Salary
💰 $147,800 - $180,600 per year
Tech Stack
AWSCloudCyber SecurityJamf
About the role
- Lead and own audit readiness for NIST CSF, AICPA SOC II Type 2, and PCI-DSS
- Own a cyber risk assessment and drive maturity in the third-party risk management program (TPRM)
- Support go-to-market and compliance teams by addressing security and compliance inquiries (e.g., responding to security questionnaires, RFPs, and due diligence requests)
- Operationalize the enterprise risk register and risk management across multiple business units
- Establish and enforce security compliance-related processes and documentation
- Automate processes and implement compliance-related tooling, drive adoption of Compliance as Code
- Execute and own excellence of operational tasks
- Collaborate and partner across the engineering organization and business to influence cybersecurity risk management and ensure operational excellence for the security certification program
Requirements
- 3+ years of experience defining, measuring, and maturing a compliance program required (5+ years strongly preferred)
- Bachelor’s, or equivalent industry experience
- Risk-approach mindset to enable the business and growth
- Ability to manage multiple concurrent priorities in a fast-paced environment
- Experience operationalizing risk assessment frameworks and implementing risk management programs
- Demonstrated experience with at least three security control frameworks, such as PCI-DSS, SOC II Type 2, NIST, ISO 27001, FFIEC, SOX, etc.
- Demonstrated experience with building and automating processes and controls
- Understanding of key cloud-based security platforms, including but not limited to: AWS, OKTA, Cloudflare, SIEM, CrowdStrike, Vanta, Cycode, JAMF, InTune, etc.
- Familiarity with key security processes, including but not limited to Vulnerability Management, Risk Management, Identity and Access Governance, Change Management, CI/CD, Detection and Response, BCP/DR
- Strong analytical skills with the ability to translate data insights into actionable recommendations for leadership
- Experience in mapping, redesigning, and optimizing business processes to align with security, privacy, and compliance requirements
- Adept at building trust and fostering collaboration across technical and non-technical stakeholders