Role Overview:
You will be responsible for secure design, development and operation of Skyhigh's products and services. Responsibilities may include threat assessment, design of security components, vulnerability assessment. Ensures products conform to standards and specifications. Develops plans and cost estimates and assesses projects to analyze risks. Responds to customer/client requests or events as they occur. Develops solutions to problems utilizing formal education, judgment and formal process. Maintains substantial knowledge of state-of-the-art security principles, theories, attacks and contributes to literate and conferences. Require thorough knowledge of security practices, procedures and capabilities in order to perform non-repetitive, analytical work.
About the Role: - You will serve as a critical member of the team who expertly blends technical security knowledge with strategic compliance management.
- You will be the primary driver of our corporate compliance program. This involves independently managing the full lifecycle of internal and external audits for key certifications like ISO 27001, SOC 2, FedRAMP, and PCI-DSS.
- You will handle audit preparation, coordinate with auditors, and meticulously gather all required evidence and documentation.
- You will take direct ownership of developing, maintaining, and communicating our Information Security Management System (ISMS) documentation and policies.
- You will ensure compliance is not an afterthought by actively reviewing operational controls and participating in IT change management. You will work directly with technical teams to integrate compliance requirements into their workflows and CI/CD pipelines.
- While compliance is the focus, you will leverage your security engineering knowledge to provide valuable insights. You will personally guide the secure design of systems and translate vulnerability findings into actionable, risk-based remediation plans that align with our compliance framework.
Qualifications: - 5-10 years of combined experience IT Audit, IT Compliance, or a related Security Engineering role with a strong compliance focus. You are a seasoned professional with deep knowledge of industry-leading security principles and frameworks.
- Hands-on experience managing audits for multiple standards, particularly ISO 27001, SOC 2, or FedRAMP. You are an expert in independently gathering evidence and presenting a compelling case for certification.
- Ability to perform both analytical, compliance-focused work and technical, hands-on tasks when needed. Your exceptional analytical, documentation, and organizational skills allow you to manage complex projects with meticulous detail.
- Excellent communicator with a proven ability to convey complex technical and compliance issues to a wide range of audiences. You excel at collaborating with cross-functional teams to drive process maturity and operational efficiency, serving as a subject matter expert and trusted advisor.
- Familiar with cloud environments (e.g., AWS, Azure, GCP) and understand the role of DevOps tools (e.g., GitLab, Jenkins) in a modern security and compliance program. You are comfortable thriving in a fast-paced, evolving global environment.