Director, Security Compliance and Trust
Core
Build and lead the Security Compliance and Trust function to earn customer, regulator, and partner confidence through governance, risk, compliance, privacy, and AI governance.
Role type
Director, Security Compliance and Trust (Hands-on leadership)
Builds
A single integrated control framework mapping ISO 27001/27701, SOC 1/2, PCI DSS, FedRAMP, GDPR, and CCPA/CPRA; an AI-first operating model for evidence automation and continuous monitoring.
Domain
Cloud-native SaaS security, privacy, and regulatory compliance across global markets (US, Canada, EU, Mexico, Latin America).
Deliverable
Production compliance frameworks, audit readiness, privacy operations, and AI governance programs.
Required skills
Multi-framework compliance program ownership (ISO, SOC, PCI), operational privacy expertise (GDPR, CCPA), hands-on policy design and control mapping, audit fieldwork leadership, global market entry compliance, AI governance framework application, customer-facing trust management.
Preferred skills
FedRAMP authorization leadership, IPO readiness/SOX experience, PIPEDA/LGPD/LFPDPPP familiarity, CIPP/E/CIPP/US/CIPM certification, AI tooling implementation for compliance.
Technologies
ISO/IEC 42001, NIST AI Risk Management Framework, EU AI Act, FedRAMP, GDPR, CCPA/CPRA, PIPEDA, LGPD, LFPDPPP.
Responsibilities
Own org design and global team development for the compliance function; build unified control mappings across multiple frameworks; lead the path to FedRAMP authorization; manage privacy operations including DSARs and cross-border transfers; serve as senior escalation point for enterprise security reviews; architect AI-driven automation for evidence collection and questionnaire response; establish company-wide security policy and training programs.
Seniority
Director, hands-on leadership