Experience Required: 10+ years in Information Security, Compliance, andcross-functional leadership
About the Role:
We are an enterprise SaaS company in the Fintech domain,catering to clients across multiple geographies and aspiring to become a trulyglobal platform. To achieve this vision, we are seeking a dynamic andexperienced Associate Director - Information Security and Compliance tolead our security and compliance initiatives. This role is pivotal in ensuringour platform is secure, compliant with global regulations, and aligned withbusiness goals.
Key Responsibilities:
Information Security and Compliance Leadership:
Lead the development and implementation of security and compliance frameworks (e.g., ISO 27001, SOC 2, GDPR, CCPA).
Oversee risk management processes, audits, and incident response plans.
Ensure adherence to regional regulatory requirements, including financial compliance standards like PSD2, AML, and KYC.
Driving Cross-Functional Initiatives:
Collaborate with developers, DevOps, IT, and HR teams to integrate security and compliance into all workflows.
Serve as a bridge between technical teams and operational departments, translating regulatory requirements into actionable tasks.
Program Management and Execution:
Design and execute company-wide security and compliance programs, ensuring timely and efficient delivery.
Monitor program progress, resolve challenges, and report outcomes to leadership.
Security and Compliance Culture Advocacy:
Drive a security-first mindset across the organization through training programs and awareness campaigns.
Embed secure coding and DevSecOps practices into the software development lifecycle.
Automation and Tools Integration:
Work with DevOps to implement automated compliance checks within CI/CD pipelines.
Leverage tools and technologies for monitoring, incident detection, and risk mitigation.
Key Skills and Qualifications:
Technical Expertise:
Strong knowledge of cloud security (AWS, Azure, GCP) and SaaS architectures.
Proficiency in security tools and practices, including DevSecOps and infrastructure-as-code (e.g., Terraform).
Familiarity with application security tools (e.g., static and dynamic analysis).
Compliance Knowledge:
Experience with global data privacy regulations (e.g., GDPR, HIPAA, PCI-DSS) and financial compliance standards.
Hands-on experience managing certifications and audits.
Leadership and Collaboration:
Proven ability to lead cross-functional teams, influencing without direct authority.
Strong stakeholder management skills, with experience aligning security goals with business priorities.
Communication and Advocacy:
Exceptional ability to communicate complex security topics to diverse audiences.
Skilled in building consensus and fostering a collaborative culture.
Preferred Certifications:
CISSP, CISA, CISM, CIPM, or similar certifications.