About the Role
Role details below.
Responsibilities
- Establish security and compliance priorities and roadmaps aligned with Digital department risk and objectives
- Design, implement, and own a comprehensive compliance program, including policies, procedures, control frameworks, and training materials
- Provide strategic direction for application security practices, including secure SDLC, shift-left, and penetration testing
- Develop and track key metrics to measure program maturity and report progress to Digital leadership
- Coordinate and manage audit activities with third-party audit partners
- Partner with Legal to interpret regulatory requirements and translate them into actionable engineering and operational controls
- Drive security awareness initiatives across the broader organization
- Represent Great Minds interests in relevant industry groups or associations
Requirements
- 7+ years of experience in information security, compliance, or related field
- 3+ years in a leadership or management role
- 3+ years working in a SaaS (software-as-a-service) product environment, preferably in a security or engineering oriented role
- 2+ years managing third-party audits and vendor security assessments
- Demonstrated experience building or significantly maturing a compliance program
- Proven experience with compliance frameworks such as SOC 2, NIST, ISO 27001, or similar
- Excellent written and verbal communication skills, with the ability to translate technical risk into business terms
- Able to effectively collaborate cross-functionally amongst engineering, product, legal, HR, and corporate IT functions
- Familiarity with cloud security in AWS environments
- Bachelor’s degree
Nice to Have
- 2+ years working with GRC tooling and/or security automation
- Strong working knowledge of K-12 education privacy regulations (FERPA, COPPA, state student data privacy laws)
- Master’s degree preferred
Compensation
The expected base salary range for this position is $167,000-$183,000, however the offered salary may be higher or lower than the above range dependent on numerous factors including, but not limited to location, work experience, skills and internal equity considerations. The base salary is not inclusive of benefits or other incentives.
Work Arrangement
Remote (Worldwide)
Additional Information
- A cover letter and resume are required to be considered for this position.
- New employees will be required to successfully complete a background check.
- Any communication to appli