
Director of Security – Compliance
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Oversee StrongMind’s security and compliance initiatives, which encompass SOC 2, student data privacy, access governance, third-party risk management, incident preparedness, and AI governance.
• Manage the SOC 2 program comprehensively, including defining scope, designing controls, collecting evidence, maintaining auditor relationships, and facilitating Type I and Type II attestations along with annual reattestations.
• Collaborate on security and compliance measures across IT Operations and Engineering departments.
• Develop and uphold access governance policies concerning provisioning, access reviews, and revocation processes.
• Handle compliance obligations related to COPPA, FERPA, state student privacy regulations, and public records responsibilities in collaboration with the Legal team.
• Create and sustain a risk-based vendor and third-party risk management strategy.
• Assess the internal security stance, focusing on cloud security issues, corporate SaaS security, and defensive readiness.
• Formulate and maintain incident response protocols, breach preparedness plans, runbooks, and tabletop exercise routines.
• Collaborate with the AI committee and Data Science team to ensure responsible governance of AI initiatives.
• Direct contracted security personnel, including vCISO or specialized support services.
• Establish ongoing processes for vendor risk assessments, access reviews, evidence gathering, control oversight, and leadership reporting.
• Deliver clear, actionable risk assessments to leadership.
• Facilitate collaboration among teams to transform policies and requirements into practical operational processes.
• Influence the security strategy and enhance security and compliance capabilities as the organization expands.
• Proven experience in managing and operating a security and compliance program, ideally having completed at least one SOC 2 attestation from inception to final report.
• Strong grasp of security controls, compliance frameworks, risk management practices, and audit methodologies.
• Capability to coordinate controls and instill accountability across teams without direct management responsibility.
• Experience in supervising contractors, consultants, vCISOs, or other external security resources.
• Background in K–12 education, educational technology, or another highly regulated data environment.
• In-depth knowledge of student privacy regulations, including COPPA and FERPA, or similar privacy and regulatory standards.
• Experience in developing security and compliance initiatives from the ground up and converting policies into repeatable operational procedures.
• Excellent communication, organizational, and project management abilities.
• Ability to engage effectively with both technical and non-technical stakeholders.
• Skill in identifying risks, articulating potential impacts, and implementing practical mitigation strategies.
• Willingness and capability to expand a security and compliance function.
• Direct experience in EdTech or familiarity with state student privacy laws and statewide data privacy agreements is preferred.
• Experience with compliance automation tools such as Vanta, Drata, Delve, or similar tools is an added advantage.
• Familiarity with cloud security posture management tools like Wiz or comparable platforms is a preferred bonus.
• Experience supporting GDPR compliance or international privacy initiatives is a plus.
• Possession of security or compliance certifications such as CISSP, CISM, CISA, or similar credentials is preferred.
• Experience in governing AI systems or assessing AI vendors within a regulated data environment is an added advantage.
• Must have eligibility to work in the United States.
• Visa sponsorship is not available.
• A competitive total compensation package, which includes medical, dental, vision, and optional benefits.
• On-site gym facilities.
• Virtual wellness programs.
• Wellness coaching services.
• Flexible work arrangements for certain roles.
• Unlimited paid time off for salaried positions.
• "Life happens" days off.
• A fully paid week off during the Christmas holiday.
• Recognition and rewards for birthdays, significant anniversary milestones, and community service contributions.
• Quarterly Town Hall meetings.
• Annual social events and traditions, including Halloween celebrations and Wellness Fairs.
RTX
Finalsite
EXALTA Group
Auto Approve
Get handpicked remote jobs straight to your inbox weekly.