Security Program Manager at Earnest
Earnest, a fintech company focused on responsible personal lending and savings, is seeking a Security Program Manager to lead our security program and partner with engineering, product, and operations to protect customer data and maintain regulatory compliance. This role will own security governance, risk management, policy development, incident response coordination, and security awareness across the organization.
Responsibilities
- Develop and execute the security program roadmap in collaboration with cross-functional teams.
- Lead risk assessments, third-party/vendor risk management, and remediation planning.
- Partner with engineering to implement secure software development practices and robust cloud security controls.
- Coordinate incident response planning, tabletop exercises, and post-incident reviews.
- Develop, implement, and enforce security policies, standards, and security awareness initiatives.
- Define and monitor security metrics, governance reporting, and executive communications.
Requirements
- 5+ years of information security or security program management experience.
- Experience with regulatory frameworks and controls (SOC 2, ISO 27001, NIST).
- Strong written and verbal communication, program management, and cross-functional collaboration skills.
- Hands-on experience with cloud security (AWS, GCP, or Azure) and identity/access management.
- Knowledge of data privacy regulations (GDPR, CCPA) and privacy-by-design principles.
- Relevant security certifications (e.g., CISSP, CISM) are a plus.
Nice to have
- Experience in fintech or regulated financial services environment.
- Familiarity with vulnerability management, penetration testing, or security operations centers.
About Earnest
Earnest is a mission-driven fintech company focused on making responsible financial products accessible to individuals and families. We value security, customer trust, and continuous learning.
Benefits
- Competitive compensation
- Comprehensive health, dental, and vision insurance
- Generous paid time off and parental leave
- 401(k) with company match
- Professional development opportunities