Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.
Act as Information Security Officer for FinTech, supporting ISO 27001, SOCv2, and DORA implementation.
Coordinate security activities across teams, ensuring alignment with cyber security strategy and governance.
Track risks, gaps, and remediation, while preparing updates for security leadership.
Coinspaid Dev is the engineering brand behind the technology and infrastructure built within Coinspaid. With over 120 engineers and 11 years of industry experience, the team builds distributed systems and blockchain infrastructure across more than 20 blockchain networks.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.
Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.
Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.
Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.
Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.
Serve as acting CISO for multiple client organizations and SGP, providing strategic security leadership and executive guidance.
Lead cybersecurity and compliance programs aligned with NIST SP 800-171, CMMC Levels 1-2, and ISO/IEC 27001.
Conduct security assessments, gap analyses, and risk reviews; develop SSPs, POA&Ms, and policies.
Strategic Growth Partners provides cybersecurity and compliance services to clients across multiple time zones. They foster a collaborative, innovative, and diverse work environment.
Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
Engineer GRC workflows with internal systems to support compliance by design.
Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.
Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.
Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
Manage identity and access, device fleet, and vendor security with ownership over control state.
Drive compliance as a sales enabler and own the customer-facing security package.
Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.
Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.
Own and build the group-wide ISMS following BSI standards and ISO 27001 certification.
Manage risk, incident response, and security awareness across technical and organizational domains.
Work hands-on with IT and engineering teams, ensuring security governance and regulatory compliance.
Vektor Group builds AI platforms for customers in the defence and government sector. It is a startup with flat hierarchies, real ownership, and fast decisions.
Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
Perform technical security and compliance reviews of third-party vendors and service providers.
iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.
Act as central contact for information security in the business group, working with development teams and customers.
Implement local ISMS, conduct risk analyses and security reviews.
Collaborate with corporate security and advise on practical security requirements.
Haufe provides digital research systems and software solutions, making complex professional knowledge easily applicable for over one million customers. It is a Great Place to Work® with cross-functional teams across Germany, Romania, and Spain.
Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
Automate compliance workflows, evidence collection, access reviews, and security checks.
Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.
Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.
Lead and maintain ATO documentation and coordinate with security, engineering, and project teams to ensure compliance.
Monitor security events, investigate threats, and assess vulnerabilities across cloud and enterprise environments.
Develop and implement security policies, conduct risk analysis, and provide cybersecurity guidance to stakeholders.
The company is a partner organization focused on cybersecurity and federal technology modernization. It offers a fully remote, mission-driven culture with opportunities for growth in a technology-focused environment.
Own and build Flodesk's security program end to end, including policies, controls, and governance.
Lead SOC 2, ISO 27001, and CCPA readiness while partnering with engineering on secure development.
Manage IT operations, vendor vetting, and security tooling to scale the program.
Flodesk is a fast-growing email marketing company that helps creators and small businesses design emails and monetize their email lists. It is a remote-first company with a globally distributed team and offices in San Francisco, Menlo Park, and Da Nang.
Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
Answer customer security questionnaires and ensure compliance documents are accurate.
Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.
Develops and maintains information security policies, procedures, and controls ensuring compliance with HITRUST, SOC 2, HIPAA, and other frameworks.
Leads audit readiness and execution, managing HITRUST and SOC 2 Type II examinations from planning through report issuance.
Drives continuous improvement of security processes, risk management, and incident response across the organization.
MRO specializes in information security assurance and regulatory compliance, helping organizations manage risk and maintain audit readiness. The company fosters a security-focused culture with a team of experienced professionals.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.