Salary
💰 $112,833 - $167,198 per year
About the role
- Report to the Director of Security and serve as a key member of the Cybersecurity team
- Maintain and improve security across external systems and product-related issues
- Serve as the primary point of contact for external auditors and take ownership of SOC 2 Type II audit
- Identify and reduce security and compliance risks, focusing on product-related issues and external systems
- Improve compliance processes using automation and compliance platforms (e.g., Vanta)
- Oversee vulnerability management and ensure timely fixes for vulnerabilities identified by tools like Orca Security
- Guide incident response processes, ensure proper logging and monitoring with Datadog, and act as project manager for follow-up actions
- Provide technical knowledge to implement and enforce legal requirements (GDPR, CCPA)
- Collaborate daily with product, engineering, legal, and HR teams and act as liaison to external auditors
Requirements
- Bachelor’s degree in computer science, engineering, or equivalent experience
- 5+ years of experience in security operations or governance, risk, and compliance (GRC)
- Successfully led multiple SOC 2 Type II audits (experience with ISO 27001 is a bonus)
- Experience with risk assessments, designing and testing controls, and managing remediation efforts
- Familiarity with risk assessment methods and automation of routine tasks
- Experience working with compliance platforms such as Vanta (preferred)
- Experience tracking and remediating vulnerabilities identified by tools such as Orca Security
- Experience with logging and monitoring systems such as Datadog
- Ability to manage competing priorities and keep complex projects on track
- Ability to explain audit findings and technical security concepts to executives and engineers
- Knowledge of regulatory requirements such as SOC 2, GDPR, and CCPA