Information Security & Compliance Manager (Remote)
Discovered View all jobs
- Abu Dhabi
- Permanent
- Full-time
- Own GDPR, CCPA, LGPD, and emerging data privacy regulations across 40+ markets.
- Maintain SOC 2 Type II certification (or lead first certification if not yet achieved).
- Prepare for ISO 27001 certification roadmap.
- Manage DPIAs (Data Protection Impact Assessments) for new features/markets.
- Be the go-to expert for client compliance questionnaires, security reviews, and audits.
- Ensure vendor compliance (AWS, payment processors, third-party APIs).
- Own enterprise client security reviews (infosec questionnaires, pen test reports, architecture reviews).
- Support sales team with security documentation, certifications, and client security calls.
- Build & maintain security collateral (security white papers, data flow diagrams, compliance matrices).
- Act as security liaison for enterprise clients (L'Oréal, Unilever, Estée Lauder).
- Negotiate data processing agreements (DPAs) and BAAs.
- Design and implement security policies, procedures, and controls.
- Conduct regular risk assessments and threat modeling.
- Manage vulnerability management program (pen tests, bug bounties, security scanning).
- Oversee incident response planning and execution.
- Drive security awareness training for engineering and ops teams.
- Monitor security tools (SIEM, CASB, endpoint protection) and respond to alerts.