EvenUp is on a mission to close the justice gap using technology and AI. We empower personal injury lawyers and victims to get the justice they deserve. Our products enable law firms to secure faster settlements, higher payouts, and better outcomes for victims injured through no fault of their own in vehicle collisions, accidents, natural disasters, and more.
We are one of the fastest-growing vertical SaaS companies in history, and we are just getting started. EvenUp is backed by top VCs, including Bessemer Venture Partners, Bain Capital Ventures, SignalFire, and Lightspeed. We are looking to expand our team with talented, driven, and collaborative individuals who seek to have a lasting impact. Learn more at www.evenuplaw.com.
Today, our engineering team is roughly 120 people, but by the end of 2026, we’ll roughly double in size. As we grow, we’re looking for a strong Manager to work cross-functionally and manage our security and IT teams within our infrastructure team. We need a hands-on Security Manager to lead our Security efforts and drive our growth. You’ll help us evaluate whether to build or buy security solutions.
Security Strategy & Team Leadership - Define EvenUp's security roadmap and lead a growing Security & IT team. Serve as the internal authority on risk and security posture, advising engineering, legal, and the executive team. Hire and develop talent as the function scales.
Compliance (SOC 2 & HIPAA) - Own our SOC 2 Type II and HIPAA programs end-to-end: gap assessments, control design, audit readiness, and ongoing compliance. Maintain policies and procedures, manage auditor relationships, and stay ahead of evolving regulatory requirements.
Product Security - Partner with Engineering to embed security into the SDLC through threat modeling, secure design reviews, and vulnerability management (SAST, DAST, pen testing). Champion a shift-left, security-by-design culture across the product org.
Corporate IT & Infrastructure Security - Own corporate IT systems (MDM, SSO/IdP, endpoint security, IAM) and cloud security posture. Evaluate and deploy security tooling. Enforce least-privilege and zero-trust principles across the organization.
Vendor & Third-Party Risk Management - Lead the vendor risk program, including security assessments, contract reviews (BAAs, DPAs), and ongoing monitoring of third-party risk exposure.
Incident Response & Risk Management - Maintain the risk register, run periodic risk assessments, and own the incident response plan. Lead tabletops, manage live incidents, and coordinate breach notification in partnership with legal.
Security Culture & Enablement - Drive security awareness across the company through training, documentation, and internal evangelism. Coach engineers and business teams on best practices and build a security-first culture from the inside out.
Mentorship & Growth: Recruit, mentor, and develop engineers through regular feedback, coaching, and career development. Support performance management, growth planning, and team health.
Proven security leadership at a startup or high-growth company - you've built or scaled a security function before, not just maintained one.
Deep compliance experience - hands-on ownership of SOC 2 Type II and HIPAA programs, from control design through audit. Familiarity with emerging requirements (state privacy laws, AI governance) is a plus.
Technical depth across the stack - strong working knowledge of cloud security (AWS/GCP/Azure), IAM, endpoint security, and secure SDLC practices. You can go deep with engineers, not just speak to them.
Product security chops - experience with vulnerability management, threat modeling, and integrating security into fast-moving engineering teams without becoming a bottleneck.
People leadership - track record of managing and growing small technical teams, with the ability to hire well and develop talent as the function scales.
Vendor & third-party risk know-how - experience running a vendor risk program, including security reviews, BAAs/DPAs, and ongoing third-party monitoring in a data-sensitive environment.
Builder mentality - you're equally comfortable writing a policy, configuring a SIEM, presenting to the exec team, and jumping into an incident at 10 pm. You default to doing before delegating.
This is a hybrid role, with an expectation of being in our San Francisco office three days per week.
#LI-Hybrid
Notice to Candidates:
EvenUp has been made aware of fraudulent job postings and unaffiliated third parties posing as our recruiting team – please know that we have no affiliation or connection to these situations. We only post open roles on our career page (evenuplaw.com/careers) or reputable job boards like our official LinkedIn or Indeed pages, and all official EvenUp recruitment emails will come from the domains @evenuplaw.com, @evenup.ai, @ext-evenuplaw.com, no-reply@ashbyhq.com or no‑reply@canditech.io email addresses.
To ensure fairness and proper consideration, we do not accept resumes or expressions of interest via email or social media messages. If you’re interested in a role, please submit your application directly through our careers page.
If you receive communication from someone you believe is impersonating EvenUp, please report it to us at talent-ops-team@evenuplaw.com. Examples of fraudulent domains include “careers-evenuplaw.com” and “careers-evenuplaws.com”.
Benefits & Perks:
As part of our total rewards package, we offer attractive benefits and perks to our employees, including:
Choice of medical, dental, and vision insurance plans for you and your family.
Additional insurance coverage options for life, accident, or critical illness.
Flexible paid time off, sick leave, short-term and long-term disability.
10 US observed holidays, and Canadian statutory holidays by province.
A home office stipend.
401(k) for US-based employees and RRSP for Canada-based employees.
Paid parental leave.
A local in-person meet-up program.
Hubs in San Francisco and Toronto.
Please note the above benefits & perks are for full-time employees
EvenUp is an equal opportunity employer. We are committed to diversity and inclusion in our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Intel is hiring a Sr. Facilities Engineer to lead mechanical system ownership, reliability engineering, and cross-discipline coordination for critical data center and lab environments at its Mission Campus.
CRB is hiring an Electrical Engineer II to design and document electrical systems for life sciences facilities, working with BIM/CAD tools and supporting projects from concept through construction.
AECOM is hiring a Hydromechanical Engineer to design and specify large-scale mechanical systems and waterworks equipment for complex water infrastructure projects across the United States.
Technical Team Lead for KBR’s Greenbelt I&T facility responsible for hands-on supervision and execution of hardware integration, test, and verification activities.
Wabtec is hiring a Production Support Engineer in Erie, PA to troubleshoot build issues, maintain engineering documentation, and drive change management in support of manufacturing operations.
Crusoe is hiring a Staff Commissioning Engineer (Mechanical) to lead and execute mechanical commissioning across Abilene data center builds, managing third-party Cx agents, factory testing, and turnover to operations.
Skyloom (an IonQ company) is hiring a hands-on Electrical Engineer to test and validate PCBAs and multi-board electronic subsystems for space-grade optical communications in Broomfield, CO.
CRB is hiring a Mechanical Engineer IV (PE) to lead HVAC and mechanical utilities design and construction support for advanced life sciences and food & beverage projects.
Experienced voice communications engineer needed to design, integrate, and sustain analog and digital voice systems for NASA operations at Kennedy Space Center.
Experienced mechanical design engineer needed to lead development and validation of small mechanisms and disposable instrument components for Intuitive's minimally invasive surgical systems.
AECOM seeks experienced Project Engineers to provide design review, field engineering, and construction coordination for the California High‑Speed Rail program, starting in Sacramento and relocating to Fresno.
Applied Materials is hiring a Process Engineer IV to lead complex process development, hardware characterization, and troubleshooting for semiconductor and display products in Santa Clara.
MasterBrand Cabinets is hiring an Engineering Technician to support CNC operations, manage Microvellum nesting and tooling, and drive manufacturing improvements at the Arthur, IL plant.
EvenUp employs advanced AI technology under a strict zero-day retention policy. Data is deleted immediately after processing, ensuring no long-term storage risks and highlighting our commitment to data security and client privacy.
10 jobs