This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Director of Security & Compliance will lead Tripleseat’s security vision and execution while ensuring the company meets its compliance obligations in a way that enables the business to scale. This strategic, hands-on role reports to the CTO and serves as the company’s foremost expert in information security - balancing modern cloud security practices, regulatory obligations (SOC 2, PCI DSS, GDPR, CCPA), and business velocity. This role is responsible for guiding the organization toward sustained compliance with applicable regulations and industry standards, while embedding a security-first mindset across engineering, product, and infrastructure. The Director will influence security architecture, risk frameworks, incident readiness, and third-party risk posture, acting as a key partner across technical and executive teams.
Job Responsibility:
Set, build, and maintain the overall security strategy for the company
Review and implement the tools needed to deploy the strategy
Build a security-aware culture
Communicate on security and compliance initiatives to Executive Management
Develop and Maintain a Strategic Compliance Roadmap
Oversee Regulatory Audit Readiness
Establish Compliance Metrics and KPIs
Policy and Framework Oversight
Risk Assessment Leadership
Third-Party and Sub-Processor Governance
Control Design and Validation
Incident Response Readiness
Privacy Program Leadership
Staff Awareness and Training Oversight
Documentation Review and Governance
Executive and Board Reporting
Advisory Support for Product and Engineering
Requirements:
Oversee team, vendors, and tools used to deliver the company's security strategy
Familiarity with tools like Drata, Tenable, and Deepwatch
Deep expertise in PCI DSS v4.0 (preferably SAQ D for service providers)
Familiarity with SOC 2 Trust Services Criteria
Strong command of global privacy regulations, including GDPR, UK DPA, CCPA, and CPRA
Experience drafting privacy policies, data processing agreements, and records of processing activities
Proven success in managing data subject access requests and other privacy rights workflows
Working knowledge of secure cloud architectures (e.g., AWS, encryption practices)
Understanding of relevant standards such as ISO 27001 and NIST SP 800-53/92
Excellent documentation and stakeholder communication skills
Demonstrated ability to lead vendor assessments and third-party compliance efforts
A customer-focused attitude and the ability to build rapport across teams
Nice to have:
Previous experience in a high-growth SaaS company or regulated industry
Certification in privacy or security (e.g., CIPP, CIPT, CISSP, or equivalent)
Experience with compliance automation platforms or GRC tools
What we offer:
Competitive Medical, Dental, and Vision Insurance
Company Paid Life Insurance, Short- and Long-Term Disability Plans