tlatechinc

tlatechinc

Data Security Compliance Director

New York, NY · Director · Full-time

Sponsorship not specified$140k-$175kDetected 7 hours ago
AWSGCPAzureRESTCybersecuritySIEMComplianceSalesOutbound SalesLeadershipCommunicationCISSP

About the role

  • Compliance isn't a checkbox here, it's a product feature.
  • This role sits at the intersection of compliance and engineering.

Responsibilities

  • SOC 2 Type II. Coordinate evidence collection, liaise with external auditors, and drive remediation across engineering and operations.
  • Vendor security. Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register.
  • Policy and controls. Author, review, and update security policies, standards, and control mappings across frameworks. Maintain alignment as the business scales.
  • Automation. Work with our Operations Engineering team and broader leadership to design and implement effective automations for as much of the security stack and responsibilities as can be automated.
  • Maintain and continuously improve our Information Security Management System.

Requirements

  • 5+ years in information security compliance, GRC, or a closely related function
  • Direct experience working with engineering teams on control implementation, log configuration, access reviews, or infrastructure hardening
  • Familiarity with vendor risk management programs and tiering methodologies Knowledge
  • Working knowledge of common control frameworks: ISO 27001, SOC 2, NIST CSF, CIS Controls

Nice to have

  • Hands-on experience with Vanta or a comparable GRC platform (Drata, Secureframe, Tugboat Logic) - we run ISO 27001 and SOC 2 through Vanta and you'll live in it daily
  • Cloud IAM and access control models, logging and monitoring pipelines (CloudTrail, SIEM fundamentals), endpoint management, and encryption at rest and in transit
  • Working knowledge of cloud-native environments (AWS, GCP, or Azure) and how controls apply in practice
  • Familiarity with legal or regulated-industry data requirements is a plus

Skills

  • Clear written communication - you'll be writing policies, audit responses, and customer facing materials
  • Collaborative - compliance happens through engineering, legal, and operations, not around them Credentials (one or more preferred)
  • Candidates with a technical background (engineering, infrastructure, DevSecOps) who have moved into GRC are strongly encouraged to apply.
  • Compensation and benefits
  • Base salary $140,000-$175,000, commensurate with experience
  • Equity participation
  • 100% remote - work from anywhere in the US
  • Health, dental, and vision coverage
  • Vacation, Sick, Paid Holidays
  • United States - Remote Pay Range
  • $140 - $175 USD

Compensation

  • Base salary $140,000-$175,000, commensurate with experience
  • ISO 27001. Maintain and continuously improve our Information Security Management System. Manage internal audits, corrective actions, and annual surveillance cycles through Vanta.

Company info

  • Syllo is a legal technology company building infrastructure that law firms and legal teams trust with sensitive data. Compliance isn't a checkbox here, it's a product feature.
  • Syllo is a legal technology company building infrastructure that law firms and legal teams trust with sensitive data.
  • What we're looking for
  • Syllo is on a mission to transform litigation.
  • Since going to market, we have gained a diverse group of enterprise customers, including some of the biggest law firms in the country, and we are quickly expanding.
  • We're looking for a Data Security Compliance Director who will own the compliance-side and business operations related to Company's data security function.

This listing is sourced directly from tlatechinc's careers page and normalized into a canonical job model.