tlatechinc
Data Security Compliance Director
New York, NY · Director · Full-time
Sponsorship not specified$140k-$175kDetected 7 hours ago
AWSGCPAzureRESTCybersecuritySIEMComplianceSalesOutbound SalesLeadershipCommunicationCISSP
About the role
- Compliance isn't a checkbox here, it's a product feature.
- This role sits at the intersection of compliance and engineering.
Responsibilities
- SOC 2 Type II. Coordinate evidence collection, liaise with external auditors, and drive remediation across engineering and operations.
- Vendor security. Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register.
- Policy and controls. Author, review, and update security policies, standards, and control mappings across frameworks. Maintain alignment as the business scales.
- Automation. Work with our Operations Engineering team and broader leadership to design and implement effective automations for as much of the security stack and responsibilities as can be automated.
- Maintain and continuously improve our Information Security Management System.
Requirements
- 5+ years in information security compliance, GRC, or a closely related function
- Direct experience working with engineering teams on control implementation, log configuration, access reviews, or infrastructure hardening
- Familiarity with vendor risk management programs and tiering methodologies Knowledge
- Working knowledge of common control frameworks: ISO 27001, SOC 2, NIST CSF, CIS Controls
Nice to have
- Hands-on experience with Vanta or a comparable GRC platform (Drata, Secureframe, Tugboat Logic) - we run ISO 27001 and SOC 2 through Vanta and you'll live in it daily
- Cloud IAM and access control models, logging and monitoring pipelines (CloudTrail, SIEM fundamentals), endpoint management, and encryption at rest and in transit
- Working knowledge of cloud-native environments (AWS, GCP, or Azure) and how controls apply in practice
- Familiarity with legal or regulated-industry data requirements is a plus
Skills
- Clear written communication - you'll be writing policies, audit responses, and customer facing materials
- Collaborative - compliance happens through engineering, legal, and operations, not around them Credentials (one or more preferred)
- Candidates with a technical background (engineering, infrastructure, DevSecOps) who have moved into GRC are strongly encouraged to apply.
- Compensation and benefits
- Base salary $140,000-$175,000, commensurate with experience
- Equity participation
- 100% remote - work from anywhere in the US
- Health, dental, and vision coverage
- Vacation, Sick, Paid Holidays
- United States - Remote Pay Range
- $140 - $175 USD
Compensation
- Base salary $140,000-$175,000, commensurate with experience
- ISO 27001. Maintain and continuously improve our Information Security Management System. Manage internal audits, corrective actions, and annual surveillance cycles through Vanta.
Company info
- Syllo is a legal technology company building infrastructure that law firms and legal teams trust with sensitive data. Compliance isn't a checkbox here, it's a product feature.
- Syllo is a legal technology company building infrastructure that law firms and legal teams trust with sensitive data.
- What we're looking for
- Syllo is on a mission to transform litigation.
- Since going to market, we have gained a diverse group of enterprise customers, including some of the biggest law firms in the country, and we are quickly expanding.
- We're looking for a Data Security Compliance Director who will own the compliance-side and business operations related to Company's data security function.
Apply directly at tlatechinc →Create a free account for alerts like thisView tlatechinc immigration profile
This listing is sourced directly from tlatechinc's careers page and normalized into a canonical job model.