Associate Director, Security & Compliance (US)

twentysix

New York (NY)

On-site

USD 140,000 - 175,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Code and Theory is seeking an Associate Director, Security & Compliance to lead security, privacy, and compliance for our SaaS products and client projects. You will own this capability end to end, from new business through implementation, certification, and ongoing monitoring.

You will drive SOC 2 Type II and ISO 27001 readiness, manage ISMS and AI governance, and coordinate auditor activities while partnering with delivery teams to embed security and privacy into our work.

Qualifications

  • 8+ years of progressive experience in information security, including leadership in SaaS and/or professional services environments.
  • Strong understanding of modern application and cloud security fundamentals (identity and access, encryption and key management, logging and monitoring, vulnerability management).
  • Demonstrated ownership of SOC 2 Type II and ISO 27001 programs from readiness through steady-state operations.
  • Strong working knowledge of privacy requirements and practices, including HIPAA, GDPR, and CCPA/CPRA, and experience operationalizing privacy controls in product and client delivery contexts.
  • Experience building security and privacy processes that work in real delivery environments.
  • Clear communication skills, able to represent security and privacy with internal teams, auditors, and client stakeholders with differing levels of technical fluency.

Responsibilities

  • Lead our security program across SaaS products and client projects, setting strategy, priorities, and measurable outcomes.
  • Lead SOC 2 Type II, ISO 27001, and ISO 42001 readiness and ongoing compliance, including control design, evidence processes, and auditor coordination.
  • Own ISMS and AI governance documentation and oversight.
  • Lead privacy governance and operational practices, ensuring compliance with applicable requirements including HIPAA, GDPR, and CCPA/CPRA, and addressing data handling, contractual privacy terms, and privacy by design expectations.
  • Partner with delivery teams to embed security and privacy into how we build, with clear expectations, practical review gates, and patterns for common risks (identity, access, data handling, multi-tenancy, logging, and auditability).
  • Establish a repeatable client engagement security plan for client work (environment segregation, access provisioning and deprovisioning, client data handling, incident coordination, and delivery requirements).
  • Lead vendor security reviews, including due diligence for critical providers, remediation tracking, and ongoing monitoring.
  • Support customer assurance efforts including security questionnaires, RFPs, client security reviews, and maintaining trust artifacts and standard responses.
  • Maintain an incident response program (playbooks, escalation, exercises) and drive post‑incident improvements.
  • Build a security and privacy culture through clear guidance, lightweight training, and day‑to‑day partnership with teams.

Skills

Security program leadership
SOC 2 Type II readiness
ISO 27001 readiness
Privacy governance
HIPAA/GDPR/CPRA knowledge
Communication with auditors
Cross-functional collaboration

Tools

Security tooling (CI/CD)
Threat modeling

Job description

We are seeking an Associate Director, Security & Compliance to lead security, privacy, and compliance for our SaaS products and the client projects we deliver as an agency. You will own this capability end to end, from new business through implementation, certification, and ongoing monitoring. This role is central to how we win and deliver projects, protect client and company data, and earn trust through clear, high quality security and privacy practices.

What You’ll Do
  • Lead our security program across SaaS products and client projects, setting strategy, priorities, and measurable outcomes.
  • Lead SOC 2 Type II, ISO 27001, and ISO 42001 readiness and ongoing compliance, including control design, evidence processes, and auditor coordination.
  • Own ISMS and AI governance documentation and oversight.
  • Lead privacy governance and operational practices, ensuring compliance with applicable requirements including HIPAA, GDPR, and CCPA/CPRA, and addressing data handling, contractual privacy terms, and privacy by design expectations.
  • Partner with delivery teams to embed security and privacy into how we build, with clear expectations, practical review gates, and patterns for common risks (identity, access, data handling, multi-tenancy, logging, and auditability).
  • Establish a repeatable client engagement security plan for client work (environment segregation, access provisioning and deprovisioning, client data handling, incident coordination, and delivery requirements).
  • Lead vendor security reviews, including due diligence for critical providers, remediation tracking, and ongoing monitoring.
  • Support customer assurance efforts including security questionnaires, RFPs, client security reviews, and maintaining trust artifacts and standard responses.
  • Maintain an incident response program (playbooks, escalation, exercises) and drive post‑incident improvements.
  • Build a security and privacy culture through clear guidance, lightweight training, and day‑to‑day partnership with teams.
What You’ll Need
  • 8+ years of progressive experience in information security, including leadership in SaaS and/or professional services environments.
  • Strong understanding of modern application and cloud security fundamentals (identity and access, encryption and key management, logging and monitoring, vulnerability management).
  • Demonstrated ownership of SOC 2 Type II and ISO 27001 programs from readiness through steady‑state operations.
  • Strong working knowledge of privacy requirements and practices, including HIPAA, GDPR, and CCPA/CPRA, and experience operationalizing privacy controls in product and client delivery contexts.
  • Experience building security and privacy processes that work in real delivery environments.
  • Clear communication skills, able to represent security and privacy with internal teams, auditors, and client stakeholders with differing levels of technical fluency.
  • Comfort operating across a geographically dispersed organization and coordinating work across time zones.
Nice to Haves
  • Experience in an agency or consulting environment supporting multiple client projects in parallel.
  • Experience supporting AI‑enabled products and data flows, including model and data risk considerations and familiarity with ISO 42001.
  • Expertise in at least one major cloud platform (GCP, AWS, or Azure) and common SaaS security patterns.
  • Experience with security monitoring, incident response, and vulnerability management programs in production environments.
  • Hands‑on experience with security tooling across CI/CD, cloud infrastructure, vulnerability scanning, and logging and monitoring workflows.
  • Relevant security and/or privacy certifications such as CISSP, CISM, CCSP, CIPP, CIPT.

The target range of base compensation for this role is $140,000 - $175,000. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, and location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Leader for SaaS & Privacy
Security & Compliance Leader for SaaS & Privacy

Code and Theory • New York (NY)

On-site
USD 140,000 - 175,000
Director of InfoSec & Data Privacy
Director of InfoSec & Data Privacy

PKR • Pennsylvania

Hybrid
USD 175,000 - 190,000
Competitive compensation
Executive visibility
Comprehensive benefits
+2
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
VP, Information Security and Compliance
VP, Information Security and Compliance

Society of Defense Financial Management • Santa Ana (CA), Northern (KY)

Hybrid
USD 200,000 - 250,000
VP, Information Security and Compliance
VP, Information Security and Compliance

Veritone • United States

On-site
USD 200,000 - 250,000
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Rosemont (IL)

Hybrid
USD 140,000 - 180,000
Director of Cyber Security
Director of Cyber Security

Insight Global • Morristown (NJ)

Hybrid
USD 185,000 - 235,000
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
Compliance Manager
Compliance Manager

RightCapital Inc. • Shelton (CT)

On-site
USD 80,000 - 100,000
Senior Security Assurance Lead - Global Compliance & Audit
Senior Security Assurance Lead - Global Compliance & Audit

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 190,000
Medical, dental, and vision insurance
Mental health benefits
401(k) plan with company match
+2