Security Lead

ColombiaFull-timePosted Jul 22, 2026

Position Overview

Mortgage Cadence is seeking an experienced Security Lead to own and mature core security programs while working collaboratively with engineering, compliance, and product teams. This role offers hands-on technical leadership with a focus on execution and program maturity. The Security Lead will translate risk management priorities into actionable plans, guide a small team of security professionals, and serve as a trusted advisor on security posture and incident response. You will balance strategic program development with operational delivery, ensuring security is embedded into the organization's development and operational processes.

Why This Role Exists

As Mortgage Cadence scales its product and client base, security program maturity has become a competitive necessity and a material business requirement. This role was created to provide experienced security leadership that can own and execute across multiple security disciplines, develop junior staff, and represent security effectively with engineering leadership, audit partners, and key clients.

Core Responsibilities

Team Leadership & Development

  • Coach junior staff on security fundamentals, investigations, and technical execution; actively invest in team capability growth.
  • Collaborate with HR and leadership on hiring plans to grow team capacity as the business scales.

Vulnerability Management & Security Posture

  • Own Mortgage Cadence's vulnerability management program, including setting remediation standards, SLAs, and accountability structures.
  • Build and maintain executive-level security posture dashboards that surface risk status, remediation trends, and key metrics to leadership.
  • Oversee triage, assignment, and resolution of security findings, ensuring risks are tracked and formally accepted with appropriate business context.
  • Drive measurable improvements to security posture over time through governance and cross-team accountability.

Security Incident Response

  • Establish and continuously mature Mortgage Cadence's incident response capability, including detection, triage, escalation, containment, and post-incident review.
  • Lead incident response during security events, providing clear communication to internal stakeholders and, when necessary, to affected clients.
  • Conduct or oversee tabletop exercises and simulations to test readiness and identify gaps in incident response processes.

Application Security & Security Testing

  • Oversee vulnerability scanning, code review practices, and penetration testing activities; integrate security requirements into the development lifecycle.
  • Collaborate with engineering leads to establish secure development standards and hold teams accountable for timely remediation of identified vulnerabilities.
  • Manage relationships with internal and external security testing partners, prioritizing assessments based on risk and business needs.

Compliance, Audit & Client Security

  • Lead Mortgage Cadence's audit and compliance programs (SOC 1/SOC 2, PCI, and other applicable frameworks), working closely with external auditors and internal stakeholders.
  • Serve as the primary security authority for client-facing security reviews, questionnaires, and due diligence engagements.
  • Work with sales and client success to support RFP processes and security-related contract discussions.
  • Ensure audit readiness is a continuous organizational state through evidence collection, control testing, and documentation.

Security Strategy & Governance

  • Own Mortgage Cadence's information security policy framework, ensuring policies remain current, enforceable, and business-aligned.
  • Represent information security on governance bodies (e.g., Change Advisory Board), providing risk-based input on significant organizational and technology changes.
  • Develop and communicate security best practices and risk guidance to the business; translate threat intelligence into actionable priorities.
  • Report on security program health, risk metrics, and strategic recommendations to senior leadership on a regular cadence.

Requirements

Qualifications & Experience

  • 5+ years of progressive information security experience, including at least 2 years in a leadership or management capacity with direct reports.
  • Demonstrated experience owning and maturing security programs across vulnerability management, incident response, and compliance.
  • Solid familiarity with compliance frameworks including SOC 1/SOC 2 (SSAE18), PCI-DSS, and relevant data privacy regulations.
  • Ability to communicate security risk clearly to engineering and executive audiences, translating technical concepts into business context.
  • Experience in a SaaS, fintech, or similarly regulated technology environment preferred.
  • Relevant certifications (CISSP, CISM, CEH, or equivalent) preferred; Security+, SSCP, or relevant domain certifications also valued.
  • Strong track record of building and developing small, high-performing teams in a collaborative, fast-paced environment.

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free