- Company Name
- Instabase
- Job Title
- Director, Security & Compliance
- Job Description
-
**Job Title:** Director, Security & Compliance
**Role Summary:**
Lead and expand the organization’s Security and Governance, Risk, and Compliance (GRC) program. Shape policy, execute audits, and manage compliance initiatives to safeguard data, meet regulatory requirements, and enable secure product delivery across cloud‑based services.
**Expectations:**
- Define and advance the GRC roadmap, ensuring alignment with business strategy.
- Deliver comprehensive security and compliance programs for GDPR, SOC 2, HIPAA, ISO 27001, FedRAMP (NIST 800‑53), and related frameworks.
- Drive continuous improvement of compliance processes, tooling, and reporting.
**Key Responsibilities:**
1. Develop security policies, procedures, and training programs.
2. Own the execution of new security and compliance initiatives, including vendor security reviews and risk assessments.
3. Establish and refine standards, processes, and tools for audit and compliance management.
4. Collaborate with Engineering, Product, GTM, Legal, and HR to embed security practices company‑wide.
5. Liaise with external auditors to achieve and maintain certifications and audit reports.
6. Produce regular status updates, operational metrics, and KPIs for leadership and stakeholders.
**Required Skills:**
- Extensive experience leading security compliance, risk assessments, and audits in cloud/SaaS environments.
- In‑depth knowledge of FedRAMP (NIST 800‑53), GDPR, SOC 2, HIPAA, and ISO 27001.
- Proven ability to work cross‑functionally, influencing engineering and product teams.
- Strong written and verbal communication; adept at stakeholder management and reporting.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred).
- Professional certifications: CISSP, CISM, CISA, or equivalent; FedRAMP or ISO 27001 certification.
**Nice to Have:**
- Experience at a Big Four consulting firm or reputable SaaS provider.
- Engineering or Computer Science background.
San francisco, United states
Hybrid
14-11-2025