Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
RateGain is looking for an experienced Head of Information Security and Data Privacy to lead security efforts across cloud and application environments. This role demands a comprehensive strategy to ensure compliance with regulations like GDPR and PCI DSS.
Qualified candidates should have over 18 years of experience, including familiarity with security frameworks such as ISO/IEC 27001. You will develop incident response plans and oversee security assessments to safeguard enterprise-level data.
We are seeking Head of Information Security and Data Privacy, who will take the helm in leading the following:
1) Information security at the enterprise level, encompassing both application security and cloud security.
2) Certification Compliance for standards such as ISO, SOC, PCI DSS.
3) Data Privacy. GDPR and CCPA readiness and compliance.
Design, implement, and manage security measures for cloud-based infrastructure, ensuring the confidentiality, integrity, and availability of data.
Conduct regular security assessments and audits of cloud environments to identify and remediate vulnerabilities.
Collaborate with cross-functional teams to integrate security best practices into cloud-based solutions.
Develop and implement strategies for securing applications throughout the software development lifecycle (SDLC).
Conduct code reviews and provide guidance to development teams on secure coding practices.
Perform application security assessments, penetration testing, and vulnerability assessments.
Develop and implement incident response plans for cloud environments and applications.
Monitor and analyze security logs to detect and respond to security incidents in a timely manner.
Ensure compliance with industry standards and regulations related to cloud security and application security.
Work with internal and external auditors to demonstrate compliance with security policies and procedures.
Implement and maintain security automation tools and scripts to streamline security processes.
Identify opportunities for automation to enhance the efficiency and effectiveness of security operations.
Lead and oversee the implementation and maintenance of GDPR and CCPA compliance programs.
Conduct thorough assessments to ensure alignment with the regulatory requirements and address any gaps.
Conduct PIAs to identify and address potential privacy risks associated with data processing activities.
Provide recommendations for mitigating privacy risks and ensuring compliance with regulations.
- 18+ years of experience.
- Experience with a global footprint.
- Proven expertise in developing and implementing enterprise strategies and programs for the effective management of information and technology risks.
- Familiarity with common information security management frameworks, including ISO/IEC 27001 and NIST.