Назад
Company hidden
5 дней назад

Compliance and Security Lead (Cybersecurity)

Формат работы
remote (только Canada)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Compliance and Security Lead (Cybersecurity): Owning hirify.global’s end-to-end security compliance program for an AI customer service platform with an accent on audits, customer trust, vendor risk, vulnerability management, and control automation. Focus on running AIUC, PCI DSS, and SOC 2 audits, reducing large vulnerability backlogs, and translating emerging agentic AI regulations into concrete platform requirements.

Location: Remote from Canhirify.global; remote-first with optional access to a local hub.

Company

hirify.global is a Canadian AI transformation and customer service automation company serving enterprise brands with AI agent management technology.

What you will do

  • Own AIUC, PCI DSS, and SOC 2 audits end to end, including evidence collection, control mapping, and auditor coordination through Drata.
  • Automate evidence collection and control monitoring to maintain year-round audit readiness.
  • Lead security sections of customer RFPs and questionnaires and maintain the SafeBase trust center.
  • Run vulnerability management, prioritizing findings, assigning ownership, and enforcing SLAs for critical issues.
  • Establish repeatable vendor security and privacy reviews and maintain policies, data handling, retention, and control documentation.
  • Track agentic AI governance developments and translate regulatory and framework changes into requirements for the platform team.

Requirements

  • Deep end-to-end audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements.
  • Direct experience working with major audit firms such as Deloitte or EY.
  • Experience automating manual compliance programs with Drata or a similar platform.
  • Experience managing vulnerability programs at scale and reducing large backlogs through prioritization, ownership, and process.
  • Confidence leading enterprise customer security conversations, RFP responses, security questionnaires, and trust center management.
  • Working knowledge of modern infrastructure, Kubernetes, Terraform, and CI/CD; strong policy and control documentation skills.

Nice to have

  • Engineering background.
  • Interest or experience in agentic AI governance, AIUC, and emerging regulatory frameworks.

Culture & Benefits

  • Unlimited vacation and flexible scheduling.
  • Extended health, dental, vision, travel, and life insurance.
  • Wellness account and employee and family assistance plan.
  • Learning and development budget and work-from-home budget.
  • Access to AI tools and hands-on work with large language models.
  • Remote-first, in-person-friendly work environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →