• Maintain and extend encryption, key management and matter-level access controls
• Own SOC 2 Type II evidence collection and the annual penetration test
• Implement and verify data residency controls across US and India regions
• Respond to security questionnaires from firms and their corporate clients
What we are looking for
• 4+ years in application or cloud security
• Hands-on experience with SOC 2 or ISO 27001 control implementation
• Understanding of data residency and retention requirements in regulated contexts
Nice to have
• Experience in legal technology or healthcare
• CISSP, OSCP or equivalent