Padmi
Filevine logo
Filevine

Legal AI · Legal Operating Intelligence System (LOIS)

Head of Trust and Security

Remote · United States$190k–$210k/yrPosted 11 days ago
SecurityStaff+Full Time
Apply at Filevine

Opens the source posting on jobs.lever.co

Source description

About the role

View original

FedRAMP & Government Compliance Leadership

Own Filevine’s FedRAMP 20x Moderate strategy, delivery plan, certification readiness, and ongoing compliance posture.

Lead the design and execution of FedRAMP evidence automation, continuous monitoring, and reporting required for Marketplace certification and sustained authorization.

Serve as the single-threaded owner for FedRAMP engagements with 3PAOs, the FedRAMP PMO, agency stakeholders, and internal executive sponsors.

Set the roadmap and priorities for dedicated FedRAMP engineering resources, ensuring regulatory requirements become shipped technical controls, automated evidence, and operationally sustainable processes.

Own POA&M governance, risk acceptance workflows, certification readiness reporting, and remediation planning across product and platform teams.

Ensure FedRAMP implementations are pragmatic, risk-based, technically grounded, and appropriately scoped for Filevine’s architecture, maturity, and business priorities.

Provide clear, consistent executive reporting on progress, risk, tradeoffs, dependencies, resourcing needs, and certification readiness.

Security Compliance & Trust Program Ownership

Own the operating model for Filevine’s security compliance and trust programs across FedRAMP, SOC 2, ISO, HIPAA, PCI-DSS, customer security commitments, and related frameworks.

Partner with the CISO, Security Engineering, Product, and Infrastructure leaders to convert compliance obligations and security findings into prioritized engineering work.

Drive governance for vulnerability findings from scanning tools, penetration tests, customer reviews, audits, and bug bounty programs, including risk adjustment, remediation ownership, escalation, and executive tradeoff decisions.

Maintain a single source of truth for security/compliance status, control gaps, remediation commitments, and customer-facing trust claims.

Ensure trust center materials, customer security responses, sales enablement messaging, and public compliance claims are accurate, current, and defensible.

Privacy Operations & Data Governance

Own Filevine’s operational privacy program in partnership with Legal, Security, Product, Marketing, and Engineering.

Oversee privacy tooling and workflows, including consent management, cookie compliance, data subject request operations, data mapping, subprocessors, retention, and privacy-by-design review processes.

Translate privacy obligations and customer commitments into product, engineering, and operational requirements.

Partner with Legal on DPAs, subprocessors, customer privacy commitments, and regulatory changes that affect Filevine products and data practices.

Support AI and data governance efforts by ensuring privacy, security, and customer trust requirements are reflected in product and operational decisions.

Product & Compliance Engineering Execution

Translate security, compliance, FedRAMP, and privacy requirements into roadmaps, epics, milestones, and prioritized engineering work.

Batch, sequence, and present initiatives through Agile ceremonies, planning forums for prioritization against company-wide initiatives.

Define success metrics, delivery milestones, ownership models, and operating cadences across long-running, multi-quarter initiatives.

Drive alignment between compliance goals, engineering capacity, product strategy, customer commitments, and business risk.

Partner with engineering leaders to scope work deeply enough that teams understand the control objective, technical requirement, evidence expectation, and business priority.

Cross-Functional & Executive Leadership

Drive alignment across Engineering, Product, Security, Legal, Compliance, Sales, Marketing, Customer Success, and executive leadership teams.

Clearly communicate scope, sequencing, dependencies, risks, and tradeoffs across a large and evolving portfolio of work.

Continuously rebalance priorities in response to customer demands, federal market requirements, audit findings, product strategy, and changing risk posture.

Lead change management efforts to embed security, privacy, compliance, and FedRAMP requirements into Filevine’s operating model and product culture.

Escalate effectively when tradeoffs require executive decision-making, budget, staffing, or scope changes.

More at Filevine

Related open roles

View all roles