
About Fingerprint
Fingerprint empowers enterprises to detect and stop online fraud with the world’s most accurate device intelligence. We lead our industry with bleeding-edge identification capabilities and work on turning new ideas and discoveries in the fraud detection space into reality. Our customers range from innovative startups to leading enterprise companies, including Plaid, Dropbox, and Booking.com.
Fingerprint is a globally dispersed, 100% remote company. We were named on the 2026 Forbes Best Startup Employers list and ranked #803 on the 2026 Inc. 5000 list of America’s fastest-growing private companies.
We have raised $77M and are backed by Craft Ventures (Tesla, Facebook, Airbnb), Nexus Venture Partners (Postman, Apollo.io, MinIO, Druva) and Uncorrelated Ventures (Redis, Rollbar, Gradle).
About the Role
Fingerprint's security, IT, and compliance function is more mature than most companies of this size: SOC 2 Type 2 achieved, a comprehensive policy suite in place, and solid IT operations running globally. What the function now needs is strategic leadership: someone who can unify security posture, IT operations, and compliance under a coherent strategy, mature each discipline to the next level, and be the credible voice of security and compliance to the rest of the engineering org and to enterprise customers.
We're looking for a Senior Manager, Security & IT to own this function end-to-end, reporting directly to the VP of Engineering. You will manage 4 people across three disciplines: application security, IT operations, and compliance.
This is a VP-direct role with high autonomy and high visibility. Enterprise customers — many of whom are financial institutions and large-scale fraud prevention operators — regularly ask about Fingerprint's security posture. You'll be the person who owns that answer.
Responsibilities
- Unify and mature the function — Create a coherent strategy across security, IT, and compliance with shared standards, shared risk language, and a roadmap that scales with the business.
- Own the security posture — Set and hold the standard for application security, zero-trust principles, vulnerability management, and security-by-default practices across the engineering org.
- Scale the compliance program — Expand scope, mature evidence collection, and position Fingerprint for compliance requirements as enterprise deals grow.
- Run reliable IT operations — Own the tooling, processes, and reliability of IT systems for a 100% remote, globally distributed engineering org.
- Be the security voice to customers and leadership — Represent Fingerprint's security posture credibly to enterprise customers, own the security questionnaire process, and communicate risk and posture to the VP and leadership team.
What You'll Do
Security Strategy & Application Security
- Define and own Fingerprint's application security roadmap: vulnerability management, penetration testing program, security review process for new features and architectural changes.
- Build security-by-default practices into engineering workflows as an enablement capability.
- Own the vendor security assessment process to ensure third parties meet our security bar.
- Define zero-trust security principles and ensure they're embedded in the Cloud Platform and engineering org.
Compliance & GRC
- Own the SOC 2 Type 2 annual audit cycle, including evidence collection, auditor management, and control maturation.
- Drive the roadmap for compliance expansion, evaluating and prioritizing future frameworks (ISO 27001, GDPR, customer-specific requirements).
- Manage the Compliance Lead, supporting their growth while providing strategic leadership context.
- Be the compliance voice in enterprise sales cycles, handling security questionnaires, customer due diligence calls, and contractual security requirements.
- Own the policy framework, ensuring Fingerprint's policy suite stays current, complete, and embedded in daily workflows.
IT Operations
- Manage the Lead IT Engineer, providing strategic direction and organizational context for day-to-day IT operations.
- Own IT strategy, including tooling decisions, access management (Okta, SCIM/SAML provisioning), endpoint management, and identity governance.
- Ensure IT operations scales proactively with engineering headcount growth.
- Define and enforce IT security policies, including device management, access reviews, and offboarding rigor.
Cross-functional Leadership & Communication
- Proactively communicate security posture, compliance status, and IT health to the VP of Engineering with clear recommendations.
- Partner with the Cloud Platform Sr. Manager on infrastructure security, network security, IAM standards, and security logging/alerting.
- Work with Engineering leadership to embed security practices across product teams.
- Represent Fingerprint's security and compliance posture to enterprise customers, prospects, and auditors.
Qualifications
- 7+ years in security, IT, or GRC with at least 3 years managing a team.
- Genuine fluency and breadth across application security, IT operations, and compliance/GRC.
- Application security depth: OWASP familiarity, vulnerability management programs (Snyk or equivalent), and security review processes for engineering teams.
- IT operations leadership: Identity and access management (Okta or equivalent), endpoint management, and remote workforce IT at scale.
- Strategic communicator: Ability to translate security and compliance complexity into business language for leadership and customers.
Preferred Qualifications
- SOC 2 ownership experience: Primary ownership of a SOC 2 audit cycle, managing auditor relationships, and building sustainable control operations.
- Additional compliance frameworks: Experience with ISO 27001 and GDPR, particularly within financial services or healthcare contexts.
- Security tooling stack familiarity: Experience with Snyk, Wiz, Cloudflare, and Okta.
- Enterprise security questionnaire experience: Experience answering rigorous due diligence questionnaires from financial institution InfoSec teams.
- High-growth SaaS experience: Experience in a fast-paced environment where security must keep pace with rapid product and customer growth without becoming a bottleneck.
The Unique Shape of This Role
This role deliberately spans three disciplines that are often separated at larger companies. At Fingerprint's scale, that breadth is a feature, not a bug: the person who owns compliance also owns the security posture that makes compliance meaningful, and the person who owns IT operations also owns the identity and access foundation that security depends on.
We don't expect you to be the deepest technical expert in AppSec, IT operations, and GRC simultaneously — your team covers that depth. What we do expect is that you understand each domain well enough to set direction, evaluate the work, and make hard prioritization calls across all three. This is a role for someone who leads through strategy, communication, and people development, rather than personal technical execution.
Why This Role?
- VP direct line with genuine autonomy: You own the function and come to the VP with recommendations, not requests for direction.
- A strong team already in place: The Lead IT Engineer and Compliance Lead are capable, experienced practitioners.
- High customer visibility: Security posture is a real differentiator in enterprise sales, and you're the person who owns it.
- Compliance maturity to build on: SOC 2 Type 2 is already achieved. The next horizon is yours to define.
- Dedicated leadership: This role exists because Fingerprint recognizes these functions need focused, strategic leadership to reach the next level.
Benefits
Open to
Worldwide
Sign in to track applications and earn points.