12 дней назад
Security Program Manager (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Program Manager (AI): Managing security compliance, audit readiness, and customer security assurance programs for an AI technology company with an accent on SOC 2 Type II, PCI DSS, HIPAA, FedRAMP, GDPR, and CCPA/CPRA. Focus on coordinating cross-functional control implementation, preparing audit evidence, responding to enterprise security questionnaires, and tracking remediation across multiple frameworks.
Location: Armenia; hybrid
Company
develops AI-powered meeting, voice, and call center software.
What you will do
- Manage and continuously improve the security compliance and governance, risk, and compliance programs.
- Coordinate SOC 2 Type II, PCI DSS, HIPAA, FedRAMP, and other external audits, including preparation, evidence collection, control validation, auditor coordination, and remediation tracking.
- Partner with Engineering, Security, IT, Legal, Privacy, Finance, People, Sales, and Customer Success to maintain effective security controls and documentation.
- Own responses to customer and prospect security questionnaires and support enterprise security reviews and due diligence.
- Maintain reusable security and privacy documentation, approved questionnaire responses, policies, procedures, evidence repositories, and compliance calendars.
- Support privacy compliance, risk assessments, vendor security reviews, metrics, and automation of recurring compliance activities.
Requirements
- 3+ years of hands-on experience in security compliance, GRC, security assurance, or a similar role.
- Hands-on experience supporting audits and assessments for multiple frameworks, including SOC 2 Type II, PCI DSS, HIPAA, and/or FedRAMP.
- Experience with audit preparation, evidence collection, control testing, remediation tracking, and external auditors or assessors.
- Experience completing customer security questionnaires and supporting enterprise customer security assessments.
- Knowledge of security controls covering identity and access management, vulnerability management, change management, incident response, business continuity, logging and monitoring, encryption, and third-party risk.
- Professional proficiency in English, strong program management, communication, documentation, and stakeholder coordination skills.
Nice to have
- Experience in a SaaS, cloud, technology, B2B, or enterprise environment.
- Experience building or scaling a security compliance or GRC program.
- Familiarity with ISO 27001, NIST CSF, NIST 800-53, CIS Controls, or CSA CCM.
- Experience with GRC, security questionnaire automation, cloud security, AWS, Azure, or GCP.
- Understanding of CI/CD, SDLC, vulnerability management, infrastructure security, and enterprise sales security requirements.
Culture & Benefits
- Hybrid work arrangement in Armenia.
- Cross-functional collaboration across security, engineering, IT, legal, privacy, finance, people, sales, and customer success.
- Opportunity to improve compliance processes and support a growing enterprise customer base.
- Respectful and inclusive workplace with no tolerance for discrimination or harassment.
Hiring process
- Applications are reviewed and shortlisted candidates are contacted for the next stages.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →