Slate (slate.auto) Logo

Slate (slate.auto)

Lead, System Security

Posted An Hour Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
144K-240K Annually
Expert/Leader
Remote
Hiring Remotely in USA
144K-240K Annually
Expert/Leader
Lead Slate’s company-wide cybersecurity program across corporate IT, cloud, applications, vehicle systems, manufacturing OT, enterprise platforms, privacy, compliance, security operations, and supply-chain risk. Set strategy, governance, budgets, and risk priorities; mature audit readiness; build and lead the security team; establish vehicle and OT security programs; oversee identity, incident response, threat intelligence, vendor risk, and secure development; and communicate security posture to executives and the board.
The summary above was generated by AI

ABOUT SLATE

At Slate, we’re building safe, reliable vehicles that people can afford, personalize and love—and doing it here in the USA as part of our commitment to reindustrialization. The spirit of DIY and customization runs throughout every element of a Slate, because people should have control over how their trucks look, feel, and represent them.

WHO WE ARE LOOKING FOR 


We are hiring a Director of Cybersecurity to own security and security compliance across all of Slate. This is a company-wide program, not a corporate IT function. You will set the strategy, roadmap, and standards that protect our people, our data, our factory, our customers, and the truck itself, and you will build the team and partnerships to carry it out.

You will work across every part of the business: corporate IT, software engineering, enterprise systems, manufacturing systems, data, vehicle engineering, legal, finance, and our external partners. The job is to make security a capability that helps Slate ship faster and with confidence, not a gate that slows it down.

You will inherit early foundations, including a team, a NIST CSF 2.0 self-assessment, a managed detection and response plan, and baseline security policies, and turn them into a mature, measurable program that holds up to auditors, regulators, partners, and the board.


WHAT YOU GET TO DO 


Security strategy and governance.  Define Slate's cybersecurity strategy, multi-year roadmap, and risk-based priorities. Own the security policy framework, risk register, and governance model. Report on security posture and risk to the CTO, executive team, and board in clear business terms, and own the security budget.


Compliance and regulatory readiness.  Lead Slate toward the frameworks and obligations our business will require, sequenced to match our growth: SOX IT general controls in partnership with Finance and internal audit, NIST CSF 2.0 maturity, ISO 27001 certification, PCI-DSS for payments, CCPA and state privacy laws, NIST 800-171 and CMMC for government and defense-adjacent work, and export control obligations. Own audit readiness, evidence collection, and remediation tracking.


Team and culture.  Recruit, lead, and develop a security team, deciding where to build in-house expertise and where to rely on partners. Run security awareness and training that people remember, and build a culture where teams bring security problems forward early.


Vehicle and product cybersecurity.  Partner with vehicle engineering and connected vehicle teams to stand up a Cybersecurity Management System aligned to ISO/SAE 21434 and UN R155/R156, including threat analysis and risk assessment (TARA), secure over-the-air updates, telematics and backend security, key and certificate management, and supplier cybersecurity requirements. Establish a product security incident response function and a coordinated vulnerability disclosure program and represent Slate in industry groups such as Auto-ISAC.


Application and cloud security.  Work with Software Engineering and DevOps to embed security into the SDLC across our consumer website, ecommerce platform, mobile app, B2B integrations, and internal applications. Set standards for threat modeling, secure code review, SAST/DAST, dependency and secrets management, and cloud security posture across AWS, Azure, and edge platforms. Drive penetration testing and remediation prioritization.

Enterprise systems security.  Partner with Enterprise Systems to secure ERP (SAP S/4HANA), WMS, procurement, warranty, and other business platforms. Own role design standards, segregation of duties, privileged access, and access reviews that satisfy SOX and keep financial and operational data trustworthy.


Manufacturing and OT security.  Partner with Manufacturing Systems, Controls, and IT Operations to secure the plant floor at Warsaw and future sites. Establish an OT security program aligned to IEC 62443, including network segmentation across ISA-95 levels, asset inventory, secure remote and vendor access, OT monitoring, and incident response plans that put safety and production uptime first. You understand that in a factory, a security control that stops the line is also an outage.


Corporate and enterprise security.  Own identity and access management strategy (workforce and federated customer and partner identity), endpoint and email security, vulnerability management, and security architecture for corporate infrastructure, working closely with IT Operations who run the underlying platforms and day to day.


Data security and privacy.  Partner with the Data team and Legal to define data classification, retention, and protection standards across our data lake house, vehicle telemetry, customer data, and manufacturing data. Ensure privacy by design for consumer and connected vehicle data and set controls for safe use of AI and LLM tools across the company.


Security operations and incident response.  Own detection, response, and threat intelligence. Build and exercise the incident response plan across IT, cloud, OT, and vehicle scenarios, including crisis communications, legal coordination, and regulatory notification. Track and improve detection coverage and response times.


Third-party and supply chain risk.  Establish a vendor security risk program covering SaaS providers, MSPs, integration partners, component suppliers, and contract manufacturers, scaled to the risk each one carries.


