Minute Media is a global technology and content company built for the future of sports consumption. Minute Media’s proprietary technology platform enables the creation, distribution, and monetization of digital content experiences, powering Minute Media’s portfolio of trusted content brands, including Sports Illustrated, The Players’ Tribune, and FanSided, as well as third-party publishers and advertisers. The technology platform also includes STN Video, an online video platform (OVP) that provides access to a robust sports highlights rights portfolio. Minute Media is building the future of how the world connects with sport, powered by innovation, shared globally, and trusted by millions of fans and the partners we serve. For more information, visit www.minutemedia.com.
About the role
You will own security at Minute Media end to end: strategy and execution, both. You inherit a working program, with an annual SOC 2 Type II audit, an established tool stack, and clear vendor-gating rules already in place. You will work closely with our Application Architect, our IT team, Legal, and engineering leads across Israel, the US and the UK. The role reports to a member of the executive team.
This is a player-coach role. One week you present the annual risk review to management; the next you are pulling audit evidence, tuning a cloud alert rule, or reading a vendor's risk scan yourself. If you need a large team under you to be effective, this is probably not the right fit. If you like owning the whole problem, it is a good one.
Requirements
What you will do:
- Own the annual SOC 2 Type II audit end to end: controls, evidence collection, external auditors and consultants. The bar we hold ourselves to is zero deviations.
- Run supply-chain security: vendor risk assessments and security questionnaires, gating rules for new vendors, and contract security terms together with Legal. We do not onboard vendors without SOC 2 or ISO 27001, and critical findings block the deal.
- Own application security with runtime-context prioritization: focus engineering on what is actually exploitable in production, and filter out the scanner noise.
- Run day-to-day security operations: cloud security posture across AWS and GCP, EDR, email security, identity and zero-trust access, alert triage and remediation follow-up with the owning teams.
- Manage the annual penetration-testing program: scoping, vendor selection, findings triage and remediation tracking with R&D.
- Own incident response: keep the plan current, run it when needed, and handle notification duties toward our cyber insurer.
- Run the security awareness program and the security portion of employee onboarding.
- Manage the security budget, tool renewals and vendor relationships.
- Set governance for AI tools used across the company: usage guidelines, risk registers, and security review of new AI vendors.
What you will bring:
- 7+ years in information security, including at least 2 years owning a security function or leading the work of others.
- Hands-on cloud security experience in AWS (GCP is a plus). You can read an alert, form an opinion and act on it yourself.
- You have taken a company through SOC 2 or ISO 27001 audits personally, evidence included, not just from the steering committee.
- Working knowledge of application security, and the ability to talk with developers in their own language.
- Experience running third-party and vendor risk.
- Clear written English. The role works daily with US and UK teams, auditors and vendors.
- Comfort using automation and AI tools to multiply what a small team can do.
Nice to have:
- Media, ad-tech or other high-traffic consumer-web experience.
- Security due diligence on M&A.
- Experience presenting risk to executive management.
Our current stack
We believe in telling you what you would actually work with: Wiz, Panorays, Kodem, SentinelOne, Abnormal AI, Okta, Twingate, Jamf, CybeReady, Keeper, Apono, AWS and GCP. Experience with these exact tools is not required; the thinking behind them is.