ActiveCampaign
Actively Hiring
Email, marketing automation, and CRM tools to create incredible customer experiences
- B2B
- Scale StageRapidly increasing operations
- Top InvestorsThis company has received a significant amount of investment from top investors
- +2
Head of Global Security, Risk and Compliance
- Full Time
Posted: 3 days ago• Recruiter recently active
Visa Sponsorship
Not Available
RelocationAllowed
About the job
We are seeking an experienced Head of Security Engineering to join our growing SaaS company. Reporting to the CTO, you will be responsible for defining, executing and overseeing a holistic security strategy to safeguard our organization’s digital assets, protect customer data, and maintain trust in our brand. You will lead a team of security professionals and drive collaboration with engineering, product, and cross-functional stakeholders to integrate security across all aspects of our operations, aligning with business objectives and industry standards.
What your day could consist of:
- Define and lead product security initiatives in close connection to the needs of partners, customers, the market and overall company objectives.
- Lead a team of security professionals, including hiring, training, and performance management.
- Lead incident response efforts operating as the incident commander, coordinating with relevant stakeholders to resolve security incidents while communicating effectively throughout.
- Lead the IT team.
- Manage Third Party (e.g., vendor) Risk Assessment Program with IT.
- Manage stakeholder (customer, partner) security questionnaires and assessment processes. Interface with customer management as necessary.
- Manage threat and vulnerability management.
- Ensure an effective SSDLC is in place for engineering.
- Implement security controls and processes to protect the company's data and systems from external threats.
- Own the SOC2 audit, and lead work to implement ISO27001 certification.
- Conduct risk assessments and implement appropriate controls to mitigate identified risks.
- Stay up to date with the latest security technologies and best practices.
- Develop and maintain security policies, standards, and procedures.
- Develop and lead comprehensive security training programs across the organization to ensure all employees understand and adhere to security best practices, fostering a culture of proactive risk awareness and protection.
- Guide security engineering on InfoSec/AppSec standards, auditing, and penetration testing.
- Manage analysis of fraud vulnerabilities, control weaknesses, and gaps to mitigate and remediate significant issues, trends, and loss events.
What is needed:
- Bachelor's degree in computer science, information technology, or a related field.
- 10+ years of experience in information security, with at least 5 years in a senior leadership role.
- Expert in security technologies and best practices.
- Experience with security risk assessment and management.
- Experience with incident response and forensics.
- Experience with security in the cloud (e.g., AWS) is required.
- CISSP, CISM, CISA or other relevant security certification is a plus.
- Excellent communication and leadership skills.
- Experience building Internal Audit functions for SOC 2, ISO 27001, and PCI-DSS.
- Excellent understanding of vulnerability management and associated tools and solutions.
- Machine Learning Models understanding is a plus.
- Seeking candidates in Chicago or Indianapolis.
- Prior penetration testing experience is a plus.
About the company
ActiveCampaign
Actively Hiring
501-1000
SaaS
Small and Medium Businesses
- B2B
- Scale StageRapidly increasing operations
- Top InvestorsThis company has received a significant amount of investment from top investors
- Valuation $1B+This company has a valuation of $1B or more
- 4.2Work / Life BalanceEmployees rate ActiveCampaign 4.2/5 on Glassdoor for work / life balance
Perks
Best in class health benefits
ActiveCampaign offers best in class health benefits with zero or very favorable employee premium cost share.
401K match
Our 401k employer match is exceptionally generous with no vesting or wait period to contribute
Family medical leave
ActiveCampaign offers up to 12 weeks of unpaid, job-protected leave per year, as well as maintained health benefits, for any employee eligible under the Family and Medical Leave Act (FMLA).
Employee equity program
Through our employee equity program, employees can share in ActiveCampaign's growth and success
Flexible work schedule
We have enhanced our remote work environment including rolling out perks such as a quarterly home office stipend, virtual events, parent support and mental wellness resources such as free Calm subscriptions, and virtual team events
Open paid-time off
Enjoy open PTO
Paid sabbatical
Month-long, paid sabbatical for employees who have been with the company 5 years
Telehealth & wellness resources
Parent support and mental wellness resources such as free Calm subscriptions, team virtual wellness events (yoga, stretching, meditation), telehealth that includes free therapy sessions and even access to personalized life coaching through
Continuing education stipend
We offer $1500 annually for continuing education programs, conferences and other development programs
Allotted time for learning
Through our partnership with Udemy you can access 5,000 professional development courses.. Topics range from very technical to crucial soft skills to help you succeed in your role and grow your career
Paid VTO
ActiveCampaign offers 3 days of volunteer time off for all employee annually, and participates in volunteer events
Similar Jobs
Trade Desk
A media buying platform built for what matters