Responsibilities
- Manage the SOC 2 Type II program end-to-end, including control operations, evidence collection, auditor relationships, and report delivery.
- Lead ISO 27001 certification from initiation to completion, including scoping the ISMS, remediating gaps, selecting an auditor, and achieving certification.
- Oversee AI governance across the organization, covering both product-embedded and internally adopted AI, maintaining an AI inventory and risk register, setting usage policies, and preparing for ISO 42001 after ISO 27001 certification.
- Manage policy, risk, and third-party governance, including the policy lifecycle, risk register, vendor assessments, security awareness training, and serving as the primary contact for customer security questionnaires and internal audits.
- Set governance standards for identity and access, including access review cadence, joiner-mover-leaver processes, and audit-trail integrity, while coordinating with partner teams on day-to-day operations.
- Build and lead a distributed team, overseeing two direct reports in Bangladesh, and hire, develop, and set program execution standards as the team grows.
- Direct compliance automation strategy by partnering with a GRC engineer to determine automation priorities and validate that automated controls enforce their intended requirements.
- Participate in a team-based security escalation rotation alongside the Director and other US staff, responding to genuine signals filtered by managed detection systems.
Requirements
- Personally led an ISO 27001 implementation to certification or built a SOC 2 Type II program from scratch and completed credible 27001 gap analysis.
- Owned a compliance or GRC program end-to-end at a company with real enterprise customers.
- Interacted directly with auditors and responded to customer security questionnaires, not just maintained a control library.
- Comfortable reading technical control evidence and having detailed conversations with engineers about system operations.
- Able to evaluate compliance automation and determine whether the control it claims to enforce is genuinely enforced.
- Capable of reading an AI system's data flows to understand what data reaches a model, where it goes, and who can retrieve it.
- Directly managed security, GRC, or compliance professionals for two or more years, including hiring and performance management.
- Has a clear point of view on which security work should be automated and which should not.
- Managed a team across time zones and can describe how a narrow daily overlap window was used and how asynchronous work was handled.
Benefits
- Exposure to cutting-edge technologies to solve meaningful problems
- Collaborative, values-driven culture that balances rigor with innovation
- Unlimited paid time off
- Annual vacation bonus – a bonus to take paid time off
- Individualized growth and development plans
- Strong values around work/life balance
- Community involvement opportunities
- Competitive benefits including medical, dental, vision, paid parental leave, and 401K