Jobs and Careers
IO
Security and Compliance Manager
IOActiveUnited States, United States, United States, United Statesfull_timeVerifiedPosted 3 Jul 2024
About the role
Objective: IOActive is seeking a dynamic and experienced Security and Compliance Manager to join our team as the first individual to hold this position. In this role, you will be responsible for identifying and driving IOActive’s information security and compliance initiatives, with a strong emphasis on the technical facets of risk management and compliance, while also ensuring alignment with business objectives, regulatory requirements and industry standards. We are looking for an individual with an entrepreneurial, inquisitive mind, who is willing to dig in deep and blaze a path in this realm. You will have a knack for being five steps ahead of the game and a keen ability to explain security and compliance topics to internal stakeholders and clients. We are looking for someone who isn’t afraid to roll up their sleeves and work to further our mission of making the world a safer and more secure place. Key Responsibilities:
- Build a culture of information protection, security and compliance, by developing and managing our information security strategy, and developing appropriate policies, training and resources.
- Drive compliance with all technical components of applicable legal, regulatory, and industry standards related to information security and privacy (e.g., ISO 27k, GDPR), with an immediate focus on becoming certified in ISO 27001.
- Lead risk assessment and management activities, identifying and mitigating potential security risks to the organization, and ensuring they are integrated across all departments.
- Provide front-line support for customer diligence requests, vendor questionnaires, assessments, attestations, and audits.
- Audit, assess, and continually monitor IOActive’s handling of sensitive data and compliance with applicable regulations an requirements.
- Coordinate with IT and other departments to ensure effective security measures are in place and compliant with GRC requirements.
- Oversee the response to security incidents and breaches, including investigation and reporting.
- Manage relationships with external auditors and regulatory bodies for security compliance and audits.
- Provide leadership and direction to the information security team, ensuring continuous development and training.
- Be a shared resource for leadership and other departments. You will provide security and privacy guidance for company data, customer information, and systems infrastructure.
- 5+ years of hands-on experience in the cybersecurity industry or with technology consulting working directly on security and compliance initiatives.
- Proven experience in an information security leadership role with a strong background in GRC.
- Experience bringing organizations into compliance with ISO 27001. Experience in data protection is highly desirable.
- Proven technical skills, including familiarity or direct technical experience with identity and access management, data protection, and technical compliance standards.
- Self-starter approach with a drive to create, build, and roll out resources designed to protect the company and its customers.
- An ability to quickly learn the business’s infrastructure and guide stakeholders.
- A passion for cyber security and stay up to date on the latest developments and trends.
- Foresight and background enabling you to contour policies and processes that are appropriate for a company at our stage, and inspire rapid adoption and adherence by all teams.
- Operational specialist who can establish, maintain and document controls, supervise compliance with the controls, and update the controls when new risks emerge.
- Comprehensive knowledge of information security standards, frameworks, and regulations.
- A knack for making thoughtful, actionable recommendation and quickly building consensus with senior-level internal stakeholders.
- Experience in managing cross-functional teams and projects.
- Exemplary communication skills to ensure communications with non-technical teams and customers on technical matters is digestible and persuasive.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s