San Francisco, California, United States; Santiago, Santiago Metropolitan Region, Chile; Somerville, Massachusetts, United States•Boston HQ
Remote
Mid Level
Full Time
about 1 year ago
ITInformation SecuritySecurityComplianceRisk ManagementData PrivacySOC 2ISO 27001GDPRAI Fluency
Requirements
- •Bachelor’s degree in Computer Science, Information Security, or related field
- •Strong communication skills with the ability to translate technical concepts into business language
- •Proven experience managing or supporting frameworks such as SOC 2 Type II, ISO 27001, and data privacy regulations like GDPR
- •Strong understanding of risk management, cloud security, and application security principles
- •Hands-on, proactive, and comfortable building processes from scratch in fast-paced environments
- •Experience interacting with clients or supporting commercial teams in security-related discussions
- •Self-starter with strong ownership, adaptability, and ability to thrive in high-growth environments
- •Comfortable working closely with engineering teams and understanding technical architectures
- •Demonstrated curiosity and ability to quickly learn and adopt new tools, including AI-driven solutions
- •Able to work onsite in Boston (MA), Menlo Park (CA) or Santiago (CL) office 4 days a week
What You'll Do
- •Own and evolve Topsort’s information security program, ensuring alignment with frameworks such as SOC 2 Type II, ISO 27001, and GDPR
- •Define, implement, and maintain policies, controls, and procedures
- •Act as the primary point of contact for clients and prospects on security and compliance topics
- •Support RFPs, security questionnaires, and trust discussions to enable commercial success
- •Design and implement risk management frameworks
- •Identify, assess, and mitigate security risks across systems, processes, and third-party vendors
- •Ensure compliance with global data privacy regulations
- •Partner with Product and Engineering to embed privacy-by-design principles across all solutions
- •Lead and coordinate internal and external audits, ensuring readiness and successful certification processes
- •Support incident response processes, monitor security posture, and continuously improve detection and prevention capabilities
- •Work closely with Engineering, Product, and Sales teams to ensure security is embedded into product development and client interactions
Nice to Have
- •Experience with AI-driven solutions to improve security processes, automate workflows, and increase efficiency
