Head of Security and IT

๐Ÿข Cardlytics, Inc. ยท all Cardlytics, Inc. jobs
๐Ÿ“ United States
๐Ÿ“… Posted 2026-08-18 ยท via Himalayas
๐Ÿท Head-of-Security,IT-leadership,Security-Engineering,Cloud-Security,IT-Director,Head-of-Information-Security,Director-Of-IT-and-Security,Head-Of-Cybersecurity,IT-Security-Director,Head-Of-IT,Director-of-Information-Security,Director-of-Security
Apply on original site โ†—

About Cardlytics
Founded in 2008, Cardlytics (NASDAQ: CDLX) is the industry-leading purchase intelligence and incentives platform. We make commerce smarter and more rewarding for everyone by helping businesses attract, understand, and incentivize consumers through our partners' digital reward programs. Join us on our mission to make commerce smarter and more rewarding for everyone!
About the Position

Cardlytics is looking for a Head of Security & IT to lead the team responsible for protecting and operating the technology that runs our business. This is a hands-on leadership role: you will set strategy and represent the program to executives, our board, and bank partners like Chase and Wells Fargo, while staying close enough to the work to step in when needed. You will lead a team of five covering security engineering, IT engineering, network engineering, security compliance, and end-user support, our identity and access management program, and the resilience of our AWS-hosted production environment.

Cardlytics is subject to strict compliance oversight from public-company (SOX) requirements and publishing partners (including major financial institutions). This role exists to make sure security and IT are never the reason the business slows down โ€” and increasingly, to make sure the company is using AI to work faster and smarter.

You'll have real executive visibility โ€” direct partnership with the CTO, exposure to the board, and a seat at the table on how Cardlytics adopts AI company-wide. It's a lean, high-trust team where your judgment matters more than process for process's sake, and where leadership is actively investing in modernizing how the function operates.
You Will:

-
Security & Compliance Leadership โ€” own the SOX/SOC 2 control environment for engineering and GUARD (our internal security/compliance program); serve as the primary point of contact for external auditors, internal audit, and third-party risk assessments from bank partners.

-
Identity & Access Management โ€” oversee and improve the identity and access management program across Google Workspace, Okta, and ConductorOne; ensure least-privilege access is enforced and evidenced for audit.

-
Cloud & Product Security โ€” maintain the cloud security baseline across our 100% AWS production environment (EKS, Lambda, Terraform, GitHub Actions); partner with Engineering to triage and remediate findings surfaced through Wiz and Expel (our MDR provider covering CloudTrail, GuardDuty, Wiz Defend, SentinelOne, and Databricks).

-
Company-Wide AI Enablement โ€” act as an internal champion for AI adoption beyond engineering โ€” helping non-technical teams identify safe, effective use cases, and modeling how the security/IT function itself uses AI to move faster (e.g., in compliance evidence-gathering, access reviews, and incident response).

-
IT Operations โ€” ensure reliable, secure device management for a hybrid Windows/macOS remote workforce, a healthy BYOD mobile posture, and responsive IT help desk support company-wide.

-
Certificate & Infrastructure Hygiene โ€” ensure SSL/TLS certificate renewal, network resilience, and general network hygiene practices are proactive, not reactive.

-
Team Leadership โ€” manage and develop a 5-person team; set priorities, review work, and be capable of personally covering any team function during absences.

-
Executive Partnership โ€” work closely with the CTO to align security/IT priorities with business strategy; communicate risk and program status clearly to non-technical executives and the board.

You Have:

-
8+ years in security and/or IT leadership, including 3+ years managing a team directly.

-
Deep, hands-on background in at least two of: security engineering, security architecture, identity & access management, or vulnerability management โ€” you can read technical output and challenge it, even if you're not writing production code day to day.

-
Direct experience owning or heavily supporting SOX and/or SOC 2 complianc

โ† All remote jobs