Manager of Security & Compliance
Apply on
Availability Status
This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.
***W2 or Self Inc ONLY***
The Manager of Security & Compliance will oversee Security and Compliance and will need to develop a multi-year roadmap and manage execution against it.
- Hands-on manager with experience wearing a lot of hats.
- Experience leading security for a business unit or division as part of a larger enterprise is a plus.
- Experience with an understanding of business risk appetite and tolerance.
- Experience engaging stakeholders to gain support
- SaaS experience is a plus.
- Experience managing and working with teammates across multiple time zones and continents is a plus.
The successful candidate will have experience in the following:
Develop and maintain strategy for SOC 2 Type 2 and PCI-DSS attestations. Work with audit support contractors to plan and execute audits.
- Experience with PCI-DSS as a Service
- Experience with PCI-DSS 4 is a plus.
- Experience with SOC 2 Type 2 audits.
Work with the Chief Privacy Officer to maintain the business s data privacy program.
- Experience with GDPR, CCPA/CPRA is a plus.
- Experience leading privacy for a multinational SaaS product is a plus.
Lead product security efforts. Develop product security / SDLC strategy that includes SAST, DAST, and OSS scanning.
- Experience with SAST, DAST, and OSS scanning.
- Experience with Fortify On-Demand and Nexus IQ is a plus.
- Experience with SDLC for security and integration with CI/CD pipelines is a
- Experience with container security management is a plus.
Lead vulnerability management program.
- Experience with industry-standard vulnerability tools.
- Experience in evaluating vulnerabilities in a Linux
- Experience developing metrics and tracking remediation.
- Experience with Qualys suite is a plus.
Lead Incident Response process in collaboration with the NOC team.
- Experience with structuring Incident Response process
- Experience with Splunk is a plus.
- Experience with CrowdStrike is a plus.
Lead Third-Party Risk Management program.
- Experience with vendor assessments for SOC 2 and PCI.
- Experience with GDPR sub-processor and controller transfer requirements.
Lead with RFP responses and customer engagement.
- Experience with contract review.
- Experience engaging customer security
- Experience with Responsive is a plus.
- Experience creating customer white papers is a plus.
Interested? Contact: Bruce Ormond