About the job
Join our dynamic team as a Security Officer, where you will spearhead security, privacy, and compliance initiatives for our SaaS products and client projects. You will take ownership of this critical function from inception through implementation, certification, and continuous monitoring. Your role will be pivotal in securing client and company data, establishing trust through exceptional security and privacy practices.
As a Security Officer, your responsibilities will encompass audit readiness, compliance with privacy requirements, and the establishment of standards, processes, and tools necessary for an effective security and privacy program.
Key Responsibilities:
- Leadership: Direct our security program across SaaS products and client initiatives, defining strategy, priorities, and measurable outcomes.
- Certifications: Oversee SOC 2 Type II, ISO 27001, and ISO 42001 readiness and compliance, including control design, evidence processes, and auditor coordination. Manage ISMS and AI governance documentation.
- Privacy: Lead privacy governance and operational practices, ensuring compliance with HIPAA, GDPR, and CCPA/CPRA, focusing on data handling, contractual privacy terms, and privacy by design principles.
- SDLC: Collaborate with delivery teams to integrate security and privacy into development processes, with clear expectations, practical review gates, and patterns to address common risks.
- Project Delivery: Create a repeatable client engagement security plan addressing environment segregation, access provisioning and deprovisioning, client data management, and incident coordination.
- Third Party Risk: Lead vendor security evaluations, including due diligence for critical providers, remediation tracking, and continuous monitoring.
- Customer Assurance: Assist in customer assurance efforts, including security questionnaires, RFPs, and maintaining trust artifacts and standard responses.
- Incident Response: Maintain an incident response program and implement improvements post-incident.
- Culture: Foster a culture of security and privacy through clear guidance, streamlined training, and daily collaboration with teams.