Partnerships

This role sits within the Technology organization and partners as a peer with the leaders of IT Infrastructure and Operations, Enterprise Systems, Manufacturing Systems, Software Engineering, DevOps, and Data. Outside of Technology, you will work closely with vehicle engineering, manufacturing, legal and compliance, finance and internal audit, supply chain, and customer care. Much of your impact will come through influence rather than authority, so trust, clarity, and pragmatism matter as much as technical depth.


WHAT YOU BRING TO THE TEAM 


  • 10 or more years in information security or cybersecurity, with at least 5 years leading security teams or programs.
  • Experience building or substantially maturing a security program across multiple domains, not only a single function such as SOC, GRC, or AppSec.
  • Hands-on leadership of compliance efforts against recognized frameworks, including SOX IT general controls and at least one of ISO 27001, NIST CSF, SOC 2, or NIST 800-171. You have been through real audits and certifications.
  • Direct experience securing manufacturing, industrial, or OT environments, or a strong working knowledge of IEC 62443, OT network segmentation, and the operational realities of a production floor.
  • Solid technical grounding in cloud security (AWS preferred), identity and access management, application security, and security operations. Deep enough to evaluate architecture and challenge vendors, not only to manage people who do.
  • A track record of translating risk into business terms and making pragmatic, prioritized tradeoffs in a fast-moving environment.
  • Strong written and verbal communication, including presenting to executives and boards, and a low-ego, collaborative approach to working across departments.

Preferred

  • Automotive, EV, or connected product security experience, including ISO/SAE 21434, UN R155/R156, or a Cybersecurity Management System.
  • Experience standing up security for a greenfield plant, a new company, or a business going through rapid scale-up.
  • Consumer ecommerce and payments security, including PCI-DSS scoping and consumer privacy regulations.
  • Experience with CMMC, ITAR/EAR, or government and defense contracting requirements.
  • Familiarity with securing data platforms and AI/ML or LLM-based applications.
  • Industry certifications such as CISSP, CISM, GICSP, or CCSP.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent experience.

Work Authorization Requirement: 

Applicants must be authorized to work in the United States on a permanent basis. We are unable to offer visa sponsorship at this time.  


SALARY RANGE 

The compensation for this position is the range Slate reasonably and in good faith expects to pay for the position taking into account the wide variety of factors that are considered in making compensation decisions, including job-related knowledge; skillset; experience, education and training; certifications; work location; and other relevant business and organizational factors. 


144,122.74 - 240,204.56 USD Annual Base Pay Range:


ADDITIONAL COMPENSATION AND BENEFITS 

Slate offers a wide range of competitive benefits, including medical, dental, vision, life insurance, disability insurance, vacation, and 401k. The successful candidate may also be eligible to participate in the equity program and/or a discretionary annual incentive program, subject to the rules governing such programs. 


WHY JOIN TEAM SLATE?

At Slate, we’re fueled by grit, determination, and attention to detail. The start-up spirit of ingenuity and resourcefulness move our business forward. Team Slate fosters a culture of excellence, innovation, and mutual respect, and is motivated by shared principles.

  • Safety First

  • Delight Customers

  • One Team

  • Relentless Improvement

  • Fast, Frugal, and Scrappy

  • Respectful Collaboration

  • Positive Legacy

WE WANT TO WORK WITH PEOPLE THAT REFLECT THE COMMUNITIES IN WHICH WE OPERATE.

Slate is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, marital status, parental status, cultural background, organizational level, work styles, tenure and life experiences. Or for any other reason.

Slate is committed to providing reasonable accommodation for qualified individuals with disabilities in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at

[email protected].

Similar Jobs

3 Minutes Ago
Remote
USA
223K-279K Annually
Junior
223K-279K Annually
Junior
Consumer Web • Healthtech • Professional Services • Social Impact • Software
Build and lead product and application security efforts, partnering with Product and Engineering on secure design, development, code reviews, vulnerability discovery, and security guardrails. Develop AI-native security tooling and support incident response, vulnerability management, penetration testing, and security operations. Help establish secure development practices and scalable security systems across Headway’s platform.
Top Skills: AWSDatadogEcsFargateFastapiGitKafkaLaceworkPagerdutyPostgresPython 3ReactRedisS3SemgrepSnykSparkSqlalchemyTypescript
3 Minutes Ago
Remote
United States
285K-385K Annually
Expert/Leader
285K-385K Annually
Expert/Leader
Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Owns company-critical, long-term technical problems across multiple teams and organizations. Defines technical strategy, architectures, roadmaps, and engineering standards for large-scale customer-facing systems. Remains hands-on in software development while driving AI adoption in products and engineering workflows. Partners with senior product, engineering, and executive leaders to resolve complex problems, improve reliability and performance, and shape Dropbox’s technical direction.
Top Skills: Agentic FrameworksAIConcurrencyDatabasesDistributed SystemsFrontend SystemsLlm ApisMlMobile SystemsSearch SystemsSoftware DevelopmentStorage Systems
8 Minutes Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Partners with digital technology business leaders to align people strategies with business objectives. Advises on workforce planning, succession, organization design, change management, culture, leadership development, and team effectiveness. Coaches senior leaders, analyzes workforce data and trends, operationalizes talent initiatives, and collaborates with HR centers of excellence and People Operations to deliver effective solutions.
Top Skills: Ai-Powered ToolsArtificial IntelligenceWorkflow Automation

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account