Job Description
- Develop, implement, and enforce information security policies, procedures, and standards to mitigate risks and ensure compliance with industry regulations and best practices.
- Identify, assess, and manage security risks across the organization. This includes conducting risk assessments, establishing risk management frameworks, and ensuring the organization's risk tolerance aligns with its business goals.
- Apply in-depth, hands-on knowledge of the FedRAMP regulations, process, and requirements to lead Torch’s FedRAMP certification.
- Review and prioritize security vulnerabilities from various sources, including vulnerability scanning tools, penetration test reports, and threat intelligence feeds. Recommend solutions to the engineering teams to address and remediate identified vulnerabilities.
- Implement and maintain security tools and technologies, like firewalls and intrusion detection systems.Â
- Lead the incident response team in the event of security breaches or incidents. Develop incident response plans, coordinate responses, and ensure timely resolution while minimizing damage.
- Develop and deliver cybersecurity and privacy training and awareness programs for employees.Â
- Collaborate with Engineering and other departments to integrate security best practices.
- Evaluate and manage the security risks associated with third-party vendors and partners. Ensure that vendors adhere to Torch’s security and compliance requirements.
- Develop standards and practices for data anonymization, encryption and tokenization in the organization, based on the organization's data classification criteria.
- Collaborate with auditors to maintain certifications such as ISO 27001, SOC 2 Type 2, Data Privacy Framework Certification, compliance with GDPR etc.
- Engage in Sales calls to communicate the organization's security capabilities, policies, and procedures to clients.
- 15+ years of experience in cybersecurity, minimum 5 years working in Security Compliance.
- Led the pursuit of, or maintained a FedRAMP Moderate+ Authorization.
- In-depth understanding of industry standards, frameworks, and regulations related to cybersecurity and privacy (FedRAMP, NIST, SOC2, ISO, GDPR etc.).
- Experience with artificial intelligence (AI) and machine learning (ML) related security and privacy risk management.
- Proven expertise in cloud systems (preferably AWS), container-based systems like Docker and Kubernetes, and automation/scripting tools for security automation (PowerShell, Python, Bash, etc.)Â
- Experience with a range of security technologies, processes, and tooling around vulnerability management, patch management, firewalling, networking including IAM, SIEM/SOC, IDS/IPS, DLP.
- Exceptional leadership and communication skills, with the ability to champion a culture of security across all levels of the organization.
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
- Technical Interview with the CTO (60 minutes), Head of Platform Engineering (60 minutes) and a Principal Engineer (60 minutes).
- Leadership/Cultural Fit Interview with the COO (60 minutes).
- Take-Home Exercise: Candidates will be required to complete a 60-minute Security and Privacy solution design presentation. While the presentation is expected to take 60 minutes, candidates should allocate approximately 2-4 hours for preparation.
- Health Insurance (medical, dental, and vision)
- Unlimited PTO
- 401k Retirement Plan
- Life & Disability Insurance
- Paid Parental Leave
- Torch Coaching
- Remote Workstation Stipend
Date Posted
05/04/2024
Views
4
Similar Jobs
Engineering Manager - Software Supply Chain Security: Auth Infrastructure - GitLab
Views in the last 30 days - 0
This job description highlights a leadership role in developing secure scalable authentication infrastructure for GitLab It emphasizes technical exper...
View DetailsBilling Coordinator III (Billing Specialist Subsidiary) - labcorp
Views in the last 30 days - 0
Labcorp seeks a Billing Specialist to manage insurance appeals and revenue cycles emphasizing collaboration and innovation The role offers remote work...
View DetailsStaff Salesforce Engineer - CRM Systems - GitLab
Views in the last 30 days - 0
This job description outlines a Staff Salesforce Developer role focusing on designing building and scaling enterprisegrade solutions across Salesforce...
View DetailsGrowth Product Lead - Loyalty - Trafilea
Views in the last 30 days - 0
Trafilea promotes itself as a transformative consumer tech platform with AIdriven growth solutions highlighting achievements like 1B revenue and globa...
View DetailsSales Prospecting Account Executive - Financial Solutions - Blackbaud
Views in the last 30 days - 0
This job posting seeks Prospect Account Executives to sell Financial Management applications for nonprofits and governments Responsibilities include s...
View DetailsSolutions Architect - phData
Views in the last 30 days - 0
This job posting seeks a Solutions Architect to join phDatas Elastic Platform Operations team focusing on cloudnative data platforms like Snowflake AW...
View Details