← All Jobs
Posted May 12, 2026

Security Compliance & Trust Certifications Lead

Apply Now
Title: Security Compliance & Trust Certifications Lead Duration: Long term Location :Remote ,USA(Candidate from California or PST times highly preferred) (ONLY W2) Job Description: Key Responsibilities Certification Program Ownership • Lead end-to-end delivery of SOC 2 Type II and ISO/IEC 27001:2022 certifications • Define certification scope, system boundaries, and control applicability • Translate business operations and technical environments into audit-ready control narratives Control Design & Implementation • Map existing security and operational controls to SOC 2 and ISO 27001 requirements • Identify control gaps and implement pragmatic remediation plans • Ensure controls align with modern SaaS and cloud-native environments Evidence Management & Audit Readiness • Design scalable evidence collection workflows and continuous monitoring processes • Implement lightweight tooling or automation for ongoing evidence capture • Prepare audit artifacts, walkthrough materials, and management responses • Serve as the primary liaison with external auditors and assessors ISMS & Governance Build-Out • Establish and operationalize a scalable Information Security Management System (ISMS) • Define and implement: • Risk assessment and risk quantification methodology • Policy and standards framework • Management review cadence Required Qualifications • 7+ years of experience in security compliance, GRC, audit readiness, or related fields • Proven hands-on delivery of SOC 2 and ISO 27001 certification programs • Experience in fast-growing SaaS or consumer technology companies • Strong ability to translate technical environments into audit-grade documentation and narratives • Familiarity with GRC platforms such as VISO Trust, Vanta, Drata, or similar • Solid understanding of cloud security controls and modern SaaS architectures • Experience with risk assessment and risk quantification methodologies Preferred Qualifications • Background in Big 4 or top-tier advisory firms (PwC, Deloitte, EY, KPMG) • Experience with AWS, GCP, or Azure cloud environments • Proven ability to partner directly with CISOs and executive leadership teams Apply Now Apply Now
Interested in this role?Apply on iHire