- Maintain SOC 2 Type II and ISO 27001 certifications end-to-end.
- Lead compliance work for new certifications and initiatives.
- Evaluate additional certifications based on market requirements.
- Administer GRC platform (Vanta) including control mapping and evidence workflows.
- Lead security working group and maintain threat registry.
- Coordinate penetration testing cycles and track remediation.
- Author and maintain security policies (GDPR, PCI).
- Respond to security questionnaires and represent compliance posture to customers.
- Provide security awareness and compliance training.