
Director, Security Compliance, Trust
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in United States.
• Develop and oversee the security compliance and trust function at Motive.
• Take charge of governance, risk, and compliance, including auditing and certification for ISO 27001/27701, SOC 1, SOC 2, PCI DSS, and the progression towards FedRAMP.
• Manage privacy and data protection, foster customer trust, create security policies, conduct training, assess human risk, and govern AI practices.
• Lead a small, senior, globally distributed team, overseeing organizational design, recruitment, and worldwide team development.
• Draft policies, design controls, engage in audit fieldwork, and address complex inquiries from customers.
• Construct an integrated control framework aligning ISO 27001/27701, SOC 1, SOC 2, PCI DSS, FedRAMP, GDPR, and CCPA/CPRA.
• Manage the annual audit calendar and nurture relationships with auditors and assessors.
• Direct Motive's journey towards FedRAMP compliance.
• Supervise privacy compliance operations, encompassing data subject rights, DPIAs, ROPA, and mechanics for cross-border transfers.
• Prepare regulatory readiness for new markets and collaborate on data residency and regional architecture.
• Represent Motive's security and privacy stance to customers, oversee trust.gomotive.com, and lead responses to security questionnaires and enterprise escalations.
• Create automation for evidence collection, continuous control monitoring, and AI-aided questionnaire responses.
• Manage the security policy and standards library, handle the exceptions process, conduct security training, simulate phishing attacks, and measure human risk.
• Establish AI governance for both product and internal AI applications according to ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act.
• Report to the CISO and collaborate with Legal, Engineering, Product, IT, Finance, Sales, and Customer Success teams.
• Over 8 years of experience in security compliance, GRC, privacy, audit, or risk management.
• More than 5 years in leadership roles, overseeing both people managers and senior individual contributors.
• Proven hands-on experience in writing policies, designing controls, creating control mappings, participating in audit fieldwork, and responding to customer inquiries.
• Established ownership of multi-framework compliance programs at scale within a cloud-native SaaS setting.
• Core expertise in ISO 27001, SOC 1, SOC 2, and PCI DSS.
• Extensive operational privacy experience, particularly with GDPR and CCPA/CPRA.
• Direct involvement in DSAR operations, DPIAs, ROPA, and cross-border transfer mechanics.
• Experience in establishing compliance and privacy in new international markets, ideally including Canada, the EU, Mexico, or Latin America.
• Familiarity with PIPEDA/Law 25, LGPD, or Mexican LFPDPPP is a significant advantage.
• Experience with FedRAMP, ideally having guided an organization through the authorization process or Moderate/High readiness.
• Concrete, demonstrated application of AI in compliance-related tasks.
• Proven ownership of customer-facing trust functions, including security reviews, questionnaires, trust portals, and enterprise escalations.
• Experience in leading globally distributed teams across various time zones.
• Working knowledge of AI governance frameworks.
• Experience supporting IPO readiness, SOX, or equivalent regulatory scrutiny is highly preferred.
• Familiarity with handling sensitive personal data at scale is highly preferred.
• CIPP/E, CIPP/US, or CIPM certifications are a plus.
• Applicants must be authorized to receive and access commodities and technologies regulated under U.S. Export Administration Regulations.
• Applicants must be authorized to access Motive products and technology.
• Comprehensive health benefits.
• Pharmacy care benefits.
• Optical care benefits.
• Dental care benefits.
• Paid time off.
• Sick leave.
• Short-term disability coverage.
• Long-term disability coverage.
• Life insurance.
• 401k contribution.
• Restricted stock units may be part of total compensation for specific roles.
• Some interviews or training sessions for new hires may take place in person at one of Motive's global offices.
Otsuka Pharmaceutical Companies (U.S.)
Renovo Solutions
Lifelancer
GCG Official
Get handpicked remote jobs straight to your inbox weekly.