role demands)

Oneleet provides a full-coverage cybersecurity platform that helps companies build, manage, and monitor their cybersecurity program. Its core offering is a roadmap that guides the implementation of a wide range of security activities—such as penetration testing, vulnerability assessments, awareness training, static code scanning, and endpoint monitoring—within a single platform so teams can plan, execute, and track progress. Unlike tools that offer isolated security functions, Oneleet integrates multiple security disciplines into one roadmap and management experience, making it easier for organizations to achieve secure posture and demonstrate trust to partners. A YC-backed startup, Oneleet’s goal is to simplify effective cybersecurity and reduce friction for companies implementing comprehensive security programs.

Company Size

11-50

Company Stage

Series A

Total Funding

$33.1M

Headquarters

Amsterdam, Netherlands

Founded

2022

Get referred to Oneleet

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Raised a $33 million Series A led by Dawn Capital in 2025.
  • YC says Oneleet is its most popular security compliance platform.
  • Bundled security tools appeal to buyers reducing compliance and vendor sprawl.

What critics are saying

  • Drata and Vanta target the same SOC 2 and ISO 27001 buyers.
  • Reported pricing around $12K to $60K+ creates budget pressure and churn risk.
  • Any breach or audit failure would directly damage its security credibility.

What makes Oneleet unique

  • Security-first compliance platform founded in 2022 by Bryan Onel, Ora Onel, and Erik Vogelzang.
  • Combines penetration testing, code scanning, device monitoring, and audit support in one workflow.
  • YC-backed platform positioned as genuine security, not compliance theater.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

Paid Holidays

Remote Work Options

Company Equity

Wellness Program

Growth & Insights

Headcount

6 month growth

-2%

1 year growth

-8%

2 year growth

0%