-
Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics, communicating with customers and prospects through RFPs, emails, or calls.
-
Review customer/prospect questionnaires and security addendums, providing and building necessary information, collaterals, and resources.
-
Maintain information security reports, RFP knowledgebase, and security assets for the security due diligence process utilizing existing RFP management tools.
-
Work flexibly across all teams in the organization, driving security RFP and third-party risk management projects, including sales, customer success, product, and engineering.
-
Own the third-party risk management process, including planning, scoping, needs analysis, ongoing project management, and communication with stakeholders.
-
Conduct security due diligence on new third parties and perform periodic risk reviews of existing third parties.
-
Own and manage controls across SOC 2 Type II, ISO standards, 21 CFR Part 11, and HIPAA frameworks, maintaining an up-to-date control landscape and evidence inventory.
-
Coordinate and support external audits end-to-end - from audit scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking.
-
Manage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail) - maintaining structured control registers, evidence repositories, and policy documentation.
-
Send and track corrective action communications to control owners, following up through resolution and maintaining a clear audit trail.
-
Conduct periodic internal compliance reviews and produce structured reports for leadership.
-
Collaborate closely with privacy, internal governance, audit, Engineering, DevOps, Legal, and HR teams to gather necessary information related to compliance and ensure controls are implemented.
-
Work with engineering, business applications, legal, and other teams as required to fulfill customer, prospect, or third-party compliance requirements.
-
Maintain and periodically review information security policies, procedures, and standards in Google Docs, ensuring they remain current and aligned with framework controls.
-
Coordinate access reviews, vendor security assessments, and third-party risk evaluations as part of the ongoing compliance calendar.
-
Undertake any other reasonable and related tasks associated with the role.