Назад
Company hidden
1 день назад

Associate Director, Security & Compliance (US)

140 000 - 175 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Associate Director, Security & Compliance (US) (SaaS security and privacy): Leading end-to-end security, privacy, and compliance programs for SaaS products and agency client projects with an accent on SOC 2 Type II, ISO 27001, ISO 42001, and privacy governance. Focus on designing controls, preparing for audits, embedding security into delivery, managing vendor reviews, and strengthening incident response.

Location: United States; remote-first

Salary: $140,000–$175,000 per year

Company

hirify.global is a digital-first creative agency combining creativity and technology to deliver digital products and client solutions.

What you will do

  • Lead security, privacy, and compliance strategy across SaaS products and client projects.
  • Own SOC 2 Type II, ISO 27001, and ISO 42001 readiness, ongoing compliance, control design, evidence collection, and auditor coordination.
  • Lead privacy governance covering HIPAA, GDPR, and CCPA/CPRA requirements.
  • Embed security and privacy practices into product development and client delivery, including identity, access, data handling, multi-tenancy, logging, and auditability.
  • Establish client security plans, lead vendor reviews, and support security questionnaires, RFPs, and client assurance activities.
  • Maintain incident response playbooks, exercises, escalation processes, and post-incident improvements.

Requirements

  • 8+ years of progressive information security experience, including leadership in SaaS and/or professional services environments.
  • Strong application and cloud security knowledge covering identity and access, encryption, key management, logging, monitoring, and vulnerability management.
  • Demonstrated ownership of SOC 2 Type II and ISO 27001 programs from readiness through steady-state operations.
  • Working knowledge of HIPAA, GDPR, and CCPA/CPRA, with experience operationalizing privacy controls.
  • Clear communication skills for working with internal teams, auditors, and client stakeholders.
  • Comfort coordinating work across a geographically dispersed organization and multiple time zones.

Nice to have

  • Agency or consulting experience supporting multiple client projects.
  • Experience with AI-enabled products, data flows, model risk, and ISO 42001.
  • Expertise in GCP, AWS, or Azure and common SaaS security patterns.
  • Experience with Vanta, Drata, SecureFrame, security tooling, or relevant security and privacy certifications.

Culture & Benefits

  • Remote-first approach with teams distributed across North America, South America, Europe, and Asia.
  • Work spans creative technology, financial services, travel and hospitality, government, education, media, and other major categories.
  • Opportunity to support SaaS products and projects for global brands and agency clients.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →