Syllo Logo

Syllo

Data Security Compliance Director

Posted One Month Ago
In-Office or Remote
Hiring Remotely in New York, NY
140-175 Annually
Senior level
In-Office or Remote
Hiring Remotely in New York, NY
140-175 Annually
Senior level
Lead and maintain ISO 27001 and SOC 2 programs, manage vendor security and VSQs, author policies, run risk assessments, coordinate audits and remediation, support engineering on control implementation, handle customer security questionnaires, run awareness and phishing programs, and drive automation of compliance workflows.
The summary above was generated by AI

About Syllo
Syllo is on a mission to transform litigation. Our product is an AI-powered litigation workspace that enables lawyers and paralegals to safely harness the power of language models throughout the litigation life cycle. Since going to market, we have gained a diverse group of enterprise customers, including some of the biggest law firms in the country, and we are quickly expanding. By reducing the expense of litigation industry-wide, we aim to improve access to high-quality representation and promote the alignment of legal outcomes with merit. We’re looking for a Data Security Compliance Director who will own the compliance-side and business operations related to Company’s data security function.
About the role
Syllo is a legal technology company building infrastructure that law firms and legal teams trust with sensitive data. Compliance isn't a checkbox here, it's a product feature. 
We're looking for a Data Security Compliance Director to own our certification programs, manage vendor security relationships and processes, own the accurate and timely completion of our security disclosures in the sales context, and keep our posture audit-ready year-round. This role sits at the intersection of compliance and engineering. While this role does not own the security of our technical stack from an engineering perspective, you will work directly with technical teams to implement controls, close evidence gaps, and translate technical postures and requirements into concrete and well communicated action.
Responsibilities
- ISO 27001. Maintain and continuously improve our Information Security Management System. Manage internal audits, corrective actions, and annual surveillance cycles through Vanta. 
- SOC 2 Type II. Coordinate evidence collection, liaise with external auditors, and drive remediation across engineering and operations. 
- Vendor security. Lead vendor security assessments, manage VSQ responses (inbound and outbound), and maintain a tiered vendor risk register. 
- Policy and controls. Author, review, and update security policies, standards, and control mappings across frameworks. Maintain alignment as the business scales. 
- Technical guidance. Engage directly with engineering on control implementation — access reviews, logging pipelines, encryption configuration, and infrastructure hardening. 
- Customer-facing compliance. Respond to customer security questionnaires and due diligence requests. Represent Syllo's security posture in enterprise sales conversations. 
- Risk management. Run the formal risk assessment process. Identify gaps, assign ownership, and track remediation to closure. 
- Awareness. Coordinate security awareness training and phishing simulation programs. 
- Automation. Work with our Operations Engineering team and broader leadership to design and implement effective automations for as much of the security stack and responsibilities as can be automated. 
What we're looking for
- 5+ years in information security compliance, GRC, or a closely related function 
- Hands-on experience managing ISO 27001 and SOC 2 audits — not just supporting them 
- Direct experience working with engineering teams on control implementation, log configuration, access reviews, or infrastructure hardening 
- Direct experience responding to and issuing VSQs and security questionnaires 
- Demonstrated technical experience and fluency • Familiarity with vendor risk management programs and tiering methodologies Knowledge 
- Working knowledge of common control frameworks: ISO 27001, SOC 2, NIST CSF, CIS Controls 
- Hands-on experience with Vanta or a comparable GRC platform (Drata, Secureframe, Tugboat Logic) — we run ISO 27001 and SOC 2 through Vanta and you'll live in it daily 
- Cloud IAM and access control models, logging and monitoring pipelines (CloudTrail, SIEM fundamentals), endpoint management, and encryption at rest and in transit
- Working knowledge of cloud-native environments (AWS, GCP, or Azure) and how controls apply in practice 
- Familiarity with legal or regulated-industry data requirements is a plus 
Skills
- Clear written communication — you'll be writing policies, audit responses, and customer facing materials 
- Technically fluent enough to engage in and evaluate critically architecture reviews and engineering threads, evaluate proposed control fixes, and identify gaps that a purely compliance-focused lens would miss 
- Organization under pressure — audit cycles don't move, and you'll manage multiple workstreams simultaneously 
- Collaborative — compliance happens through engineering, legal, and operations, not around them Credentials (one or more preferred) 
- CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent 
Candidates with a technical background (engineering, infrastructure, DevSecOps) who have moved into GRC are strongly encouraged to apply.
Compensation and benefits
- Base salary $140,000–$175,000, commensurate with experience 
- Equity participation 
- 100% remote — work from anywhere in the US 
- Health, dental, and vision coverage 
- Vacation, Sick, Paid Holidays

United States - Remote Pay Range
$140—$175 USD

Similar Jobs

Yesterday
Remote or Hybrid
174K-286K Annually
Expert/Leader
174K-286K Annually
Expert/Leader
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Leads global communications strategy for Mastercard’s Commercial and New Payment Flows business. Responsibilities include executive profiling, internal and external communications, media relations, digital and social activation, storytelling, events, product launch messaging, regional coordination, stakeholder advising, and communications measurement. The role builds relationships with financial services, payments, technology media, influencers, and analysts while strengthening Mastercard’s reputation and supporting senior leadership.
Top Skills: Communications Measurement ToolsDigital AssetsDigital PaymentsSocial Media
Yesterday
Remote or Hybrid
245K-335K Annually
Senior level
245K-335K Annually
Senior level
Fintech • Machine Learning • Payments • Software • Financial Services
Leads enterprise AI engineering strategy and multi-team delivery of scalable, responsible AI systems. Oversees foundation model training, LLM inference, similarity search, guardrails, evaluation, governance, observability, and production optimization. Establishes responsible AI standards, makes technology decisions, develops long-term platform roadmaps, partners with research and risk teams, and attracts and mentors engineering talent.
Top Skills: AWSAws UltraclustersAzureC#C++CudaGoGCPHugging FaceJavaPythonPyTorchVectordbs
Yesterday
Remote or Hybrid
245K-335K Annually
Expert/Leader
245K-335K Annually
Expert/Leader
Fintech • Machine Learning • Payments • Software • Financial Services
Leads data science for consumer and developer experiences, partnering with engineers and product managers to deliver customer-focused products. Builds, evaluates, validates, and deploys machine learning models using large-scale numerical and textual data. Applies statistical modeling, A/B testing, clustering, classification, sentiment analysis, time series, and deep learning while translating technical insights into business outcomes. The role also includes team leadership, talent development, and evaluating emerging AI and cloud technologies.
Top Skills: SparkAWSCondaGenerative AiH2OMachine LearningPythonRRelational DatabasesScala

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account