InfoSec Lead
Job Description
Build security that keeps pace with growth. Orbital is bringing its information security due diligence, compliance, and vendor risk capabilities in-house and scaling them end-to-end. This NYC-based hybrid role helps establish structure and consistency across work that has previously been supported by contractors, partnering closely with a UK-based IT Manager and cross-functionally with Engineering, Product, Legal, and external Infosec support.
You will shape how security and compliance scale with the business, improve the way due diligence is executed (including customer DDQs), and maintain certifications and evidence gathering as a continuously-run capability. If security operations and compliance have to stay accurate while product and customer needs evolve, this role is designed for that reality.
Responsibilities
- Own the InfoSec strategy and roadmap: set direction for how security and compliance scale with the business, identify control gaps and weaknesses, prioritize remediation, and track outcomes through to completion.
- Run the risk program: manage risk identification, assessment, and treatment, keep the risk register current, and decide what risks are acceptable.
- Own third-party risk assurance: conduct vendor security reviews for new vendors and renewals, and lead customer and vendor due diligence (DDQs) when Orbital is being assessed.
- Support DDQ resolution: pull in the right stakeholders and join client calls when needed to resolve DDQs.
- Drive DDQ automation: improve automation on the DDQ side so manual effort does not grow disproportionately as the program matures.
- Maintain current compliance: ensure ongoing compliance with ISO 27001 and SOC 2 Type 2, and pursue future certifications relevant to Orbital.
- Manage compliance end-to-end: run ISMS management reviews, conduct quarterly access control reviews, gather audit evidence, and handle scheduling and remediation tracking.
- Keep security documentation current: maintain policy and public-facing security documentation (including a trust centre) so certification readiness is not a periodic scramble.
- Partner cross-functionally: work with Engineering, Product, and Legal to embed security and compliance requirements into how Orbital builds and sells, staying close to product changes to keep customer-facing security information accurate.
Requirements
- Senior in-house or scale-up InfoSec leadership experience owning due diligence, vendor review, and compliance end-to-end in a fast-moving business.
- Strong understanding of cloud and cloud security, ideally with a technical background in IT Security or SWE / DevOps.
- A track record of scaling due-diligence processes, identifying what can be templated, automated, or self-served, and delivering those improvements.
- Comfort working close to Engineering, including participating in technical conversations and understanding IT systems well enough to weigh in on security-sensitive changes.
- Pragmatic, delivery-focused mindset: distinguish genuine risk from distraction and keep due diligence and audit work moving at commercial pace.
- AI-literacy with working familiarity in AI governance, including ISO 42001 and the EU AI Act.
- Ability to operate independently as an individual contributor initially, with real ownership of the roadmap rather than an audit-only scope.
- Working knowledge of privacy law to partner with Legal, including GDPR, CCPA, and US state privacy laws.
Working model and collaboration
This is a full-time role based in the US, hybrid in New York, NY with ideally some flexibility to come into the New York office. You will work alongside Orbital’s UK-based IT Manager, and both report independently to the Head of Operations, each owning interconnected remits. You will also partner with external Infosec support and collaborate with Engineering, Product, and Legal to embed security and compliance into day-to-day execution.
Security culture at Orbital
Security is everyone’s responsibility. Team members are expected to follow security policies, complete regular awareness training, and handle sensitive data in line with ISO 27001. Reporting risks or incidents quickly supports the culture of security and compliance.
Compensation and screening
Compensation range: $180,000 - $225,000 per year.
Background screening: everyone who works with Orbital goes through background screening before they start.