Head of Trust and Security

🕒 il y a 26 jours

🇺🇸 États-Unis – Télétravail

💵 $190 000 - $210 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Filevine

Filevine

201 - 500 employés

☁️ SaaS

⚖️ Juridique

🤖 Intelligence artificielle

💰 €108 000 000 Series D en 2022-04

SaaS • Legal • Artificial Intelligence

Filevine est une plateforme technologique juridique complète qui offre une large gamme de services adaptés aux cabinets d'avocats et aux praticiens du droit. La plateforme propose des solutions de gestion de cas, de gestion de documents et de gestion de contrats, ainsi que la gestion des leads et des analyses commerciales. En utilisant des technologies avancées d'IA, Filevine améliore le flux de travail juridique avec des outils tels que DemandsAI, ImmigrationAI et FilevineAI pour automatiser les tâches et améliorer la productivité. Elle s'intègre parfaitement avec les outils populaires comme QuickBooks et Gmail, assurant une pile technologique juridique complète. Filevine offre également des capacités de signature électronique, des fonctionnalités de gestion du temps et de la facturation, et un portail client pour faciliter la communication. La plateforme est utilisée par divers types de pratiques juridiques, y compris les dommages corporels, le droit de la famille, les recours collectifs, et plus, et est reconnue pour ses normes de sécurité robustes et ses certifications de conformité telles que SOC 2 Type II et HIPAA.

Description

• Own Filevine’s FedRAMP 20x Moderate strategy, delivery plan, certification readiness, and ongoing compliance posture. • Lead the design and execution of FedRAMP evidence automation, continuous monitoring, and reporting required for Marketplace certification and sustained authorization. • Serve as the single-threaded owner for FedRAMP engagements with 3PAOs, the FedRAMP PMO, agency stakeholders, and internal executive sponsors. • Set the roadmap and priorities for dedicated FedRAMP engineering resources, ensuring regulatory requirements become shipped technical controls, automated evidence, and operationally sustainable processes. • Own POA&M governance, risk acceptance workflows, certification readiness reporting, and remediation planning across product and platform teams. • Ensure FedRAMP implementations are pragmatic, risk-based, technically grounded, and appropriately scoped for Filevine’s architecture, maturity, and business priorities. • Provide clear, consistent executive reporting on progress, risk, tradeoffs, dependencies, resourcing needs, and certification readiness. • Drive governance for vulnerability findings from scanning tools, penetration tests, customer reviews, audits, and bug bounty programs, including risk adjustment, remediation ownership, escalation, and executive tradeoff decisions. • Maintain a single source of truth for security/compliance status, control gaps, remediation commitments, and customer-facing trust claims. • Ensure trust center materials, customer security responses, sales enablement messaging, and public compliance claims are accurate, current, and defensible. • Translate privacy obligations and customer commitments into product, engineering, and operational requirements. • Support AI and data governance efforts by ensuring privacy, security, and customer trust requirements are reflected in product and operational decisions. • Drive alignment between compliance goals, engineering capacity, product strategy, customer commitments, and business risk.

🎯 Exigences

• Bachelor’s degree or equivalent practical experience. • 10+ years of experience in security compliance, GRC, product/program leadership, privacy, trust, or related roles within SaaS, cloud, or high-trust technology environments. • Direct ownership of FedRAMP Moderate, FedRAMP High, FedRAMP 20x, or a comparable federal cloud authorization program. • Proven experience translating regulatory, security, and privacy requirements into technical implementation plans with engineering teams. • Experience leading complex, cross-functional initiatives with executive visibility, ambiguous requirements, and multi-quarter delivery timelines. • Experience partnering with security engineering, infrastructure, product, legal, audit, and customer-facing teams. • Deep knowledge of FedRAMP, NIST 800-53, FedRAMP 20x automation concepts, continuous monitoring, POA&M governance, 3PAO engagement, and federal cloud authorization workflows. • Strong working knowledge of security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, PCI-DSS, and customer security review processes. • Strong working knowledge of privacy operations, consent management, data governance, DSR workflows, subprocessors, DPAs, retention, and privacy-by-design practices. • Ability to translate regulatory and security requirements into actionable, value-driven product and engineering work. • Strong product and program management expertise, including roadmap development, prioritization, milestone definition, and executive reporting. • Pragmatic, analytical approach to risk management and decision-making in fast-paced environments. • Excellent stakeholder management, written communication, and executive presence. • Comfort operating with dedicated engineering resources while remaining accountable for prioritization, clarity, outcomes, and risk-based tradeoffs.

🏖️ Avantages

• Medical, Dental, & Vision Insurance (for full-time employees) • Competitive & Fair Pay • Maternity & paternity leave (for full-time employees) • Short & long-term disability • Opportunity to learn from a dedicated leadership team • Top-of-the-line company swag

Postuler Maintenant

Emplois Similaires

🕒 il y a 26 jours

Logicalis GmbH

201 - 500

💼 Conseil

📦 Logistique

🏥 Santé

Professional Services Consultant responsible for delivering network solutions to enterprise clients using Fortinet products. Engaging with PMO and RMO to ensure project success while maintaining client satisfaction.

🇺🇸 États-Unis – Télétravail

💵 $90 000 - $122 000 / an

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 26 jours

Confluent

1001 - 5000

🤖 Intelligence artificielle

☁️ SaaS

Join Confluent as a Staff Security Risk & Compliance Program Manager overseeing access management. Lead strategic direction and enforce security protocols for the data streaming platform.

🇺🇸 États-Unis – Télétravail

💵 $222 100 - $261 000 / an

💰 Secondary Market en 2021-06

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 26 jours

C Cubed Capital Partners, LLC

1 - 10

💸 Finance

💳 Fintech

⚖️ Juridique

Director of IT & Cybersecurity leading enterprise IT operations and cybersecurity for C Speed, LLC. Managing IT staff, overseeing projects, and ensuring compliance with security standards.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Azure

Cloud

Cyber Security

DNS

Firewalls

🕒 il y a 27 jours

iRhythm Technologies, Inc.

1001 - 5000

🏥 Santé

💼 Conseil

📦 Logistique

Product Security Manager ensuring FDA compliance and conducting security risk assessments for medical devices at iRhythm. Collaborating with multiple teams to enhance the security lifecycle.

🇺🇸 États-Unis – Télétravail

💵 $127 000 - $165 000 / an

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

SDLC

🕒 il y a 27 jours

Tonal

501 - 1000

👥 B2C

🔧 Matériel

Director of IT & Security at Tonal managing end-to-end IT operations and ensuring compliance with security regulations. Leading a team while collaborating with senior leadership to meet the company’s objectives.

🗣️🇺🇸🇬🇧 Anglais requis