Job Description
📋 Description Maintain SOC 2 Type II compliance: control operation, evidence collection, and annual audits. Lead ISO 27001 certification efforts from gap assessment to surveillance. Own security/privacy programs across GDPR, CCPA and other regulations. Serve as primary advisor on security, privacy, and compliance strategy. 🎯 Requirements 3-5 years in information security, data privacy, governance, compliance, or risk management. Experience maintaining SOC 2 Type II and leading ISO 27001 in SaaS/cloud environments. Hands-on with Vanta or similar GRC platforms (Drata, Secureframe, Sprinto). Strong privacy knowledge: GDPR, CCPA, other applicable regs. Ability to translate technical risk to actionable business recommendations. Experience with cloud infrastructure, IAM, security controls; cross-functional leadership. 🎁 Benefits Competitive compensation Paid Time Off Paid parental leave Remote workplace Flexible work schedules Health, dental, vision, and LTD insurance