Logo for Cardlytics

Head of Security and IT

Role overview

Qualifications

  • 8+ years in security and/or IT leadership
  • Deep, hands-on background in at least two of: security engineering, security architecture, identity access management, or vulnerability management
  • Direct experience owning or heavily supporting SOX and/or SOC 2 compliance programs
  • Experience with modern IAM tooling and cloud security platforms

Responsibilities

  • Own the SOX/SOC 2 control environment for engineering and GUARD
  • Oversee and improve the identity and access management program
  • Maintain the cloud security baseline across the AWS production environment
  • Manage and develop a 5-person team

Key facts

Other skills

  • Team Leadership
  • Security Policies
  • Microsoft Windows
  • Communication
  • Teamwork
  • Problem Solving
  • Accountability

About the company

Cardlytics logo

Cardlytics

AdTech & Programmatic Advertising

Cardlytics (NASDAQ: CDLX) is an advertising platform in banks' digital channels. We partner with financial institutions to run their banking rewards programs that promote customer loyalty and deepen banking relationships. In turn, we have a secure view into where and when consumers are spending their money. We use these insights to help marketers identify, reach, and influence likely buyers at scale, as well as measure the true sales impact of marketing campaigns. At Cardlytics, we are analysts, developers, and data scientists. We are marketers, account managers, and consultants to our clients. We are all focused on making sense of the data we see to make it informative and actionable for our partners. Headquartered in Atlanta, GA with additional offices in New York, Menlo Park, Los Angeles, Troy, Champaign and London, our team rallies around a common desire to win and to help our clients win. We are focused on building a revolutionizing company, but we still care about each other as human beings, and in fact, we know this is a big part of what makes us great. For more information, visit www.cardlytics.com.

Company details

Company typeSME
IndustryAdTech & Programmatic Advertising
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Cardlytics
Founded in 2008, Cardlytics (NASDAQ: CDLX) is the industry-leading purchase intelligence and incentives platform. We make commerce smarter and more rewarding for everyone by helping businesses attract, understand, and incentivize consumers through our partners' digital reward programs. Join us on our mission to make commerce smarter and more rewarding for everyone!

About the Position

Cardlytics is looking for a Head of Security & IT to lead the team responsible for protecting and operating the technology that runs our business. This is a hands-on leadership role: you will set strategy and represent the program to executives, our board, and bank partners like Chase and Wells Fargo, while staying close enough to the work to step in when needed. You will lead a team of five covering security engineering, IT engineering, network engineering, security compliance, and end-user support, our identity and access management program, and the resilience of our AWS-hosted production environment.

Cardlytics is subject to strict compliance oversight from public-company (SOX) requirements and publishing partners (including major financial institutions). This role exists to make sure security and IT are never the reason the business slows down — and increasingly, to make sure the company is using AI to work faster and smarter.

You'll have real executive visibility — direct partnership with the CTO, exposure to the board, and a seat at the table on how Cardlytics adopts AI company-wide. It's a lean, high-trust team where your judgment matters more than process for process's sake, and where leadership is actively investing in modernizing how the function operates.

You Will:

  • Security & Compliance Leadership — own the SOX/SOC 2 control environment for engineering and GUARD (our internal security/compliance program); serve as the primary point of contact for external auditors, internal audit, and third-party risk assessments from bank partners.

  • Identity & Access Management — oversee and improve the identity and access management program across Google Workspace, Okta, and ConductorOne; ensure least-privilege access is enforced and evidenced for audit.

  • Cloud & Product Security — maintain the cloud security baseline across our 100% AWS production environment (EKS, Lambda, Terraform, GitHub Actions); partner with Engineering to triage and remediate findings surfaced through Wiz and Expel (our MDR provider covering CloudTrail, GuardDuty, Wiz Defend, SentinelOne, and Databricks).

  • Company-Wide AI Enablement — act as an internal champion for AI adoption beyond engineering — helping non-technical teams identify safe, effective use cases, and modeling how the security/IT function itself uses AI to move faster (e.g., in compliance evidence-gathering, access reviews, and incident response).

  • IT Operations — ensure reliable, secure device management for a hybrid Windows/macOS remote workforce, a healthy BYOD mobile posture, and responsive IT help desk support company-wide.

  • Certificate & Infrastructure Hygiene — ensure SSL/TLS certificate renewal, network resilience, and general network hygiene practices are proactive, not reactive.

  • Team Leadership — manage and develop a 5-person team; set priorities, review work, and be capable of personally covering any team function during absences.

  • Executive Partnership — work closely with the CTO to align security/IT priorities with business strategy; communicate risk and program status clearly to non-technical executives and the board.

You Have:

  • 8+ years in security and/or IT leadership, including 3+ years managing a team directly.

  • Deep, hands-on background in at least two of: security engineering, security architecture, identity & access management, or vulnerability management — you can read technical output and challenge it, even if you're not writing production code day to day.

  • Direct experience owning or heavily supporting SOX and/or SOC 2 compliance programs, including working with external auditors.

  • Experience with modern IAM tooling (Okta, Google Workspace, or similar) and cloud security platforms (Wiz or comparable CNAPP/CSPM).

  • Comfort operating in a fully remote, lean-team environment where you'll rely upon managed/third-party providers rather than building everything in-house.

  • Working knowledge of AWS and IaC concepts (Terraform) sufficient to have informed conversations with engineering — you don't need to write it yourself.

  •  Executive-level communication skills: able to translate technical risk into business terms for a CTO, board, and bank auditors.

  • Genuine enthusiasm for applying AI tools to security, IT, and compliance workflows — and for helping non-technical teams do the same.

  • Experience in fintech, adtech, or another environment with heavy third-party/bank compliance scrutiny— valued, not required.

  • Familiarity with Databricks, EKS, or MDR/managed-SOC relationships (e.g., Expel or similar)— valued, not required..

  • A security or compliance certification (CISSP, CISM, or equivalent) — valued, not required. 

Technical Environment

We primarily use macOS and Google Workspace (Docs, Sheets, Slides). While our preferred platform is macOS, we support both macOS and Windows. Familiarity with or willingness to work within this environment is required.

Core Values

Our shared values are the driving force behind everything we do. Across all roles, we are looking for teammates who embody these values:

  • Customer and partner first

  • Act with urgency and focus

  • Integrity with our partners and data

  • Accountability even when challenged

  • Empowerment over hierarchy

  • Growth over comfort

Benefits and Perks

  • Flexible paid time off plus company holidays

  • Medical, dental, and vision insurance begins on your first day

  • 401(k) retirement plan with company match, plan also includes a student loan debt repayment option

  • Employee Stock Purchase Plan

  • Educational assistance for continuing education

  • Lifestyle Spending Account for physical, emotional, and financial wellness (like gym memberships, home down payments, art classes, park passes, and more!)

  • Complimentary Calm app subscriptions to support employee mental health and wellbeing

As an equal opportunity employer, Cardlytics is committed to diversity, equity, and inclusion. Our people bring our products and organization to life, and every unique perspective makes us better. If you can do the job and you’re excited about growing with us as we scale our best-in-class advertising platform, we’d love to hear from you. If you need accommodation in the recruiting process due to a disability, please email recruiting@cardlytics.com or inform your recruiter.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Head of Cybersecurity Related jobs

Other jobs at Cardlytics

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.