InfoSec Lead
- $180,000–$225,000 per year
- Hybrid
- FullTime
- IT
About the role
Orbital is the AI platform for real estate legal work.
Real estate shapes the world around us: our homes, our workplaces and our cultural landmarks. It’s the infrastructure that powers everyday life and is the world's largest asset class. Yet behind every single deal, real estate and legal teams work hard to navigate decades-old complexity; manually connecting documents, hidden obligations, geo-spatial context, and multiple parties into a path forward. We connect the legal and physical record, so that path is clearer than ever before. Our mission is to make real estate transactions faster, clearer, and less manual.
Here, you'll be part of changing how the deals behind the largest asset class get transacted, and will help shape the future of real estate.
A bit about us:
🚀 We’re building at the forefront of AI technology, without losing the deeply human expertise our clients depend on.
🏢 Orbital is built with former practising real estate lawyers and 250+ years of combined legal expertise. We're purpose-built for the complexity of real estate: accelerating due diligence, drafting and negotiation, and deal coordination with legal-grade precision.
💰 We've just raised a $60m Series B, led by Brighton Park Capital, to accelerate our global expansion – $75m raised to date.
🤝 We're trusted by 5,000+ real estate professionals, spanning UK Magic Circle and US Am Law 100 firms, to household names like M&S. Leading firms like BCLP, Orrick, Goodwin, Womble Bond Dickinson and Clifford Chance rely on Orbital to remove the busywork, freeing legal and real estate teams to focus on sharp judgment, standout client service, and closing deals faster.
💡 Working at Orbital means joining a bold, ambitious team, with the trust to take ownership and make a real impact from day one.
The Role
Orbital has been scaling fast, and we’re scaling or security and compliance with it. We're hiring a senior, NYC-based InfoSec Lead to own our information security due diligence, compliance, and vendor risk end-to-end - bringing structure and consistency to work that's currently covered on a contractor basis.
Now is the time to bring this function in-house, focusing on automating manual tasks (such as customer DDQs), enhancing our compliance stance, and ultimately securing the Infosec function as a proactive enabler of our growth.
This is a full-time InfoSec role, working alongside our UK-based IT Manager. Whilst experience in IT operations or IT management is helpful, the Infosec Lead and IT Manager report independently to our Head of Operations and own separate (but naturally interconnected) remits.
You’ll also work closely with Engineering, Product, Legal and our external Infosec support, to keep security and compliance embedded in how the business runs, not bolted on after the fact.
Based in the US, with ideally some flexibility to come to the New York office.
What You'll Own
InfoSec & Compliance Delivery
You will:
Own our InfoSec strategy and roadmap: set the direction for how security and compliance scale with the business, not just an executor; identify control gaps and weaknesses, prioritize remediation, and track it through to completion.
Own our risk program: run risk identification, assessment and treatment, keep the risk register current. You're making the call on what's an acceptable risk.
Own third party risk assurance, in both directions: run vendor security reviews for vendors we bring on (or are renewing with) and own customer & vendor due diligence (DDQs) when we’re the ones being assessed.
Pull in support required from the rest of the business and jump on client calls when needed to resolve DDQs.
Drive automation on the DDQ side specifically, so it doesn’t eat a disproportionate share of your time as the function matures.
Own our existing and future compliance certifications: you’ll be responsible for maintaining compliance with existing standards (ISO 27001 and SOC2 Type 2) and pursuing future certifications relevant to us. Management of the compliance program will be end-to-end, and involve ISMS management reviews, quarterly access control reviews, audit evidence gathering, scheduling and remediation tracking.
This also includes keeping policy & public-facing security documentation (eg. our trust centre) current - so certification is a continuously-run capability rather than a periodic scramble.
Partner cross-functionally: work with Engineering, Product, and Legal to embed security and compliance requirements into how we build and sell, and stay close enough to product changes that customer-facing security information is always accurate.
What We're Looking For
Significant senior in-house or scale-up InfoSec leadership experience: you've owned due diligence, vendor review, and compliance work end-to-end inside a fast-moving business, not just advised from the outside.
Strong understanding of cloud & cloud security, and ideally previous technical background in IT Security or SWE / DevOps.
A track record of scaling due-diligence processes, not just running them manually, you know how to spot what can be templated, automated, or self-served, and you make that happen rather than just wishing for it.
Comfortable being close to engineering: you don't need to write code, but you're happy sitting in technical conversations, understanding product changes, and knowing enough about IT systems to weigh in sensibly on security-sensitive changes.
Pragmatic and delivery-focused: you know the difference between a genuine risk and a distraction, and you keep due diligence and audit work moving at commercial pace rather than becoming a bottleneck.
AI-literacy with working familiarity with AI governance (ISO 42001, EU AI Act etc).
Comfortable operating independently: this is an individual-contributor role to start, with real ownership of the roadmap rather than a narrow, audit-only remit.
Working knowledge of privacy law is important (GDPR/CCPA/US state privacy laws) to partner with our legal function.
Why This Might Not Be For You
You want to run day-to-day IT operations or manage IT staff. That sits with our IT Manager, not this role.
You prefer tasks defined and handed to you. This is a role for an independent decision maker... you're expected to identify what needs doing, set the plan, and drive it to closure yourself, not wait to be briefed.
You feel more comfortable with a narrowly-defined, audit-only remit. This role sits close to Engineering, Product, and Legal, and is expected to actively reduce manual DDQ overhead over time, not just process tickets.
Why Join Orbital
Shape how security and compliance scale with the business... the processes and playbooks here are still being built.
Genuine cross-functional influence: you'll be close to Engineering, Product, and Legal, not sitting outside them.
Genuine momentum: $60m Series B, doubling headcount, expanding across two continents.
Work alongside a leadership team that treats security as a business enabler, not just a risk function.
🔒 Security is everyone’s responsibility at Orbital. We ask all team members to follow our security policies, complete regular awareness training, and handle sensitive data with care in line with ISO 27001 standards. Spot something unusual? Reporting risks or incidents quickly helps us maintain the strong culture of security and compliance we all depend on.
💡 At Orbital, we’re committed to building a diverse and inclusive team. We especially welcome applications from people who are traditionally underrepresented in tech. Even if you don’t meet every single requirement, or if the right role isn’t listed yet, we’d still love to hear from you.
💰 This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on several factors, which may include job-related knowledge, skills, experience, and business requirements.
Everyone who works with Orbital goes through background screening before they start. It's part of how we keep Orbital secure, for the people who work here and for the client information we're trusted with.
Description as published by Orbital.