Job Description
Summary
What you'll do
- Oversee Privacy and Compliance Frameworks:
- Oversee GDPR compliance practices and drive certification efforts with TrustArc/eTrust, a leading privacy compliance governance certifier.
- Design and execute privacy and security programs aligned with regulatory frameworks (e.g., SOC2, GDPR, ISO 27001).
- Lead security and privacy program initiatives collaboratively across teams.
- Act as a point of contact for privacy-related inquiries and audits.
- Manage Security Protocols:
- Develop and implement security protocols to ensure data integrity and protection.
- Conduct system security audits and penetration testing.
- Define access control measures, encryption standards, and secure data transfer protocols.
- Technical Leadership:
- Lead vulnerability assessments and remediation strategies.
- Collaborate with engineering teams to integrate privacy-by-design and security-by-design principles.
- Develop Training Programs:
- Establish company-wide privacy and security training initiatives.
- Stay current with evolving regulations and security threats, adapting strategies accordingly.
What we’re looking for
- Bachelor’s or Master’s degree.
- 4-8 years of experience driving security/privacy engineering, business practices, and programs in a fintech SaaS or HRIS/payroll platform.
- Proven track record managing GDPR, SOC2, or ISO 27001 implementations.
- Strong understanding of encryption, authentication, and network security.
- Familiarity with compliance management platforms like TrustArc or Drata.
- Excellent written and verbal communication skills with the ability to simplify complex ideas for diverse audiences.
Certificates preferred
- Certified Information Systems Security Professional (CISSP).
- Certified Information Privacy Professional (CIPP/E, CIPP/US)ISO 27001.
- Lead Implementer certification.
Skills
- Communications Skills
- Legal Consulting
- Team Collaboration