- Maintain SOC 2 Type II compliance through control operation, evidence collection, and audit readiness.
- Lead ISO 27001 certification efforts from gap assessment through surveillance.
- Manage security and privacy frameworks including GDPR, CCPA, and other regulations.
- Improve security controls, governance standards, policies, and risk management practices.
- Conduct security risk assessments, manage incident response, and drive remediation.
- Administer Vanta to automate compliance monitoring and audit workflows.
- Partner with Engineering, Product, and Legal to embed security and privacy into business processes.
- Define enterprise data governance, classification, and retention standards.