On a typical day, you might:
- Lead and strategically rebuild the enterprise-level Information Security Management System (ISMS), including the comprehensive development, refinement, and ongoing management of the ISO 27001 program in collaboration with internal and external auditors.
- Drive the achievement and continuous maintenance of ISO and SOC 2 compliance by assessing existing gaps and implementing new technical controls and best practices within our SaaS environment.
- Act as a strategic partner by collaborating extensively with cross-functional teams to streamline internal audit processes, efficiently gather evidence for security controls, and foster a culture of shared responsibility.
- Manage the end-to-end operational risk lifecycle by leading the operational risk board, maintaining a dynamic risk registry, driving mitigation strategies, and overseeing third-party penetration testing and vulnerability monitoring.
- Champion a culture of compliance by developing and delivering impactful security awareness training, preparing actionable metrics on program effectiveness, and maintaining a comprehensive knowledge base to support customer and partner inquiries.
- Ensure continuous improvement by regularly auditing company performance against information security standards, identifying areas for improvement, and proactively managing multiple simultaneous compliance initiatives to drive corrective actions.
The ideal candidate will bring:
- 5+ years of proven experience in a senior or leadership role within information technology/security compliance, with a strong track record in cloud-based SaaS solutions and a focus on establishing and maintaining SOC 2 Type 2 controls.
- A demonstrated ability to assess, realign, and significantly improve a compliance department, including successfully introducing and implementing new technical controls and processes.
- Deep expertise in ISMS governance models (e.g., NIST, ISO 27001), information security roles, and a hands-on ability to design, implement, and validate security controls (ISO, ITIL, NIST, PCI, SOC).
- A proven ability to define, drive, and execute a program vision with clear milestones and measurable outcomes, even in ambiguous environments.
- Exceptional written and verbal communication skills, with the talent to articulate complex technical and compliance concepts clearly and persuasively to diverse audiences, from technical teams to executive leadership and external auditors.
- Strong, practical risk management and auditing experience, with an ability to identify, assess, and mitigate complex security risks.
- In-depth knowledge and practical experience with data privacy regulations such as GDPR and Privacy Shield.
- Experience in training, mentoring, or leading other compliance professionals.
- Proficiency with data visualization tools like Looker or Tableau, and basic scripting skills (e.g., Python) for data analysis or automation.
- BS in Computer Science, Information Systems, IT, or equivalent practical experience.
Top Skills
What We Do
ActiveCampaign helps small teams power big businesses with the must-have platform for intelligent marketing automation. Customers from over 170 countries depend on ActiveCampaign’s mix of pre-built automations and integrations (including Facebook, Google, WordPress, Salesforce, Shopify, and Square) to power personalized marketing, transactional emails, and one-to-one CRM interactions throughout the customer lifecycle.
ActiveCampaign holds the highest customer satisfaction rating among Marketing Automation, E-Commerce Personalization, Landing Page Builders, and CRM solutions on G2.com and is one of only a handful of software solutions with over 10,000 positive reviews. ActiveCampaign has also been named the Top Rated Email Marketing Software on TrustRadius. Learn more and start your free trial at ActiveCampaign.com.
Why Work With Us
We are focused on our employees, our customers, and even our customer's customers. Ideas are valued over titles, contributions are valued over appearances, helping a co-worker is more important than outshining them. We are passionate about diversity and inclusion, believing everyone has a voice and can make a difference.
Gallery
