
Director of Security Compliance
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Arizona, +1 more state.
• Oversee the compliance team tasked with managing Blue Yonder’s information security certifications and attestations.
• Establish the direction, priorities, and operating rhythms for compliance initiatives.
• Take ownership of the complete audit lifecycle, which includes scoping, control mapping, evidence gathering, control execution, auditor coordination, issue resolution, and final reporting.
• Supervise external auditors and certification organizations, managing scope, timelines, sampling, and outcomes.
• Develop and sustain shared cross-framework controls to minimize redundant evidence collection and audit fatigue.
• Enhance SOX / ITGC compliance in collaboration with Internal Audit, Finance, and control owners.
• Expand emerging frameworks, including ISO 42001 for AI management systems.
• Promote continuous compliance through automation, evidence pipelines, process enhancements, and GRC tools.
• Collaborate with Engineering, Product, Cloud Platform, Privacy, Legal, Internal Audit, and Customer Trust teams.
• Create reports for executives, customers, and regulators while assisting in customer audits.
• Equip Sales and Customer Trust with up-to-date attestations and evidence.
• Cultivate the compliance team through coaching, ownership, and career development.
• At least 10+ years of experience in security compliance, audit, or information security within an enterprise SaaS setting.
• Demonstrated leadership of a security compliance, IT audit, or GRC function in a complex, multi-product SaaS or tech environment.
• Direct management experience leading a team of compliance professionals.
• Extensive hands-on expertise in delivering ISO 27001, SOC 1, and SOC 2 audits.
• Experience overseeing certification bodies and audit firms end-to-end.
• Working knowledge of ISO 27701, ISO 22301, ISO 42001, and Sarbanes-Oxley / ITGC.
• Experience in developing, enhancing, or transforming compliance programs in cloud and/or SaaS settings.
• Proficiency in cloud technologies, with Microsoft Azure preferred, along with familiarity with AWS, GCP, and OCI.
• Understanding of cloud shared-responsibility models and their effect on control scope and evidence.
• Proficient in control frameworks and capable of aligning overlapping requirements into a cohesive control environment.
• Experience in utilizing automation, evidence pipelines, and GRC platforms to enhance audit readiness.
• Strong ability to influence cross-functionally with both technical and non-technical stakeholders.
• Excellent organizational and project management capabilities.
• Experience with GDPR and other data privacy frameworks is preferred.
• Familiarity with FedRAMP and U.S. public-sector security requirements is preferred.
• Knowledge of NIST SP 800-53 and the NIST Cybersecurity Framework is preferred.
• Experience in leading a geographically distributed compliance team is preferred.
• Relevant certifications such as CISA, CISM, CISSP, CIPP, ISO 27001 Lead Auditor / Lead Implementer, or equivalent are preferred.
• Experience in supply chain, logistics, and/or enterprise SaaS within an AI-driven product organization is preferred.
• Eligibility for an annual performance bonus or commission program.
• Comprehensive Medical, Dental, and Vision coverage.
• 401K with matching contributions.
• Flexible Time Off policy.
• Access to a Corporate Fitness Program.
• Voluntary benefits, including Legal Plans, Accident and Hospital Indemnity, and Pet Insurance.
• Initiatives focused on workplace inclusion and belonging.
• Support for professional, personal, educational, and volunteer opportunities.
• Commitment to work-life balance.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.