Lead Information Security program ensuring compliance and protection for AI-powered talent platform. Collaborate with HR and oversee security operations for a global company.
Responsibilities
Lead the security program for our AI-powered talent platform
Maintain Beamery's ISO/IEC 42001 certification
Lead AI risk assessments and impact evaluations for systems processing candidate and employee data
Embed security-by-design principles in AI development
Design and maintain enterprise security program aligned with ISO 27001 and SOC 2 Type II
Lead security operations including vulnerability management, penetration testing, SIEM monitoring, incident response, and business continuity planning
Oversee cloud security for AWS, Google Cloud, and Azure environments
Manage vendor security assessments and third-party risk management
Build security awareness culture through training and ongoing education programs
Ensure compliance with GDPR, CCPA/CPRA, UK DPA, and emerging global privacy regulations
Oversee DPIAs for high-risk processing activities, data breach procedures, and data subject rights fulfillment
Implement privacy controls including data minimization, purpose limitation, and lawful basis documentation
Manage DPAs with customers and Standard Contractual Clauses for international data transfers
Partner with HR to align information security controls with internal HR compliance requirements
Ensure platform compliance with AI hiring regulations (NYC Local Law 144, EU AI Act)
Collaborate with Product to build transparency and explainability into AI-powered screening tools
Lead external audits including SOC 2 Type II, ISO 27001, ISO 42001, and customer security assessments
Maintain audit-ready documentation and monitor evolving regulatory landscape
Support Sales with security expertise to accelerate deal closure
Partner with Engineering and Product to translate compliance requirements into scalable technical controls
Build security and compliance into M&A readiness planning
Requirements
10-15 years information security and compliance experience with 5+ years in leadership roles, preferably in B2B SaaS or HR technology
Deep expertise in ISO 27001, SOC 2, GDPR, and CCPA with proven track record achieving and maintaining certifications
Strong understanding of AI governance and emerging AI regulations (ISO 42001, EU AI Act) as applied to employment technology
Hands-on experience with cloud security architecture and DevSecOps practices across AWS, Google Cloud, or Azure
Demonstrated success building security and compliance programs including policy development, control implementation, and team building
Experience managing external audits and supporting enterprise sales cycles with security/compliance expertise
Exceptional communication skills with ability to translate technical concepts for executives, board members, and customers
Strong business acumen to balance security requirements with business objectives in fast-paced environments.
CISSP required; CISM, CRISC, or CISA strongly preferred
CIPM or CIPP/E highly desirable
Bachelor's degree in Computer Science, Information Security, or related technical field; Master's degree preferred
Benefits
Diversity and open expression culture
Support for reasonable adjustments and adaptations during recruitment
Information Security professional managing governance, audit, and compliance in banking domain. Collaborating across teams to enhance security posture and control effectiveness.
IT Security Manager providing operational leadership for ICBC’s IT security program. Enhancing cyber security practices and managing security initiatives in a dynamic, hybrid cloud environment.
Security Officer ensuring safety and security of Yankee Candle assets and personnel. Responsiblities include monitoring, patrols, incident response, and safety training at the corporate campus.
Senior Specialist in Information Security Governance, Risk & Compliance at Cellulant, driving information security, privacy, and compliance standards within BFSI context.
Cloud Security & Application Security Engineer at Cellulant enhancing security across cloud - native platforms and applications. Working in a hybrid role to support a leading payment service provider in Africa.
IT Audit Consultant joining Baker Tilly to manage technology risks for clients, offering strategic advice and audit support. Engaging with client executives to ensure compliance and operational efficacy.
Senior Health and Safety Advisor overseeing health and safety on construction projects for Aecon. Ensuring compliance with SST legislation and promoting zero accident culture.
Senior Information Security Specialist executing Daikin Europe’s Information Security strategy. Collaborating with leadership to ensure our systems and services remain secure and compliant with regulations.
Experienced Information Security Officer at Daikin responsible for defining Information Security strategy and ensuring compliance with regulatory frameworks. Collaborating with external specialists and mentoring junior team members in EMEA.
Security Specialist ensuring the protection of company and government assets. Conducting daily security functions and providing technical support while maintaining compliance with regulations.