1 день назад
Associate Director, Security & Compliance (US)
140 000 - 175 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Associate Director, Security & Compliance (US) (SaaS security and privacy): Leading end-to-end security, privacy, and compliance programs for SaaS products and agency client projects with an accent on SOC 2 Type II, ISO 27001, ISO 42001, and privacy governance. Focus on designing controls, preparing for audits, embedding security into delivery, managing vendor reviews, and strengthening incident response.
Location: United States; remote-first
Salary: $140,000–$175,000 per year
Company
is a digital-first creative agency combining creativity and technology to deliver digital products and client solutions.
What you will do
- Lead security, privacy, and compliance strategy across SaaS products and client projects.
- Own SOC 2 Type II, ISO 27001, and ISO 42001 readiness, ongoing compliance, control design, evidence collection, and auditor coordination.
- Lead privacy governance covering HIPAA, GDPR, and CCPA/CPRA requirements.
- Embed security and privacy practices into product development and client delivery, including identity, access, data handling, multi-tenancy, logging, and auditability.
- Establish client security plans, lead vendor reviews, and support security questionnaires, RFPs, and client assurance activities.
- Maintain incident response playbooks, exercises, escalation processes, and post-incident improvements.
Requirements
- 8+ years of progressive information security experience, including leadership in SaaS and/or professional services environments.
- Strong application and cloud security knowledge covering identity and access, encryption, key management, logging, monitoring, and vulnerability management.
- Demonstrated ownership of SOC 2 Type II and ISO 27001 programs from readiness through steady-state operations.
- Working knowledge of HIPAA, GDPR, and CCPA/CPRA, with experience operationalizing privacy controls.
- Clear communication skills for working with internal teams, auditors, and client stakeholders.
- Comfort coordinating work across a geographically dispersed organization and multiple time zones.
Nice to have
- Agency or consulting experience supporting multiple client projects.
- Experience with AI-enabled products, data flows, model risk, and ISO 42001.
- Expertise in GCP, AWS, or Azure and common SaaS security patterns.
- Experience with Vanta, Drata, SecureFrame, security tooling, or relevant security and privacy certifications.
Culture & Benefits
- Remote-first approach with teams distributed across North America, South America, Europe, and Asia.
- Work spans creative technology, financial services, travel and hospitality, government, education, media, and other major categories.
- Opportunity to support SaaS products and projects for global brands and agency clients.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Plaid
1 день назад
Security Analyst, Third-Party Ecosystem Risk Management
119 000 - 176 000$
3 дня назад
Principal Security GRC Analyst (FedRAMP)
150 000 - 200 000$
CrowdStrike
6 дней назад
Principal Consultant - Cloud Red Team Blue Team (Cloud Cybersecurity)
140 000 - 195 000$
1 день назад
Staff Security Analyst (Cybersecurity)
123 200 - 154 000$
Affirm
3 дня назад
Security Risk Management Specialist II
115 000 - 180 000$
9 часов назад
Senior Director, Governance and Risk (Cybersecurity)
120 000 - 195 000$