Vice President of Information Security
Phenom
At Phenom, our purpose is to help a billion people find the right work through our AI-powered talent experience platform. We are redefining the HR tech space by providing innovative solutions that enable companies to recruit, develop, and manage their employees more effectively. As a rapidly growing global organization with over 1,500 employees across 6 countries, we foster a culture of creativity and continuous innovation. We are looking for a highly motivated, experienced, and curious VP of Information Security. The ideal candidate would have knowledge of software security, data privacy, information security, application security, and regulatory standards for a SaaS platform.
What you'll do
In this role, you will manage security programs, refine the current landscape and supervise the security & compliance team. You will also educate our employees and customers on Phenom’s security framework.
- Perform continuous development, manage, and execute the information security and compliance program, the training program, and the internal and customer vulnerability management program
- Ensure Phenom’s security and compliance program is effective, efficient, and remains updated.
- Manage the Information Security and Compliance team
- Monitor security threat and risk management feeds for concerns; evaluate coordination options, determine trusted personnel and perform remediation as necessary
- Monitor internal communication channels for indicators of security events or actions which have a possible security ramification, also enforce policy and procedure adherence
- Manage FedRAMP program and update FedRAMP assessment and authorization documents
- Manage assessments: SOC2, ISO, FedRAMP, NIST, etc.
- Troubleshoot vulnerability scans
- Address customer security survey requirements
- Work with Sales Team – be the Lead in assisting regarding security & privacy
- RFP & Proposals – contribute to technical sections of the RFPs and Proposals
- Able to run application scans for various Phenom applications and work with development to remediate vulnerabilities
- Completing risk assessments
- Conduct Manual Pen Testing on complex applications
- Apply ethical hacking standards to proactively identify issues
- Perform periodic third-party Risk Assessments
- Perform Internal Audits
- Assist in regulatory accreditation processes
What you've done
- 8+ years of experience in an information security role
- Strong understanding of security tools, technologies, and policies
- Good Application Security background
- A bachelor's degree in computer science, information systems, or a related field
- In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls
- Experience with compliance audits such as FedRAMP/FISMA and SOC 2/ISO
- Experience with SSAE-18/SOC 2 and familiarity with ISO control mapping
- Familiarity with security architecture and operational principles
- Solid understanding of network protocols
- Good understanding of GDPR, CCPA, Russia Data Privacy, and other global privacy regulations
- Prior experience in working with C-level individuals on the client's side
- Prior experience in application development (including Mobile) and SDLC processes is preferred
- Professional ethical hacking experience using one or more of the following tools: Fortify On-Demand, Tenable IO, SOAPUI, HIDS, and NIDS, DLP Solutions
- Preferred Certifications (not required) – CISA, Certified Ethical Hacker, others in-app security and/or data privacy domain
- Excellent verbal, written, and interpersonal communication skills
- Strong collaboration skills with the ability to positively influence and motivate teams
- Ability to work in a fast pace environment with minimal supervision
Salary
- Expected salary range $180,000 - $220,000
Please note the Salary range is subject to change in the future in accordance with Phenom’s policies
Benefits
- We want you to be your best self and to pursue your passions!
- Health and wellness benefits/programs to support holistic employee health
- Flexible hours and working schedules, as well as parental leave for new parents
- Growing organization with career pathing and development opportunities
- Tons of perks and extras in every location for all Phenoms!
#LI-DS1