Jobedly Post a Job

Associate Director, Security & Compliance (US)

Code and Theory · New York, NY
Full-timeTechnologyTechnology$128,000–$173,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Associate Director Security Compliance role

Associate Director Security Compliance positions focus on delivering results in their domain. This page aggregates open Associate Director Security Compliance roles and what employers typically expect.

We are seeking an Associate Director, Security & Compliance to lead security, privacy, and compliance for our SaaS products and the client projects we deliver as an agency. You will own this capability end to end, from new business through implementation, certification, and ongoing monitoring. This role is central to how we win and deliver projects, protect client and company data, and earn trust through clear, high quality security and privacy practices. You will be responsible for audit readiness, ensuring applicable privacy requirements are met, and establishing the standards, processes, and tooling needed to run an effective security and privacy program. The Machine is the agentic operating system for marketing, built by Code and Theory. It plugs into the tools marketing teams use and turns disconnected workflows into a single intelligent system, connecting brand strategy, creative production, and media performance. The Machine helps power agencies across Stagwell's network and world-leading brands. WHAT YOU’LL DO Lead our security program across SaaS products and client projects, setting strategy, priorities, and measurable outcomes Lead SOC 2 Type II, ISO 27001, and ISO 42001 readiness and ongoing compliance, including control design, evidence processes, and auditor coordination. Own ISMS and AI governance documentation and oversight Lead privacy governance and operational practices, ensuring compliance with applicable requirements including HIPAA, GDPR, and CCPA/CPRA, and addressing data handling, contractual privacy terms, and privacy by design expectations Partner with delivery teams to embed security and privacy into how we build, with clear expectations, practical review gates, and patterns for common risks (identity, access, data handling, multi-tenancy, logging, and auditability) Establish a repeatable client engagement security plan for client work (environment segregation, access provisioning and deprovisioning, client data handling, incident coordination, and delivery requirements) Lead vendor security reviews, including due diligence for critical providers, remediation tracking, and ongoing monitoring Support customer assurance efforts including security questionnaires, RFPs, client security reviews, and maintaining trust artifacts and standard responses Maintain an incident response program (playbooks, escalation, exercises) and drive post incident improvements Build a security and privacy culture through clear guidance, lightweight training, and day to day partnership with teams WHAT YOU’LL NEED 8+ years of progressive experience in information security, including leadership in SaaS and/or professional services environments Strong understanding of modern application and cloud security fundamentals (identity and access, encryption and key management, logging and monitoring, vulnerability management) Demonstrated ownership of SOC 2 Type II and ISO 27001 programs from readiness through steady state operations Strong working knowledge of privacy requirements and practices, including HIPAA, GDPR, and CCPA/CPRA, and experience operationalizing privacy controls in product and client delivery contexts Experience building security and privacy processes that work in real delivery environments Clear communication skills, able to represent security and privacy with internal teams, auditors, and client stakeholders with differing levels of technical fluency Comfort operating across a geographically dispersed organization and coordinating work across time zones NICE TO HAVES Experience in an agency or consulting environment supporting multiple client projects in parallel Experience supporting AI-enabled products and data flows, including model and data risk considerations and familiarity with ISO 42001 Expertise in at least one major cloud platform (GCP, AWS, or Azure) and common SaaS security patterns Experience with security monitoring, incident response, and vulnerability management programs in production environments…

Salary estimate

$128,000 – $173,000/yr
Provided by the employer.

Skills for this role

AWSAzureGCPCommunicationLeadershipSecurity

Resume tips for Associate Director Security Compliance applicants

Interview preparation

Prepare concrete STAR-format stories that show Associate Director Security Compliance outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Associate Director Security Compliance problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Code and Theory

Code and Theory is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles