- Maintain and extend encryption, key management and matter-level access controls
- Own SOC 2 Type II evidence collection and the annual penetration test
- Implement and verify data residency controls across US and India regions
- Respond to security questionnaires from firms and their corporate clients
What we are looking for
- 4+ years in application or cloud security
- Hands-on experience with SOC 2 or ISO 27001 control implementation
- Understanding of data residency and retention requirements in regulated contexts
Nice to have
- Experience in legal technology or healthcare
- CISSP, OSCP or equivalent