Responsibilities
- Define and execute a strategic security roadmap that supports business objectives and risk tolerance.
- Develop and monitor KPIs and metrics to assess the strength and progression of security maturity.
- Embed security practices into the software development lifecycle, including threat modeling, architecture reviews, and automated code scanning.
- Collaborate with engineering teams to balance security remediation with product development priorities.
- Expand security automation and tooling to minimize manual effort and improve threat detection.
- Perform continuous risk evaluations of internal platforms and third-party providers, converting technical flaws into business-level risk insights.
- Lead compliance efforts for standards such as SOC2, ISO 27001, CMMC, and FedRAMP, ensuring controls are implemented and audit-ready.
- Manage a centralized Risk Register to track and report top organizational threats to executive stakeholders.
- Communicate complex security topics clearly to non-technical leaders and executives.
- Design and deliver security training programs to promote company-wide security awareness and accountability.
Compensation
Total compensation includes base salary, bonus, equity, and a comprehensive benefits package available through the company's career site.
Work Arrangement
Hybrid