Principal Compliance Specialist

April 30

Apply Now
LastPass logo

LastPass

LastPass manages your passwords and online life, so you don’t have to.

Password Management • Identity Management • Single Sign-On • SaaS • Cloud

501 - 1000

Description

• We are seeking a qualified GRC candidate to join our Security and Privacy GRC Team as a Principal Compliance Specialist. This position is pivotal for stakeholder engagement, decision support, and assurance activities across both product and enterprise functions. Our mission within the GRC team is to foster a unified environment that promotes effective and efficient risk management. This not only builds customer trust but also encourages innovation and seamlessly integrates governance into business workflows. • This individual will bridge the gap between compliance and code, embedding regulatory requirements directly into the fabric of our software development lifecycle. You will be instrumental in evolving our compliance practices to be as agile and automated as our development processes. • If you are passionate about complex problem solving and motivated by scale, then this is the role for you! • Who will you work with? - Internal teams, especially software engineering and DevOps to advance cybersecurity initiatives, ensuring alignment with our comprehensive controls library and internal mapping for consistent and efficient reporting. - Organizational Leadership as we measure and report on our ISPMS program. - Strategic customers and partners via escalated security and data protection queries, providing necessary consultancy and support. • What are some of the exciting challenges you will be working on? - Collaborate with engineering and business stakeholders to advance cybersecurity and privacy initiatives. - Perform assurance and audit tasks to facilitate continuous control reporting, monitoring, and management. - Assist in the preparation and execution of both external and internal audit activities. - Respond to security and data protection queries from customers and partners, providing necessary consultancy and support. - Develop and implement compliance-as-code and governance-as-code frameworks within the organization's DevOps and software development practices. - Work directly with software engineering teams to integrate compliance requirements into the CI/CD pipeline. - Advocate for and lead the adoption of tools and processes that support automation and continuous compliance in a dynamic engineering environment. - Facilitate the transformation of compliance policies into executable code, ensuring that compliance checks are built into the early stages of the software development process. - Drive initiatives that support high-level interface between GRC and software engineering functions, ensuring seamless communication and understanding.

Requirements

• Proven work experience in a GRC function. • Proven track record of implementing compliance-as-code and governance-as-code in a complex software development environment in accordance with standards such as OWASP Top 10 and/or SLSA. • Deep understanding of software development lifecycles, agile methodologies, and DevOps practices. • Expertise in Code Security and Compliance Standards. • Proven experience in cybersecurity GRC functions and working knowledge of cybersecurity frameworks (e.g., ISO 27001, SOC 2, NIST-CSF, NIST 800-53, CIS).

Benefits

• Market-leading password manager • High-growth, collaborative environment with inclusive teams • Remote first culture • Competitive compensation • Flexible Paid time off policies including but not limited to: Monthly self-care days (12 extra paid days off annually), volunteering days • Generous Parental leave • Comprehensive health coverage, dependents included • Home office setup support • LastPass families free account up to 5 members • Continuous learning and development opportunities

Apply Now
Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@remoterocketship.com
Jobs by Title
Remote Account Executive jobsRemote Accounting, Payroll & Financial Planning jobsRemote Administration jobsRemote Android Engineer jobsRemote Backend Engineer jobsRemote Business Operations & Strategy jobsRemote Chief of Staff jobsRemote Compliance jobsRemote Content Marketing jobsRemote Content Writer jobsRemote Copywriter jobsRemote Customer Success jobsRemote Customer Support jobsRemote Data Analyst jobsRemote Data Engineer jobsRemote Data Scientist jobsRemote DevOps jobsRemote Ecommerce jobsRemote Engineering Manager jobsRemote Executive Assistant jobsRemote Full-stack Engineer jobsRemote Frontend Engineer jobsRemote Game Engineer jobsRemote Graphics Designer jobsRemote Growth Marketing jobsRemote Hardware Engineer jobsRemote Human Resources jobsRemote iOS Engineer jobsRemote Infrastructure Engineer jobsRemote IT Support jobsRemote Legal jobsRemote Machine Learning Engineer jobsRemote Marketing jobsRemote Operations jobsRemote Performance Marketing jobsRemote Product Analyst jobsRemote Product Designer jobsRemote Product Manager jobsRemote Project & Program Management jobsRemote Product Marketing jobsRemote QA Engineer jobsRemote SDET jobsRemote Recruitment jobsRemote Risk jobsRemote Sales jobsRemote Scrum Master + Agile Coach jobsRemote Security Engineer jobsRemote SEO Marketing jobsRemote Social Media & Community jobsRemote Software Engineer jobsRemote Solutions Engineer jobsRemote Support Engineer jobsRemote Technical Writer jobsRemote Technical Product Manager jobsRemote User Researcher jobs