Specialist, Information Security and Privacy
Core
Serve as the main point of contact for security, privacy, and compliance topics, managing third-party risk and owning the operational backbone of the compliance program for a cloud platform.
Role type
Specialist, Information Security and Privacy
Builds
Compliance frameworks (SOC 2, ISO, HIPAA, 21 CFR Part 11) and third-party risk management processes
Domain
Cloud Security & Compliance
Deliverable
dashboards & analysis
Required skills
Information security compliance, Third-party risk management, Security RFP handling, Audit coordination, Control landscape management, Policy maintenance
Preferred skills
Cloud platform exposure (AWS/GCP), Customer security query handling
Technologies
Google Workspace (Sheets, Drive, Docs, Gmail)
Responsibilities
Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics; Review customer/prospect questionnaires and security addendums; Maintain information security reports and security assets; Own the third-party risk management process; Conduct security due diligence on new third parties; Own and manage controls across SOC 2 Type II, ISO standards, 21 CFR Part 11, and HIPAA frameworks; Coordinate and support external audits end-to-end; Manage compliance tracking across Google Workspace; Send and track corrective action communications; Conduct periodic internal compliance reviews; Collaborate with privacy, governance, audit, Engineering, DevOps, Legal, and HR teams; Maintain and periodically review information security policies; Coordinate access reviews and vendor security assessments.
