Head of Security, Compliance & GRC jobs in United States
cer-icon
Apply on Employer Site
company-logo

Nametag · 6 days ago

Head of Security, Compliance & GRC

Nametag is building the future of secure digital identity, and they are seeking an experienced Security, Compliance & GRC leader to own and evolve their security and compliance program. This hands-on leadership role involves maintaining certifications, driving compliance initiatives, and collaborating with various teams to ensure security is integrated into the business.

Identity ManagementPrivacySecurity

Responsibilities

Own and maintain SOC 2 Type II certification, including evidence collection, control monitoring, and audit coordination
Drive IAL3 compliance readiness and implementation
Manage accessibility compliance (WCAG) requirements
Identify and pursue additional certifications as needed based on customer and market requirements
Coordinate penetration testing cycles and drive remediation with engineering
Maintain a living view of organizational risk and surface it to leadership
Develop and maintain security policies, procedures, and controls
Respond to security incidents with speed and clarity
Respond to customer security questionnaires promptly and accurately
Support sales in security-sensitive enterprise deals
Maintain public-facing trust documentation
Participate in customer security calls and reviews as needed
Partner with engineering to build security into the development process
Provide clear security guidance and timely reviews so teams can ship with confidence
Collaborate with product on security and accessibility features
Work with customer success to address customer security concerns

Qualification

SOC 2 Type IICompliance Program ManagementSecurity OperationsGRC Tooling KnowledgePenetration TestingIdentity VerificationTechnical FluencyKindnessBias for ActionNIST 800-63 StandardsCISSP CertificationCommunicationCollaboration SkillsIntegrity

Required

7+ years of experience in security, compliance, or GRC, with demonstrated ownership of SOC 2 Type II programs
Experience building or running compliance programs in startup or resource-constrained environments
Strong understanding of how auditors think - ideally from auditor-side experience or running multiple audit cycles
Technical fluency to read pen test reports, understand cloud architecture, and have informed conversations with engineers
Knowledge of GRC tooling and vendors, with opinions on what's worth investing in at different company stages
Excellent communication skills - able to translate security topics for executives, salespeople, and customers

Preferred

Experience with identity verification, authentication, or security-focused products is a strong plus
Familiarity with IAL2/IAL3 or NIST 800-63 identity proofing standards is a strong plus
CISSP, ISO 27001 Lead Auditor, or similar certifications are a plus but not required

Benefits

Competitive salary
Meaningful equity ownership
Comprehensive health benefits (medical, dental, vision)
Flexible paid time off
Quarterly team off-sites and travel support
New computer hardware and equipment
An inclusive environment where your voice has impact and your work drives change

Company

Nametag

twittertwittertwitter
company-logo
Nametag is the first identity verification platform for secure account recovery

Funding

Current Stage
Early Stage
Total Funding
unknown
2021-01-01Series Unknown

Leadership Team

leader-logo
Aaron Painter
CEO
linkedin
leader-logo
Ross Kinder
CTO
linkedin
Company data provided by crunchbase