CybersecurityJobs.io
← Back to all jobs

Job Description

The Director of Cybersecurity & Compliance leads hands-on security and compliance operations for XpertDox, with responsibility for certification programs, control implementation, and audit readiness. This is an onsite role based in Scottsdale, Arizona.

Key Responsibilities

  • Implement and maintain security and compliance controls supporting SOC 2 Type 2, ISO 27001, ISO 22301, HIPAA, and HITRUST certification programs.
  • Own evidence collection and continuous control monitoring, including preparation for and execution of third-party audits.
  • Own enterprise client security questionnaires, maintain the answer library and trust documentation, and provide technical depth for client security reviews.
  • Own role-based access control and manage provisioning and deprovisioning, including periodic access reviews across cloud, on-premise, and remote access. Ensure access governance for the global delivery team in India.
  • Run multi-factor authentication (MFA) and single sign-on (SSO) operations.
  • Own application and web platform security, including secure development practices, code and dependency scanning, and secrets management.
  • Drive remediation of security findings with engineering teams.
  • Run vulnerability management and operate endpoint and cloud security controls.
  • Coordinate penetration testing and track findings through remediation.

Required Qualifications

  • Relevant certification such as CISSP, CISM, CISA, GIAC, or Security+.
  • Hands-on experience implementing and evidencing SOC 2 Type 2 and ISO 27001 controls, ideally using GRC or continuous-monitoring tooling.
  • 6+ years in cybersecurity and compliance, including hands-on ownership of security operations or a compliance program.
  • Strong identity and access management experience, including RBAC, SSO, MFA, and periodic access reviews across cloud and hybrid environments.
  • Application and web security experience, including secure development practices, code and dependency scanning, and vulnerability remediation.
  • Experience in healthcare, health-tech, or another environment involving PHI.
  • Experience completing enterprise client security questionnaires and supporting audits.
  • Team leadership or senior individual-contributor experience.

Location and Work Schedule

This role is onsite at the Scottsdale, Arizona headquarters, Monday through Friday. The position is not remote or hybrid. You must relocate to the Scottsdale area before your start date. Travel is minimal.

Compensation and Incentives

  • Base salary: $120,000 to $160,000 per year, commensurate with experience.
  • Incentive stock options.
  • Relocation assistance, reimbursed against receipts.

Benefits

  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • 401(k) with matching
  • Unlimited PTO and parental leave
  • Wellness program
  • Friday lunch
  • Snacks
  • Relocation assistance, reimbursed against receipts

Similar Jobs