Job Description
📋 Description Own PCI compliance end to end, from scoping to audit to remediation. Build and run vulnerability management to find, prioritize, and close issues. Translate technical risk into decisions for leadership and prioritization. Craft programs that help non-security teams understand and own risk. 🎯 Requirements 5+ years in cybersecurity, incl. 3+ years running PCI DSS or ISO 27001 Technical fluency: read system diagrams and discuss architecture with engineers Track record running a security or GRC program solo or as founding function A strong verbal communicator who can explain risk to non-technical executives Collaborative, low-ego style that builds buy-in and resolves conflicts 🎁 Benefits Remote-first workplace Comprehensive health coverage Unlimited PTO Pre-IPO equity package