
Senior Director, Information Security and Compliance
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Take ownership of and enhance the maturity of Foundant's information security and GRC program from start to finish.
• Establish the strategic security and compliance roadmap for five products across all regions served.
• Lead and mentor the Head of Technical Security and Head of GRC.
• Align the technical security and GRC teams to focus on risk reduction and fostering a security-first culture.
• Act as Foundant's executive representative during security incidents.
• Engage with clients, leadership, and regulatory bodies during incidents.
• Develop and refine GRC policies, risk registers, control frameworks, and audits.
• Ensure adherence to regulatory requirements in the US, Canada, Europe, the UK, and Australia.
• Collaborate with Product and Engineering leaders to integrate security and privacy by design across all product offerings.
• Create and deliver security and compliance metrics to executive leadership and the Board.
• Convert technical risks into business impacts and prioritize them effectively.
• Manage third-party and vendor risk assessments.
• Represent Foundant's security posture to clients and prospects during enterprise sales processes, security evaluations, and due diligence inquiries.
• Perform additional duties as assigned.
• Over 8 years of progressive leadership experience in information security and/or governance, risk, and compliance (GRC).
• Proven experience in leading both technical security and compliance functions.
• Background in establishing or enhancing a security and compliance program for a multi-product SaaS organization.
• Familiarity with international regulatory and compliance frameworks, such as GDPR, UK GDPR, Australian Privacy Act, SOC 2, and ISO 27001.
• Experience in managing security incident response programs.
• History of serving as a public or client-facing spokesperson during incidents.
• Experience in managing and developing senior technical and compliance personnel.
• CISSP, CISM, or CRISC certification is preferred, though not mandatory.
• No specific degree requirement; relevant professional experience is accepted.
• Must have legal eligibility to work in the United States.
• Competitive salary and benefits package.
• Tuition reimbursement opportunities.
• Lifestyle reimbursement programs.
• Customized mindfulness initiatives.
• Tailored fitness initiatives.
• Flexible paid time off (PTO) policy.
• Opportunities for professional and personal development.
• Collaboration across teams, allowing exposure to diverse ideas, expertise, and projects.
• Opportunities for career growth and internal mobility.
• Autonomy and responsibility in your role.
• Employee recognition initiatives.
• Workplace accommodations during the interview and employment processes.
GardaWorld Federal Services
Cherokee Federal
FRSecure
Synack, Inc.
Get handpicked remote jobs straight to your inbox weekly.