Skip to main content
Syllo

Data Security Compliance Director

RemoteUnited States onlyArchived
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Startup
$140k–$175k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Director of Data Security Compliance needed to own certification programs (ISO 27001, SOC 2 Type II), manage vendor security, and handle security disclosures for a legal tech company. Requires 5+ years in information security compliance, hands-on ISO 27001/SOC 2 audit management, and direct experience with engineering teams on control implementation. Must be technically fluent and organized under pressure.

Core skills

ISO 27001SOC 2 Type IIGRC

Required skills

NIST CSFCIS ControlsVantaDrataSecureframeTugboat LogicCloud IAMaccess controlloggingmonitoringCloudTrailSIEMendpoint managementencryptionAWSGCPAzure

Optional skills

legal industry data requirements

What you'll do

  • Maintain and continuously improve our Information Security Management System.
  • Manage internal audits, corrective actions, and annual surveillance cycles through Vanta.
  • Coordinate evidence collection, liaise with external auditors, and drive remediation across engineering and operations.
  • Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register.
  • Author, review, and update security policies, standards, and control mappings across frameworks.
  • Maintain alignment as the business scales.
  • Engage directly with engineering on control implementation — access reviews, logging pipelines, encryption configuration, and infrastructure hardening.
  • Respond to customer security questionnaires and due diligence requests.
  • Represent Syllo's security posture in enterprise sales conversations.
  • Run the formal risk assessment process.
  • Identify gaps, assign ownership, and track remediation to closure.
  • Coordinate security awareness training and phishing simulation programs.
  • Work with our Operations Engineering team and broader leadership to design and implement effective automations for as much of the security stack and responsibilities as can be automated.

What they require

  • 5+ years in information security compliance, GRC, or a closely related function
  • Hands-on experience managing ISO 27001 and SOC 2 audits — not just supporting them
  • Direct experience working with engineering teams on control implementation, log configuration, access reviews, or infrastructure hardening
  • Direct experience responding to and issuing VSQs and security questionnaires
  • Demonstrated technical experience and fluency
  • Familiarity with vendor risk management programs and tiering methodologies
  • Working knowledge of common control frameworks: ISO 27001, SOC 2, NIST CSF, CIS Controls
  • Hands-on experience with Vanta or a comparable GRC platform (Drata, Secureframe, Tugboat Logic) — we run ISO 27001 and SOC 2 through Vanta and you'll live in it daily
  • Cloud IAM and access control models, logging and monitoring pipelines (CloudTrail, SIEM fundamentals), endpoint management, and encryption at rest and in transit
  • Working knowledge of cloud-native environments (AWS, GCP, or Azure) and how controls apply in practice
  • Familiarity with legal or regulated-industry data requirements is a plus
  • Clear written communication — you'll be writing policies, audit responses, and customer facing materials
  • Technically fluent enough to engage in and evaluate critically architecture reviews and engineering threads, evaluate proposed control fixes, and identify gaps that a purely compliance-focused lens would miss
  • Organization under pressure — audit cycles don't move, and you'll manage multiple workstreams simultaneously
  • Collaborative — compliance happens through engineering, legal, and operations, not around them
  • Candidates with a technical background (engineering, infrastructure, DevSecOps) who have moved into GRC are strongly encouraged to apply.

Benefits

  • Base salary $140,000–$175,000, commensurate with experience
  • Equity participation
  • 100% remote — work from anywhere in the US
  • Health, dental, and vision coverage
  • Vacation, Sick, Paid Holidays

Syllo is defining the Litigation AI category. We are the first unified platform designed to autonomously manage the entire litigation lifecycle end-to-end.

LegalTechStartup
$140k–$175k/yr