Manager, IT Compliance & Vendor Management in Framingham, Massachusetts at The Landline Company
Explore Related Opportunities
Job Description
About The Landline Company
The Landline Company is redefining the airport journey by building infrastructure that decentralizes the airport. Its platform connects air and ground transportation, extending the airport experience into everyday places and enabling seamless door-to-gate travel while unlocking new demand.
Landline is pioneering remote terminal concepts that bring airport check-in, bag drop, and security screening closer to travelers, including directly into the neighborhoods and destinations where they live, work, and stay.
Operating across North America with a growing network of partners, including Air Canada, American Airlines, Sun Country Airlines, and CLEAR, Landline is building the infrastructure that allows travel to begin anywhere. Learn more at landlineco.com.
The Role
Landline is seeking a Manager, IT Compliance & Vendor Management to build and run the company's cybersecurity control program and to oversee the managed service provider (MSP) that delivers its day-to-day IT operations. This single role owns two connected accountabilities: the performance of Landline's MSP, and the design, operation, and evidencing of the company's control program against the NIST Cybersecurity Framework (CSF) 2.0.
Landline operates in a regulated transportation environment and contracts with airline partners and airports that impose their own security and data-handling requirements. The control program must satisfy those obligations as well as the company's internal risk requirements.
What You Will Do
- Maintain the company's control set mapped to NIST CSF 2.0 across all six Functions: Govern, Identify, Protect, Detect, Respond, and Recover
- Administer the Vanta GRC platform, including integrations, control monitoring, evidence collection, automated test configuration, and remediation tracking
- Perform periodic control testing and design effectiveness reviews, document results, and drive remediation to closure with named owners and due dates
- Own the policy lifecycle: drafting, annual review, approval routing, publication, and attestation tracking
- Maintain the enterprise risk register, including risk scoring methodology, treatment decisions, and executive reporting
- Prepare and coordinate evidence for customer security reviews, airline partner assessments, insurance questionnaires, and external audits or assessments
- Administer the security awareness training program, including phishing simulation and completion tracking
- Serve as the primary relationship owner for the MSP, managing escalations, scheduling, and day-to-day service delivery expectations
- Monitor and report on contracted service levels, document breaches, drive root-cause analysis, and enforce contractual remedies where warranted
- Chair quarterly business reviews with the MSP, setting the agenda, tracking commitments, and maintaining a running action log
- Own the MSP contract lifecycle, including scope changes, renewals, pricing negotiation, and the exit and transition plan
- Verify that MSP-operated controls function as contracted, requiring evidence rather than assertion
- Govern access administration performed by the MSP, including joiner/mover/leaver execution, privileged access review, and periodic user access certification
- Maintain the responsibility assignment matrix (RACI) that defines which controls the MSP operates, which Landline operates, and which are shared
- Operate the vendor intake and security review process for new technology purchases
- Maintain the vendor inventory with data classification, criticality tiering, and review cadence
- Collect and review third-party assurance artifacts (SOC 2 Type II reports, ISO 27001 certificates, penetration test summaries), including analysis of complementary user entity controls and any qualified opinions
- Track vendor contract security terms, breach notification obligations, and data processing agreements
- Maintain the incident response plan and coordinate the annual tabletop exercise
- Serve as compliance lead during security incidents, covering evidence preservation, regulatory notification analysis, and post-incident reporting
- Maintain business continuity and disaster recovery documentation, and coordinate annual restoration testing with the MSP
- Deliver a recurring compliance and vendor performance report to executive leadership
- Provide security and compliance input to procurement, legal, and operations
- Track and report program metrics
What We're Looking For
- Five or more years in IT compliance, information security, IT audit, or IT governance, including at least two years with direct responsibility for a control program or audit function
- Hands-on experience implementing or operating a recognized security framework (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or equivalent)
- Experience administering or serving as a primary user of a GRC or compliance automation platform (Vanta, Drata, Secureframe, LogicGate, AuditBoard, ServiceNow GRC, or equivalent)
- Experience managing or formally overseeing an outsourced IT provider, including service level monitoring and escalation
- Working knowledge of core IT controls: identity and access management, endpoint management, logging and monitoring, vulnerability management, backup and recovery, and change management
- Ability to read a SOC 2 Type II or similar report critically, including scope boundaries, exceptions, carve-outs, and complementary user entity controls
- Clear written communication, as this role produces documentation that external parties read and rely on
- Professional certification such as CISA, CRISC, CISM, or CISSP is a plus
- Direct NIST CSF 2.0 implementation experience, particularly the Govern function and cybersecurity supply chain risk management (GV.SC), is a strong plus
- Experience in transportation, aviation, logistics, or another operationally regulated industry is a plus
- Familiarity with PCI DSS, CCPA/CPRA, or state breach notification requirements is welcome
- Prior experience building a compliance program from an early or undefined baseline is valued
- ITIL foundation or an equivalent service management background is a plus
- Contract negotiation experience with technology vendors or service providers is a plus
Location
Remote in a major metro area in Canada or the United States, with business travel as needed
Compensation
120,000 – 175,000
Why Landline
- Help build the infrastructure that decentralizes the airport and enables travel to begin anywhere
- Work on first-of-their-kind concepts at the intersection of aviation, transportation, and infrastructure
- Direct exposure to senior leaders across airlines, airports, and public-sector partners
- A highly engaged, fast-moving team shaping a new model for how people travel
- Significant opportunity for growth as the company scales
Benefits
- Comprehensive benefits and PTO plan including medical, dental, vision, 401(k), disability, parental leave, and company-paid life insurance
- Flight benefit privileges with our airline partners
- Discretionary PTO