
Head of Trust and Security
Posted Jul 10

Posted Jul 10
This is a fully remote position, open to applicants in United States.
• Take charge of Filevine’s FedRAMP 20x Moderate strategy, delivery framework, certification readiness, and ongoing compliance posture.
• Spearhead the design and implementation of automation for FedRAMP evidence, continuous monitoring, and reporting essential for Marketplace certification and sustained authorization.
• Act as the primary point of contact for FedRAMP engagements with 3PAOs, the FedRAMP PMO, agency stakeholders, and internal executive sponsors.
• Establish the roadmap and priorities for dedicated FedRAMP engineering resources, ensuring that regulatory requirements are transformed into deployed technical controls, automated evidence, and sustainable operational processes.
• Oversee POA&M governance, risk acceptance workflows, certification readiness reporting, and remediation planning across product and platform teams.
• Ensure that FedRAMP implementations are practical, risk-based, technically sound, and appropriately aligned with Filevine’s architecture, maturity, and business objectives.
• Deliver clear and consistent executive reports on progress, risks, trade-offs, dependencies, resource requirements, and certification readiness.
• Manage governance for vulnerability findings from scanning tools, penetration tests, customer evaluations, audits, and bug bounty programs, including risk adjustment, remediation responsibility, escalation, and executive trade-off decisions.
• Maintain a comprehensive source of truth for security/compliance status, control gaps, remediation commitments, and customer-facing trust claims.
• Ensure the accuracy, currency, and defensibility of trust center materials, customer security responses, sales enablement messaging, and public compliance claims.
• Convert privacy obligations and customer commitments into product, engineering, and operational requirements.
• Support AI and data governance initiatives by ensuring that privacy, security, and customer trust requirements are integrated into product and operational decisions.
• Foster alignment between compliance goals, engineering capabilities, product strategy, customer commitments, and business risk.
• Bachelor’s degree or equivalent practical experience.
• Over 10 years of experience in security compliance, GRC, product/program leadership, privacy, trust, or similar roles within SaaS, cloud, or high-trust technology environments.
• Direct ownership of FedRAMP Moderate, FedRAMP High, FedRAMP 20x, or a similar federal cloud authorization program.
• Demonstrated experience in translating regulatory, security, and privacy requirements into technical implementation plans in collaboration with engineering teams.
• Proven track record of leading complex, cross-functional initiatives with executive visibility, ambiguous requirements, and multi-quarter delivery timelines.
• Experience collaborating with security engineering, infrastructure, product, legal, audit, and customer-facing teams.
• Extensive knowledge of FedRAMP, NIST 800-53, FedRAMP 20x automation concepts, continuous monitoring, POA&M governance, 3PAO engagement, and federal cloud authorization processes.
• Strong understanding of security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, PCI-DSS, and customer security review procedures.
• In-depth knowledge of privacy operations, consent management, data governance, DSR workflows, subprocessors, DPAs, retention, and privacy-by-design methodologies.
• Ability to convert regulatory and security requirements into actionable, value-driven product and engineering activities.
• Exceptional product and program management skills, including roadmap development, prioritization, milestone definition, and executive reporting.
• A practical, analytical approach to risk management and decision-making in dynamic environments.
• Excellent stakeholder management, written communication abilities, and executive presence.
• Comfortable working with dedicated engineering resources while remaining accountable for prioritization, clarity, outcomes, and risk-based trade-offs.
• Medical, Dental, & Vision Insurance (for full-time employees)
• Competitive & Fair Pay
• Maternity & paternity leave (for full-time employees)
• Short & long-term disability
• Opportunity to learn from a dedicated leadership team
• Top-of-the-line company swag
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.