Responsibilities:
Enhance and implement the security strategy, including objectives, architecture, information access model, budget, schedule, staffing, and vendor engagement.
Ensure that solution and service offerings meet required compliance levels.
Represent the security program externally with customers, prospects, and partners, and internally with employees.
Collaborate with the Operations and Engineering teams to integrate security requirements into the product roadmap, implementation, operation, and support.
Collaborate with IT and HR on corporate security, physical security, workplace safety matters, and personnel security.
Develop and maintain our privacy program, own GDPR/CCPA compliance, handle data-subject requests, conduct DPIAs, and train the business on privacy best practices.
Manage security incidents in the production and IT environments.
Lead remediation from audit findings or security incidents.
Own the company's security awareness program and training.
10+ year track record of progressive experience in network and information security and risk management
Proven experience in managing AppSec, SecOps, and GRC teams.
Experience designing, implementing, and leading security and risk management programs.
Experience in managing compliance projects SOC2, ISO 27001, PCI.
A solid technical background with strong knowledge of cloud security models and controls.
Demonstrated experience in data-protection and privacy (e.g. acting as a DPO or equivalent).
Deep familiarity with GDPR, CCPA, and other global privacy regulations, plus hands-on exposure to privacy by design and DPIA processes.
Outstanding communication, interpersonal, and relationship building skills; the ability to work well in a cross-functional, matrix management environment.
An organized, responsive, and engaged problem-solving mindset and approach.