Epicareer Might not Working Properly
Learn More
M

Manager of Security & Compliance

  • Full Time, onsite
  • MDMS Recruiting
  • Hybrid2 days onsite, United States of America
Salary undisclosed

Apply on


Original
Simplified

***W2 or Self Inc ONLY***

The Manager of Security & Compliance will oversee Security and Compliance and will need to develop a multi-year roadmap and manage execution against it.

  • Hands-on manager with experience wearing a lot of hats.
  • Experience leading security for a business unit or division as part of a larger enterprise is a plus.
  • Experience with an understanding of business risk appetite and tolerance.
  • Experience engaging stakeholders to gain support
  • SaaS experience is a plus.
  • Experience managing and working with teammates across multiple time zones and continents is a plus.

The successful candidate will have experience in the following:

Develop and maintain strategy for SOC 2 Type 2 and PCI-DSS attestations. Work with audit support contractors to plan and execute audits.

  • Experience with PCI-DSS as a Service
  • Experience with PCI-DSS 4 is a plus.
  • Experience with SOC 2 Type 2 audits.

Work with the Chief Privacy Officer to maintain the business s data privacy program.

  • Experience with GDPR, CCPA/CPRA is a plus.
  • Experience leading privacy for a multinational SaaS product is a plus.

Lead product security efforts. Develop product security / SDLC strategy that includes SAST, DAST, and OSS scanning.

  • Experience with SAST, DAST, and OSS scanning.
  • Experience with Fortify On-Demand and Nexus IQ is a plus.
  • Experience with SDLC for security and integration with CI/CD pipelines is a
  • Experience with container security management is a plus.

Lead vulnerability management program.

  • Experience with industry-standard vulnerability tools.
  • Experience in evaluating vulnerabilities in a Linux
  • Experience developing metrics and tracking remediation.
  • Experience with Qualys suite is a plus.

Lead Incident Response process in collaboration with the NOC team.

  • Experience with structuring Incident Response process
  • Experience with Splunk is a plus.
  • Experience with CrowdStrike is a plus.

Lead Third-Party Risk Management program.

  • Experience with vendor assessments for SOC 2 and PCI.
  • Experience with GDPR sub-processor and controller transfer requirements.

Lead with RFP responses and customer engagement.

  • Experience with contract review.
  • Experience engaging customer security
  • Experience with Responsive is a plus.
  • Experience creating customer white papers is a plus.

Interested? Contact: Bruce Ormond

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job