Source description
About the role
Compliance Program Ownership
Own and manage Hevo's compliance certifications end-to-end — including SOC 2 Type II, ISO 27001, GDPR, and any other applicable frameworks — across audit cycles, evidence collection, and remediation
Lead internal readiness assessments and gap analyses against compliance frameworks; define and drive remediation roadmaps in partnership with Engineering and Infrastructure teams
Serve as the primary point of contact for external auditors, certification bodies, and customer security review teams
Respond to customer security questionnaires, due diligence requests, and vendor assessments with accuracy and speed
Security Engineering & Controls
Design, implement, and continuously improve security controls across Hevo's cloud infrastructure, access management, data handling, and software development lifecycle (SDLC)
Collaborate with DevOps and Engineering teams to embed security and compliance requirements into CI/CD pipelines, infrastructure-as-code, and deployment practices
Conduct regular security risk assessments, vulnerability reviews, and internal audits — prioritizing findings and driving resolution within defined timelines
Define and enforce policies around data classification, access controls, encryption, logging, monitoring, and incident response
Policy & Governance
Develop, maintain, and operationalize security policies, standards, and procedures aligned with industry frameworks and Hevo's risk appetite
Build and run a compliance awareness and training program across the organization — making security and compliance a shared responsibility
Establish and maintain a continuous compliance monitoring framework using GRC tooling and automation where possible
Track and report on compliance metrics, audit findings, and risk posture to leadership on a regular cadence
Cross-Functional Collaboration
Partner with Product and Engineering to assess compliance implications of new features, integrations, and infrastructure changes early in the development cycle
Work with the Legal and Finance teams on contractual obligations, data processing agreements (DPAs), and regulatory requirements across geographies
Support Sales and Customer Success in closing security-sensitive deals by providing timely, accurate responses to enterprise security reviews
More at Hevo Data
