We're looking for an experienced information security compliance leader to build and run a lean, audit-ready program. The foundation is in place. You will take full ownership and run it your way. You will own two big rocks: Own security compliance end-to-end Plan and run gap assessments, control design, evidence collection, and auditor coordination (SOC 2 Type II; ISO/IEC 27001:2022) Operate and improve our ISMS (risk assessment, internal audit, management review, corrective actions) Maintain policies, control testing cadence, asset inventories, and audit-ready evidence (e.g., Secureframe/Vanta) Lead vendor risk management and third-party due diligence Own security questionnaires & customer trust Own RFPs/DDQs/security questionnaires (SIG Lite, CAIQ, and custom) with clear SLAs Meet with customer security teams to explain security controls Build a living answers library and artifacts (policies, diagrams, pen test reports, BCP/DR, vulnerability management posture) Stand up and maintain a trust portal Partner with Sales/Legal/Security to unblock deals and negotiate security addenda Additional Impact: Translate frameworks into lightweight, automated processes that fit a high-velocity startup Track and report meaningful compliance/risk metrics to leadership Help hire/mentor as the program scales
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed
Number of Employees
11-50 employees