We are seeking a highly motivated and experienced Head of Information Security and Compliance to lead our efforts in ensuring the security and compliance of our systems and data, with a focus on meeting the needs of our customers. In this role, you will be responsible for the overall strategy and execution of our information security and compliance program. You will work closely with our internal IT and operations teams to develop and implement security policies and procedures, and you will also be responsible for conducting and overseeing external audits to ensure compliance with SOC2 and GDPR. This role requires a leader who can not only strategize but also execute and collaborate effectively across teams.
What you will do:
Serve as the primary point of contact and subject matter expert for customers regarding security and compliance inquiries.
Develop, implement, and maintain a comprehensive information security and compliance program that meets the needs of our customers and complies with relevant regulations, including SOC2 and GDPR.
Lead and mentor a team (if applicable) responsible for implementing and maintaining security controls.
Work closely with internal IT and operations teams to ensure that security controls are integrated effectively into our systems and processes.
Oversee regular security assessments and audits to identify vulnerabilities and ensure compliance.
Manage and oversee external audits for SOC2 and GDPR compliance, including vendor selection and due diligence and performance management.
Stay up-to-date on the latest security threats, vulnerabilities, and regulatory changes.
Develop and deliver security awareness training to employees.
Report regularly to senior management on the status of the information security and compliance program.
Take ownership of our infosec related obligations for each customer including monitoring and tracking
Own Tech Solutions related to InfoSec when adopted and implemented
Requirements
What you Bring:
Bachelors degree in computer science, information security, or a related field.
7+ years of progressive experience in information security and compliance, with demonstrated leadership experience.
Deep understanding of security frameworks and regulations, including SOC2, GDPR, and other relevant standards.
Proven experience in developing and implementing information security and compliance programs.
Experience managing security assessments, audits, and penetration testing.
Excellent communication, interpersonal, and presentation skills, with the ability to effectively communicate complex technical information to both technical and non-technical audiences.
Ability to work independently and as part of a team, and to lead and motivate others.
Bonus Points:
Masters degree in a related field.
Experience working in a cloud-based environment.
Experience with ChromeOS and Windows operating systems.
Relevant certifications, such as CISSP, CISM, or CCSP.