Role overview
A senior leadership role owning the compliance, privacy, and customer-trust function for a software platform serving physical-operations customers across transportation, logistics, construction, energy, field service, and the public sector. Reporting to the Chief Information Security Officer, the position blends strategic program leadership with hands‑on policy writing, control design, audit fieldwork, and direct customer engagement. The role is expected to scale globally into Canada, the EU, Mexico, and South America, and to operate an AI-first governance model rather than a traditional GRC stack.
Responsibilities
- Lead governance, risk, and compliance end-to-end, including org design, hiring, framework selection, and the decision of where to accept versus remediate risk.
- Build a unified control framework that maps once across ISO 27001/27701, SOC 1 and SOC 2, PCI DSS, FedRAMP, GDPR, and CCPA/CPRA, with single-source evidence collection.
- Own the annual audit calendar, manage assessor relationships, and drive a FedRAMP authorization effort from the ground up as public‑sector demand matures.
- Operate the privacy program: data subject rights, DPIAs, ROPA, cross‑border transfers, and special handling for sensitive driver data such as location history, in‑cab video, telematics behavior, and biometric‑adjacent processing.
- Prepare regulatory readiness for new markets ahead of go‑to‑market, partnering with Engineering and Platform on data residency and regional architecture.
- Represent the security and privacy posture externally: own the trust portal, scale security questionnaire responses, and serve as the senior escalation point in enterprise deals.
- Architect an AI‑first operating model, personally building evidence automation, continuous control monitoring, and AI‑assisted questionnaire response.
- Stand up an AI governance program aligned with ISO/IEC 42001, the NIST AI RMF, and the EU AI Act, covering both product and internal AI use.
Requirements
- Eight or more years in security compliance, GRC, privacy, audit, or risk management, including five or more years leading people managers and senior individual contributors.
- Demonstrated hands‑on track record personally writing policies, designing controls, sitting in audits, and owning operational delivery rather than purely delegating.
- Experience standing up compliance and privacy in new international markets, ideally Canada, the EU, Mexico, or Latin America; familiarity with PIPEDA/Law 25, LGPD, or LFPDPPP is a strong plus.
- Experience with FedRAMP, ideally having led an organization through authorization or Moderate/High readiness.
- Concrete, demonstrated use of AI for compliance work such as evidence collection, questionnaire response, control monitoring, policy drafting, audit prep, or regulatory gap analysis, with measurable outcomes.
- Experience owning customer‑facing trust functions and leading globally distributed teams across multiple time zones.
Nice to have
- IPO readiness, SOX, or equivalent regulated‑environment experience, and prior work with sensitive personal data at scale.
Benefits and work setup
- Compensation range for United States‑based candidates: $225,000–$305,000, with total package potentially including equity. Benefits include health, pharmacy, dental, and vision coverage, paid and sick time, short‑and long‑term disability, life insurance, and 401k contributions, subject to eligibility. Some interviews or onboarding sessions may occur in person at global offices.