Head of Information Security

Posted 3 days ago

jobleadsusSeattle (WA)
Information Security AnalystsComputer Systems Design Services

SENIORITY

Manager

Apply

About the role

ResponsibilitiesOwn and scale the data security, compliance, and AI governance program for HumanlyEstablish, maintain, and continuously improve the policies, procedures, and controls that protect the company and drive adoption across every functionOwn the certification and audit roadmap and partner with engineering on secure SDLC, vulnerability management, and access governanceDesign and run the security awareness program - onboarding, annual training, phishing simulations, and role-based training for engineers and high-risk functionsOwn the security incident response plan and lead detection, containment, investigation, breach notification decisions, and post-incident review in partnership with legalMaintain and regularly test business continuity and disaster recovery plansOwn the privacy program across GDPR, CCPA/CPRA, including data subject rights workflows, DPAs, and sub-processor disclosuresBuild and operate the AI governance framework - model inventory, risk classification, review and approval, bias and fairness testing, and ongoing monitoringMaintain an enterprise risk register covering security, AI, privacy, and third-party risk, and drive periodic assessments and remediationOwn the security and trust narrative for prospects and customers, leading responses to RFIs, RFPs, and security questionnaires alongside GTMRequirements5+ years in information securityYou've owned a compliance program end-to-end and not just contributed to one. You know what it takes to get to SOC 2, and what comes afterYou've operated in a regulated environment (GDPR, CCPA, or similar) and understand privacy not as a legal checkbox but as a product and trust issueBuilder mindset. You can assess what's in place, decide what's worth keeping, and build what isn't there yet, without waiting for a team under youCommercial orientation. You've sat in customer calls, answered security questionnaires, and know how to turn trust into a revenue lever rather than a deal blockerAI governance experience, or strong familiarity with the emerging landscape. You understand the specific risks AI introduces in a data-sensitive product and have opinions on how to manage themTactical-to-strategic range. You can go from reviewing a vendor contract to advising leadership, and you're comfortable with bothAI fluency in your own work. You're already using AI tools to multiply your efforts, not just governing others' use of themHard Skillsinformation securitycompliance program managementSOC 2GDPRCCPAAI governancevulnerability managementsecurity incident responsebusiness continuity planningdisaster recoverySoft Skillsbuilder mindsetcommercial orientationtactical-to-strategic rangeleadershipcommunicationproblem-solvingcollaborationadaptabilitycritical thinkingcustomer engagement#J-18808-Ljbffr

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this