Head of Trust and Security
FilevineRemoteFull-time3w ago
AISecurityLegalOperationsGrowthPlatformremotecurated-jd
Job description
Head of Trust and Security at Filevine.
About the role
Filevine is seeking a senior leader to direct our security, compliance, privacy, and government authorization programs. You will manage the technical and operational roadmap that integrates regulatory requirements into our engineering and product workflows. This role focuses on driving high-stakes initiatives like FedRAMP 20x Moderate readiness while ensuring our broader trust programs remain scalable and effective.
Key facts
What you'll do
- Lead the strategy and execution for FedRAMP 20x Moderate certification and ongoing compliance.
- Direct dedicated engineering resources to build automated evidence collection and continuous monitoring systems.
- Act as the primary point of contact for 3PAOs, the FedRAMP PMO, and agency stakeholders.
- Manage vulnerability governance, risk acceptance workflows, and POA&M remediation planning.
- Oversee the operational privacy program, including data mapping, consent management, and privacy-by-design reviews.
- Align security and compliance objectives with product roadmaps and engineering capacity.
- Provide executive-level reporting on risk posture, audit readiness, and certification progress.
- Maintain the accuracy of customer-facing trust materials and security documentation.
Requirements
- Bachelor degree or equivalent professional experience.
- 10+ years of experience in GRC, security compliance, privacy, or product leadership within SaaS or cloud environments.
- Direct experience managing FedRAMP Moderate, High, or 20x authorization programs.
- Proven ability to convert complex regulatory frameworks into technical engineering requirements.
- Experience leading cross-functional teams through multi-quarter initiatives with high executive visibility.
- Strong knowledge of NIST 800-53, SOC 2, ISO 27001, HIPAA, and PCI-DSS.
- Expertise in privacy operations, including DSR workflows, DPAs, and subprocessor management.
Nice to have
- Specific experience with FedRAMP 20x, compliance-as-code, or GRC engineering.
- Background supporting regulated customers in federal, state, healthcare, or insurance sectors.
- Professional certifications such as CISSP, CISM, CISA, CRISC, or PMP.
Skills & tools
- FedRAMP 20x and federal cloud authorization workflows.
- Evidence automation and continuous control monitoring.
- Risk management and vulnerability remediation governance.
- Stakeholder management and executive communication.
- Agile project management and product roadmap development.
Practical notes
- Filevine provides medical, dental, and vision insurance, as well as maternity and paternity leave for full-time employees.
- The company offers competitive pay and professional development through a dedicated leadership team.
- All official communication regarding this role will originate from a filevine.com email address.
- Filevine is an equal opportunity employer and provides reasonable accommodations for qualified individuals with disabilities; inquiries can be directed to legal@filevine.com.