Serve as the security and data privacy owner across all ACG Services SaaS products, including CLC Platform and ACE.
Perform architectural and design reviews to ensure security-by-design principles are applied consistently.
Provide formal security sign-off for software releases and major feature introductions.
Oversee integrated code and dependency security assessments, including vulnerability and penetration testing activities.
Own R&D adherence to security and compliance frameworks, including ISO 27001, SOC 2, PCI-DSS, and related customer security requirements.
Partner with IT/ISRM and Support to prepare for and support internal and external audits, customer questionnaires, and assessments.
Define, document, and continuously improve security processes spanning: Secure software development, Access control and identity management, Provisioning and deprovisioning, Incident response and escalation, Business continuity and disaster recovery.
Lead R&D security training and awareness programs for engineering teams.
Assess and integrate AI-aware security practices, including: Risk assessment of AI-enabled features, Secure use of models, training data, and inference pipelines, Alignment with emerging internal and external AI governance expectations.
Provide privacy assessment and oversight for new features and data use cases.
Requirements
Bachelor’s or Master’s degree in Computer Science, Computer Engineering, or a related technical field.
Demonstrated experience leading security and compliance for SaaS platforms in cloud-based environments.
Strong working knowledge of security and compliance frameworks such as ISO 27001, SOC 2, NIST, and GDPR.
Experience embedding security practices into software development lifecycles and product release processes.
Hands-on knowledge of: Threat modeling and risk assessment techniques
Vulnerability management and penetration testing approaches
Secure architecture and design reviews
Fluency in one or more common programming languages (e.g., Java, JavaScript, C#, or C++).
Experience working effectively with global, distributed engineering teams.
Strong written and verbal communication skills, with the ability to influence without authority.