
Director, Security & Compliance
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in Minnesota.
• Take ownership of the renewal and ongoing operation of the SOC 2 Type II report, acting as the main liaison to the audit firm.
• Enhance the control environment and minimize manual evidence collection processes.
• Create, document, and implement controls that are in line with SOC 2 Type II, HIPAA, PCI, and GDPR/CCPA standards.
• Collaborate directly with auditors to ensure continuous compliance.
• Broaden the company's attestation scope as necessary.
• Act as the primary point of contact for customer security assessments, questionnaires, and due diligence inquiries.
• Oversee the security policy suite, risk register, and incident response strategy.
• Conduct tabletop exercises.
• Establish standards for data classification, retention, and access control.
• Collaborate with engineering on implementing least-privilege access, encryption, and data lifecycle management.
• Develop and enforce secure software development lifecycle policies and environmental and physical security standards.
• Manage vendor and third-party risk, including evaluations of SaaS and AI tools.
• Support the Legal team with security and data privacy contract negotiations.
• Construct the company’s AI governance framework, encompassing acceptable use policies, model/vendor risk assessments, and oversight of AI data management.
• Monitor emerging AI standards and translate them into actionable controls.
• Collaborate with product and engineering teams on responsible AI practices.
• Provide security and compliance insights regarding shadow AI risks.
• Advise the executive team and board on security and compliance matters.
• Work alongside Sales and Customer Success during enterprise transactions.
• Expand the security and compliance function within the organization.
• Bachelor’s degree in Computer Science, Information Security, or a related discipline.
• Over 6 years of experience in security, compliance, IT/GRC, or risk management.
• A minimum of 2 years managing a SOC 2 program on a daily basis, including evidence gathering, control oversight, and auditor relations.
• Direct, hands-on experience with operating and renewing an existing SOC 2 Type II program.
• Proficient understanding of data governance practices, including classification, retention, access review, and compliance with CCPA/GDPR.
• Familiarity with AI governance concepts and frameworks such as NIST AI RMF, OWASP LLM Top 10, and ISO 42001.
• Experience in drafting policies and configuring compliance automation tools.
• Excellent written and verbal communication skills.
• Familiarity with compliance automation platforms like Vanta, Drata, Secureframe, or similar tools.
• Skills in vendor and third-party risk assessment and management.
• Ability to establish credibility with enterprise customers and prospects regarding security and trust issues.
• Candidates must reside in the United States.
• This position is not eligible for visa sponsorship.
• Preferred qualifications: CISSP, CISM, CIPP, or CISA certifications.
• Preferred: Experience in achieving or maintaining ISO 27001 or ISO 42001 standards.
• Flexible, work-from-anywhere model.
• 401(k) plan with both deferred and Roth options.
• Employer matching contribution of 50% up to a maximum of 4.5% of gross pay.
• Comprehensive medical plans with co-pay or HSA coverage options.
• Dental and vision insurance plans.
• Daycare and Medical FSA/HSA options.
• $50,000 group term life insurance coverage.
• Generous paid time off (PTO) policies.
• Employee Assistance Program (EAP).
• Additional life insurance options.
• Critical illness and accident insurance, as well as cancer and hospital indemnity coverage.
• Legal/ID Shield services.
• Pet insurance available.
• Paid family or medical leave where applicable under state regulations.
• Four weeks of paid paternity leave after one year of employment, with partial eligibility starting at six months in states that do not have a state program.
• Twelve weeks of paid leave for the birth parent, subject to eligibility criteria.
Compre Group
Ankura
WVU Medicine
McKesson
Get handpicked remote jobs straight to your inbox weekly.