Director of Security – Compliance

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of StrongMind

StrongMind

51 - 200 employees

Founded 2001

📚 Education

☁️ SaaS

🤝 B2B

Education • SaaS • B2B

StrongMind is a K-12 education company that provides digital learning solutions, curriculum, and services for schools and families. It offers an adaptive, engaging digital curriculum and technology platform aimed at strengthening student outcomes and simplifying K-12 digital learning, along with enrollment marketing and support services. StrongMind also provides a homeschool product for families with built-in curriculum and daily planning guidance.

📋 Description

• Own StrongMind’s security and compliance program, including SOC 2, student data privacy, access governance, third-party risk, incident readiness, and AI governance • Own the SOC 2 program end to end, including scope, control design, evidence collection, auditor relationships, Type I and Type II attestation, and annual reattestation • Coordinate security and compliance controls across IT Operations and Engineering • Establish and maintain access governance policies for provisioning, access reviews, and revocation • Manage compliance requirements related to COPPA, FERPA, state student privacy laws, and public records obligations with Legal • Build and maintain a risk-based vendor and third-party risk management program • Monitor internal security posture, including cloud security findings, corporate SaaS security, and defensive readiness • Develop and maintain incident response plans, breach preparedness procedures, runbooks, and tabletop exercises • Partner with the AI committee and Data Science organization on responsible AI governance • Direct contracted security resources, including vCISO or specialist support • Establish recurring processes for vendor risk reviews, access reviews, evidence collection, control monitoring, and leadership reporting • Provide clear, actionable risk reporting to leadership • Coordinate across teams and turn policies and requirements into operational processes • Influence security strategy and scale security and compliance capabilities as the company grows

🎯 Requirements

• Demonstrated experience owning and operating a security and compliance program, ideally through at least one SOC 2 attestation from program buildout through final report • Strong understanding of security controls, compliance frameworks, risk management, and audit processes • Ability to coordinate controls and drive accountability across teams without direct management authority • Experience directing contractors, consultants, vCISOs, or other external security resources • Experience working in K–12, education technology, or another highly regulated data environment • Strong understanding of student privacy requirements, including COPPA and FERPA, or comparable privacy and regulatory frameworks • Experience building security and compliance programs from the ground up and translating policies into repeatable operational processes • Strong communication, organization, and project management skills • Ability to work effectively with technical and non-technical stakeholders • Ability to identify risk, communicate potential impact, and establish practical mitigation strategies • Ability and willingness to grow a security and compliance function • Direct EdTech experience or experience with state student privacy laws and statewide data privacy agreements preferred as a bonus • Experience with Vanta, Drata, Delve, or similar compliance automation tools preferred as a bonus • Experience with Wiz or similar cloud security posture management tools preferred as a bonus • Experience supporting GDPR compliance or international privacy programs preferred as a bonus • CISSP, CISM, CISA, or comparable security or compliance certification preferred as a bonus • Experience governing AI systems or evaluating AI vendors in a regulated data environment preferred as a bonus • Must be eligible to work in the United States • Visa sponsorship is unavailable

🏖️ Benefits

• A competitive total compensation package, including medical, dental, vision, and voluntary benefits • On-site gym • Virtual wellness programs • Wellness coaching • Flexible work options for select roles • Unlimited PTO for salaried roles • “Life happens” days • A fully paid holiday week off at Christmas • Recognition and rewards for birthdays, meaningful anniversary milestones, and community service hours • Quarterly Town Halls • Annual social events and traditions, including Halloween celebrations and Wellness Fairs

Apply Now

Similar Jobs

🔥 1 hour ago

MANSCAPED

201 - 500

🏭 Manufacturing

💼 Consulting

📣 Marketing

Quality and regulatory director ensuring MANSCAPED grooming products meet safety, quality, and global compliance standards. Leading QMS, supplier quality, product safety, and regulatory strategy.

🔥 2 hours ago

Ipsen

5001 - 10000

🏥 Healthcare

💼 Consulting

📦 Logistics

Commercial regulatory affairs director guiding FDA advertising and promotion compliance for Ipsen’s biopharmaceutical medicines. Leading OPDP interactions, promotional reviews, submissions, and cross-functional regulatory strategy.

🔥 6 hours ago

Stord

1001 - 5000

🍽️ Food & Beverage

💼 Consulting

📣 Marketing

Regional HSS and loss prevention manager protecting Stord’s fulfillment and warehouse operations. Leading safety, compliance, investigations, security, and team development across North Carolina facilities.

🔥 6 hours ago

US Pharmacopeia

1001 - 5000

🏥 Healthcare

📦 Logistics

💼 Consulting

Digital standards strategy director shaping pharmaceutical quality frameworks at USP. Aligning regulators, standards bodies, manufacturers, and internal teams around digital standards governance and adoption.

🔥 8 hours ago

Stord

1001 - 5000

🍽️ Food & Beverage

💼 Consulting

📣 Marketing

Regional HSS manager leading safety, compliance, and loss prevention across Stord’s fulfillment facilities. Building teams, reducing shrink, managing investigations, and ensuring regulatory readiness.