> Markdown version of [/jobs/ext/1485360-principal-information-security](https://www.wearedevelopers.com/jobs/ext/1485360-principal-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal, Information Security - **Company:** Interos Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $184,000.0 - $230,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Software as a Service, Cyber Security, Disaster Recovery, Identity and Access Management, Python (Programming Language), Network Security, Microsoft Security Essentials, Windows PowerShell, Red Team (Cyber Security), Zero Trust Network Access, Software Vulnerability Management, Data Logging, Scripting, Cloud Platform System, Large Language Models, Microsoft InTune, Purple Team (Cyber Security) - **Published:** July 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=099012acc0838b45 ## About the Role * 8+ years of experience in information security, with demonstrated breadth across security engineering, incident response, compliance, and infrastructure security * A track record of operating independently in a fast-paced SaaS environment, making judgment calls without waiting for escalation * Working knowledge of compliance frameworks including SOC2 and CMMC with experience owning or significantly contributing to audit readiness * Strong written communication skills, with the ability to write polished security questionnaire responses and communicate clearly with customers, vendors, and internal stakeholders * Scripting capability (PowerShell, Python, or equivalent) to automate security workflows, not expected to be a full-time developer * Comfort with modern SaaS infrastructure, cloud environments, and identity and access management systems * Cross-functional influence, you are as comfortable advising an engineering team on a design review as you are briefing an executive on risk posture * Proven ability to take full ownership in ambiguous environments, working independently to identify priorities, solve problems, and drive outcomes with lean resources. * Strong risk judgment, with the ability to separate signal from noise and advise the business on security issues that create meaningful exposure. * Balanced, business-minded approach to security, weighing risk, urgency, customer commitments, and company priorities to recommend practical paths forward. BONUS POINTS * Experience creating AI Agents to automate and assist with tasks * Hands-on experience with the Microsoft security stack: Defender, Entra ID, Intune, and M365 security capabilities * Experience evaluating AI/LLM security risks, including prompt injection, model misuse, data exposure, and agentic AI threats * Experience with vulnerability management tooling such as Rapid7 or similar platforms * Relevant certifications such as CISSP, GCIH, GCIA, CCSP, AWS Certified Security Specialty, AWS Certified Solutions Architect, or CAISP * Familiarity with CMMC and FedRAMP requirements or experience supporting federal customers, Technical Skill: We hold a performance-driven standard across everything we build and deliver. We value depth of expertise, strong judgment, and the ability to turn complex challenges into clear, effective solutions. Will: We show up hungry, humble, and smart. We take ownership, seek growth, and elevate one another through curiosity, accountability, and collaboration. ## Description We are hiring an Information Security Lead to be a hands-on player and coach that leads the Information Security & Compliance function at interos.ai. You will build, run, and continuously improve our security posture across security engineering, security operations, and GRC. You will have high visibility, broad scope, and meaningful influence at a small, fast paced start up. You will have freedom and agency to meaningfully make interos.ai more secure. Each day and week will look different. You might lead an incident response investigation, review architecture proposals, write a polished response to a customer security questionnaire, or reconfigure Defender settings to minimize a recently discovered risk. You operate across the full security spectrum, not just one lane. This role is roughly: 55% security engineering (engineering, configuration, answering questions from the org, & risk management), 20% GRC (SOC2, CMMC, compliance posture), 25% security operations (incident response, monitoring, DR tabletop exercises, red team/purple team exercises). The daily rhythm looks like 70% hands-on engineering, 10% strategic planning, and 20% cross-team collaboration. WHAT YOU'LL DO Own and operate the security tooling stack end to end, including identity and Zero Trust management; endpoint management; network security controls; vulnerability management; and security monitoring and logging * Lead incident response from initial triage through containment, investigation, root cause analysis, and post-mortem documentation * Own disaster recovery planning and lead DR and incident response tabletop exercises to validate business continuity and incident readiness * Plan and lead red team / purple team exercises to validate security controls and stress-test incident response readiness * Manage third-party penetration testing engagements, tracking findings by severity, coordinating remediation with Engineering, and overseeing the retest cycle * Work closely with the Engineering and Platform team on architecture and design reviews, providing security guidance on new features, integrations, and infrastructure changes * Harden cloud and on-premises environments, managing IAM policies, endpoint protection, and network security controls * Work with contractors and external security partners to maintain SOC2 and CMMC compliance posture, including managing the control environment, coordinating evidence collection, and tracking remediation across teams * Handle customer-facing and vendor-facing security questionnaires independently, translating interos.ai's security posture into clear, polished written responses * Review customer and prospect contracts for security terms, including DPAs and security addendums, partnering with Legal on redlines during deals and renewals * Write and maintain scripts and automations for security workflows, leveraging AI-supplemented tooling where appropriate * Keep leaders informed of Security Risks, including facilitating monthly Security review meetings and our Quarterly Security, Risk, & Compliance Committee meetings with executive leadership team. * Serve as the organization's go-to technical security advisor, staying current on emerging incidents, trends, and threat analysis * Conduct vendor risk management on third-party tools and services prior to internal adoption, including the fast-growing category of AI and LLM tools * Partner with engineering leadership to evaluate AI and LLM security risks, contribute to responsible AI usage policies, and implement controls for AI tools and integrations used across the platform ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)