Senior Director, Information Security and Compliance
Posted 3hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior security leader advancing Foundant’s SaaS information security and GRC programs. Protecting mission-critical software serving foundations, nonprofits, and community organizations worldwide.
Responsibilities:
- Own and drive the maturity of Foundant's information security and GRC program end to end
- Set the strategic security and compliance roadmap across five products and every region served
- Lead and develop the Head of Technical Security and Head of GRC
- Align technical security and GRC teams around reducing risk and building a security-first culture
- Serve as Foundant's executive voice during security incidents
- Communicate with clients, leadership, and regulators during incidents
- Build and mature GRC policies, risk registers, control frameworks, and audits
- Ensure compliance across US, Canadian, European, UK, and Australian regulatory requirements
- Partner with Product and Engineering leaders to embed security and privacy by design across all product lines
- Develop and present security and compliance metrics to executive leadership and the Board
- Translate technical risk into business impact and clear priorities
- Own third-party and vendor risk management
- Represent Foundant's security posture to clients and prospects during enterprise sales cycles, security reviews, and due-diligence questionnaires
- Perform other duties as assigned
Requirements:
- 8+ years of progressive leadership experience in information security and/or governance, risk, and compliance (GRC)
- Experience leading both technical security and compliance functions
- Experience building or maturing a security and compliance program for a multi-product SaaS company
- Experience navigating international regulatory and compliance frameworks, including GDPR, UK GDPR, Australian Privacy Act, SOC 2, and ISO 27001
- Experience leading security incident response programs
- Experience serving as a public-facing or client-facing spokesperson during incidents
- Experience managing and developing senior technical and compliance leaders
- CISSP, CISM, or CRISC preferred, but not required
- No specific degree requirement; equivalent professional experience is accepted
- Must be legally eligible to work in the United States
Benefits:
- Competitive salary and benefits
- Tuition reimbursements
- Lifestyle reimbursements
- Bespoke mindfulness initiatives
- Bespoke fitness initiatives
- Flexible PTO policy
- Professional and personal development opportunities
- Cross-team collaboration and exposure to diverse ideas, expertise, and projects
- Career growth and internal mobility opportunities
- Autonomy and responsibility
- Employee recognition
- Workplace accommodations throughout the interview and employment process




















