Drive and perform periodic compliance-related activities, such as user access reviews, internal audits, and third party risk management
Develop, implement, and improve core compliance projects, such as leading security awareness training initiatives and helping drive adoption of best practices across the company
Curate responses for customer due diligence and security questionnaires and maintain our security knowledge base
Collaborate with internal stakeholders and external auditors to support third party audits including SOC 1, SOC 2, and ISO 27001
Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements
Requirements
Bachelor’s degree in a related field
2+ years of experience in GRC, information security consulting, cybersecurity risk, audits, or similar roles
Strong written and verbal communication skills with both technical and non-technical stakeholders
Familiarity with and participation in one or more of the following frameworks: ISO 27001, SOC 1, SOC 2, FedRAMP, PCI DSS
Familiarity with information security fundamentals for cloud software systems
Benefits
Start-up equity
Full health, vision & dental coverage
Catered lunches & dinners for SF employees
Commuter benefit
Team building events & happy hours
Flexible PTO
Apple equipment plus home office budget
401k plan
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.