Назад
Company hidden
7 дней назад

Policy and Compliance Lead (Cybersecurity)

130 000 - 160 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Policy and Compliance Lead (Cybersecurity) (Information Security): Developing and maintaining information security policies, standards, and procedures aligned with regulatory requirements and frameworks such as ISO 27001, NIST, and SOC 2 with an accent on compliance assessments, audit readiness, and actionable security controls. Focus on leading policy lifecycle improvements, remediating compliance gaps, and translating complex regulatory requirements into scalable solutions with audit, legal, risk management, and technology teams.

Location: USA - Remote

Salary: $130K–$160K plus bonus or incentive pay

Company

hirify.global is a science and technology company operating across life sciences, diagnostics, and biotechnology businesses.

What you will do

  • Design, develop, and maintain information security policies, standards, and procedures.
  • Lead compliance initiatives and assessments, coordinate cross-functional teams, and identify and remediate gaps.
  • Advise business units on policy interpretation, risk mitigation, and security best practices.
  • Improve the policy management lifecycle through stakeholder engagement, reviews, exception management, and metrics reporting.
  • Translate compliance requirements into practical, scalable solutions with audit, legal, risk management, and technology teams.

Requirements

  • Strong knowledge of regulatory frameworks and standards including ISO 27001, NIST CSF, SOC 2, GDPR, HIPAA, or PCI DSS.
  • Ability to translate technical and regulatory requirements into clear policies, procedures, and actionable controls.
  • Experience preparing for and managing IT security audits such as SOC 2, ISO 27001, or PCI DSS.
  • At least 3 years of experience in information security, risk management, compliance, or policy development in a corporate environment.
  • Ability to work remotely from the USA.

Nice to have

  • Experience with GRC platforms, policy management tools, security automation, and continuous compliance monitoring.
  • Experience influencing stakeholders at all organizational levels, including senior leadership.

Culture & Benefits

  • Remote work from home for eligible employees.
  • Paid time off.
  • Medical, dental, and vision insurance.
  • 401(k) benefits for eligible employees.
  • Bonus or incentive pay eligibility.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →