Director, Security Compliance and Trust

gomotive

United States

Remote

USD 225,000 - 305,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Equity potential
401k plan

Job summary

gomotive seeks a senior leader to own compliance, privacy, and customer-trust for a software platform serving transport, logistics, and more. Reporting to CIO, you’ll blend policy writing, control design, audits, and direct customer engagement.

You will build a global governance program, scale teams across time zones, and lead an AI-first approach to evidence collection and regulatory readiness. This role blends strategic leadership with hands-on execution.

Qualifications

  • Eight+ years in security compliance, GRC, privacy, audit, or risk management.
  • Five+ years leading people managers and senior individual contributors.
  • Experience standing up compliance and privacy in new international markets.
  • Hands-on track record writing policies and designing controls.

Responsibilities

  • Lead governance, risk, and compliance end-to-end, including org design and risk decisions.
  • Build a unified control framework mapping ISO 27001/27701, SOC 1/2, PCI DSS, GDPR, CCPA/CPRA.
  • Own the annual audit calendar and drive FedRAMP authorization from the ground up.
  • Operate the privacy program: data rights, DPIAs, transfers, sensitive data handling.
  • Prepare regulatory readiness for new markets in collaboration with Engineering/Platform.
  • Represent security posture externally and manage trust portal responses.
  • Architect an AI-first operating model with evidence automation and monitoring.
  • Stand up AI governance aligned with ISO/IEC 42001, NIST AI RMF, EU AI Act.

Skills

GRC leadership
Policy writing
Audit management
Privacy program
Cross-border compliance
FedRAMP
AI for compliance
Customer trust ownership
Team leadership

Job description

Role overview

A senior leadership role owning the compliance, privacy, and customer-trust function for a software platform serving physical-operations customers across transportation, logistics, construction, energy, field service, and the public sector. Reporting to the Chief Information Security Officer, the position blends strategic program leadership with hands‑on policy writing, control design, audit fieldwork, and direct customer engagement. The role is expected to scale globally into Canada, the EU, Mexico, and South America, and to operate an AI-first governance model rather than a traditional GRC stack.

Responsibilities
  • Lead governance, risk, and compliance end-to-end, including org design, hiring, framework selection, and the decision of where to accept versus remediate risk.
  • Build a unified control framework that maps once across ISO 27001/27701, SOC 1 and SOC 2, PCI DSS, FedRAMP, GDPR, and CCPA/CPRA, with single-source evidence collection.
  • Own the annual audit calendar, manage assessor relationships, and drive a FedRAMP authorization effort from the ground up as public‑sector demand matures.
  • Operate the privacy program: data subject rights, DPIAs, ROPA, cross‑border transfers, and special handling for sensitive driver data such as location history, in‑cab video, telematics behavior, and biometric‑adjacent processing.
  • Prepare regulatory readiness for new markets ahead of go‑to‑market, partnering with Engineering and Platform on data residency and regional architecture.
  • Represent the security and privacy posture externally: own the trust portal, scale security questionnaire responses, and serve as the senior escalation point in enterprise deals.
  • Architect an AI‑first operating model, personally building evidence automation, continuous control monitoring, and AI‑assisted questionnaire response.
  • Stand up an AI governance program aligned with ISO/IEC 42001, the NIST AI RMF, and the EU AI Act, covering both product and internal AI use.
Requirements
  • Eight or more years in security compliance, GRC, privacy, audit, or risk management, including five or more years leading people managers and senior individual contributors.
  • Demonstrated hands‑on track record personally writing policies, designing controls, sitting in audits, and owning operational delivery rather than purely delegating.
  • Experience standing up compliance and privacy in new international markets, ideally Canada, the EU, Mexico, or Latin America; familiarity with PIPEDA/Law 25, LGPD, or LFPDPPP is a strong plus.
  • Experience with FedRAMP, ideally having led an organization through authorization or Moderate/High readiness.
  • Concrete, demonstrated use of AI for compliance work such as evidence collection, questionnaire response, control monitoring, policy drafting, audit prep, or regulatory gap analysis, with measurable outcomes.
  • Experience owning customer‑facing trust functions and leading globally distributed teams across multiple time zones.
Nice to have
  • IPO readiness, SOX, or equivalent regulated‑environment experience, and prior work with sensitive personal data at scale.
Benefits and work setup
  • Compensation range for United States‑based candidates: $225,000–$305,000, with total package potentially including equity. Benefits include health, pharmacy, dental, and vision coverage, paid and sick time, short‑and long‑term disability, life insurance, and 401k contributions, subject to eligibility. Some interviews or onboarding sessions may occur in person at global offices.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Manager
Compliance Manager

RightCapital Inc. • Shelton (CT)

On-site
USD 80,000 - 100,000
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Associate Director, Security & Compliance (US)
Associate Director, Security & Compliance (US)

twentysix • New York (NY)

On-site
USD 140,000 - 175,000
Director, Security Compliance and Trust
Director, Security Compliance and Trust

Socket.dev • United States

On-site
USD 225,000 - 305,000
Health, dental, vision benefits
Paid time off & sick leave
Disability & life insurance
+1
Director, Governance, Risk & Compliance
Director, Governance, Risk & Compliance

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000
Head of Compliance and Regulatory Affairs
Head of Compliance and Regulatory Affairs

Secure Engage • Oregon (WI)

Hybrid
USD 180,000 - 240,000
Remote-first flexibility
Equity participation
Benefits package
+2
Director, Compliance & Assurance
Director, Compliance & Assurance

Socket.dev • Menlo Park (CA)

On-site
USD 227,000 - 287,000
Bonus
Equity
Benefits
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
Senior Privacy Counsel
Senior Privacy Counsel

Abnormal • United States

On-site
USD 180,000 - 240,000