The Director of Cybersecurity & Compliance leads hands-on security and compliance operations for XpertDox, with responsibility for certification programs, control implementation, and audit readiness. This is an onsite role based in Scottsdale, Arizona.
Key Responsibilities
- Implement and maintain security and compliance controls supporting SOC 2 Type 2 , ISO 27001 , ISO 22301 , HIPAA , and HITRUST certification programs.
- Own evidence collection and continuous control monitoring, including preparation for and execution of third-party audits .
- Own enterprise client security questionnaires, maintain the answer library and trust documentation, and provide technical depth for client security reviews.
- Own role-based access control and manage provisioning and deprovisioning, including periodic access reviews across cloud, on-premise, and remote access. Ensure access governance for the global delivery team in India .
- Run multi-factor authentication (MFA) and single sign-on (SSO) operations.
- Own application and web platform security, including secure development practices, code and dependency scanning , and secrets management .
- Drive remediation of security findings with engineering teams.
- Run vulnerability management and operate endpoint and cloud security controls.
- Coordinate penetration testing and track findings through remediation.
Required Qualifications
- Relevant certification such as CISSP , CISM , CISA , GIAC , or Security+ .
- Hands-on experience implementing and evidencing SOC 2 Type 2 and ISO 27001 controls, ideally using GRC or continuous-monitoring tooling.
- 6+ years in cybersecurity and compliance, including hands-on ownership of security operations or a compliance program.
- Strong identity and access management experience, including RBAC , SSO , MFA , and periodic access reviews across cloud and hybrid environments.
- Application and web security experience, including secure development practices, code and dependency scanning, and vulnerability remediation.
- Experience in healthcare, health-tech, or another environment involving PHI .
- Experience completing enterprise client security questionnaires and supporting audits.
- Team leadership or senior individual-contributor experience.
Location and Work Schedule
This role is onsite at the Scottsdale, Arizona headquarters, Monday through Friday . The position is not remote or hybrid . You must relocate to the Scottsdale area before your start date. Travel is minimal.
Compensation and Incentives
- Base salary: $120,000 to $160,000 per year, commensurate with experience.
- Incentive stock options.
- Relocation assistance, reimbursed against receipts.
Benefits
- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- 401(k) with matching
- Unlimited PTO and parental leave
- Wellness program
- Friday lunch
- Snacks
- Relocation assistance, reimbursed against receipts
Director of Cybersecurity & Compliance in scottsdale at Unknown Company
This position is listed as full time and able to be worked remotely.