Head of Trust and Secirty

Head of Trust and Secirty

Vollzeit 90000 - 120000 € / Jahr (geschätzt) Homeoffice (teilweise)
F

Auf einen Blick

  • Aufgaben: Leite die Sicherheits- und Compliance-Strategien für innovative rechtliche KI-Lösungen.
  • Unternehmen: Filevine, ein schnell wachsendes Unternehmen im Bereich Legal AI mit einem dynamischen Team.
  • Vorteile: Wettbewerbsfähige Vergütung, Gesundheitsleistungen und die Möglichkeit, remote zu arbeiten.
  • Weitere Informationen: Exzellente Karrierechancen in einem innovativen und unterstützenden Arbeitsumfeld.
  • Warum dieser Job: Gestalte die Zukunft der Rechtsbranche mit modernster Technologie und einem starken Team.
  • Qualifikationen: Mindestens 10 Jahre Erfahrung in Sicherheits-Compliance und Führung in technologieorientierten Umgebungen.

Das prognostizierte Gehalt liegt zwischen 90000 - 120000 € pro Jahr.

Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work.

Grounded in a singular system of truth, Filevine brings together data, documents, workflows, and teams into one unified platform—where modern legal work happens with clarity and consistency.

  • Powered by
  • LOIS

, the Legal Operating Intelligence System, Filevine connects context across every matter to transform legal operations from reactive to proactive.

LOIS reads, understands, and reasons across your data to surface insight, automate complexity, and give professionals the clarity and confidence to see more, know more, and do more.

Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country.

Role Overview

The Head of Trust, Security Compliance, Privacy & Fed RAMP is a senior leadership role accountable for Filevine’s highest-trust security, compliance, privacy, and government authorization initiatives.

This leader owns the operating system that turns regulatory obligations, customer commitments, security risk, and privacy requirements into prioritized, shipped work across Engineering, Security, Product, Legal, Sales, and Customer‑facing teams.

This is not a coordinator role.

The leader will own Filevine’s Fed RAMP 20x Moderate strategy and execution, with dedicated engineering resources assigned specifically to Fed RAMP compliance.

They will set the compliance engineering roadmap, define evidence and automation requirements, drive cross‑functional execution, and hold stakeholders accountable for measurable outcomes.

The first mission for this role is to accelerate Filevine’s Fed RAMP 20x Moderate readiness and ongoing compliance posture as meausered by booked ARR, logos closed, pipeline conversion and customer adoption.

This includes evidence automation, control implementation, continuous monitoring, vulnerability and remediation governance, POA&M discipline, 3PAO and Fed RAMP PMO engagement, agency‑facing readiness, and executive‑level risk reporting.

Beyond Fed RAMP, this leader owns Filevine’s broader trust and compliance stack, including security compliance, privacy operations, customer trust commitments, audit readiness, and the internal processes that keep these programs scalable.

They must be able to operate at both strategic and execution levels: translating regulatory frameworks into technical work, aligning leaders around risk‑based priorities, and communicating clearly with executives, auditors, customers, and engineering teams.

Operating in a hypergrowth legal‑tech and AI environment, the role requires technical judgment, executive presence, strong prioritization instincts, and the ability to build durable compliance systems rather than one‑time audit artifacts.

Key Responsibilities

  • Fed RAMP & Government Compliance Leadership
  • Own Filevine’s Fed RAMP 20x Moderate strategy, delivery plan, certification readiness, and ongoing compliance posture.
  • Lead the design and execution of Fed RAMP evidence automation, continuous monitoring, and reporting required for Marketplace certification and sustained authorization.
  • Serve as the single‑threaded owner for Fed RAMP engagements with 3PAOs, the Fed RAMP PMO, agency stakeholders, and internal executive sponsors.
  • Set the roadmap and priorities for dedicated Fed RAMP engineering resources, ensuring regulatory requirements become shipped technical controls, automated evidence, and operationally sustainable processes.
  • Own POA&M governance, risk acceptance workflows, certification readiness reporting, and remediation planning across product and platform teams.
  • Ensure Fed RAMP implementations are pragmatic, risk‑based, technically grounded, and appropriately scoped for Filevine’s architecture, maturity, and business priorities.
  • Provide clear, consistent executive reporting on progress, risk, tradeoffs, dependencies, resourcing needs, and certification readiness.
  • Security Compliance & Trust Program Ownership
  • Own the operating model for Filevine’s security compliance and trust programs across Fed RAMP, SOC 2, ISO, HIPAA, PCI‑DSS, customer security commitments, and related frameworks.
  • Partner with the CISO, Security Engineering, Product, and Infrastructure leaders to convert compliance obligations and security findings into prioritized engineering work.
  • Drive governance for vulnerability findings from scanning tools, penetration tests, customer reviews, audits, and bug bounty programs, including risk adjustment, remediation ownership, escalation, and executive tradeoff decisions.
  • Maintain a single source of truth for security/compliance status, control gaps, remediation commitments, and customer‑facing trust claims.
  • Ensure trust center materials, customer security responses, sales enablement messaging, and public compliance claims are accurate, current, and defensible.
  • Privacy Operations & Data Governance
  • Own Filevine’s operational privacy program in partnership with Legal, Security, Product, Marketing, and Engineering.
  • Oversee privacy tooling and workflows, including consent management, cookie compliance, data subject request operations, data mapping, subprocessors, retention, and privacy‑by‑design review processes.
  • Translate privacy obligations and customer commitments into product, engineering, and operational requirements.
  • Partner with Legal on DPAs, subprocessors, customer privacy commitments, and regulatory changes that affect Filevine products and data practices.
  • Support AI and data governance efforts by ensuring privacy, security, and customer trust requirements are reflected in product and operational decisions.
  • Product & Compliance Engineering Execution
  • Translate security, compliance, Fed RAMP, and privacy requirements into roadmaps, epics, milestones, and prioritized engineering work.
  • Batch, sequence, and present initiatives through Agile ceremonies, planning forums for prioritization against company‑wide initiatives.
  • Define success metrics, delivery milestones, ownership models, and operating cadences across long‑running, multi‑quarter initiatives.
  • Drive alignment between compliance goals, engineering capacity, product strategy, customer commitments, and business risk.
  • Partner with engineering leaders to scope work deeply enough that teams understand the control objective, technical requirement, evidence expectation, and business priority.
  • Cross‑Functional & Executive Leadership
  • Drive alignment across Engineering, Product, Security, Legal, Compliance, Sales, Marketing, Customer Success, and executive leadership teams.
  • Clearly communicate scope, sequencing, dependencies, risks, and tradeoffs across a large and evolving portfolio of work.
  • Continuously rebalance priorities in response to customer demands, federal market requirements, audit findings, product strategy, and changing risk posture.
  • Lead change management efforts to embed security, privacy, compliance, and Fed RAMP requirements into Filevine’s operating model and product culture.
  • Escalate effectively when tradeoffs require executive decision‑making, budget, staffing, or scope changes.

Qualifications

Education

Bachelor’s degree or equivalent practical experience.

Experience

  • 10+ years of experience in security compliance, GRC, product/program leadership, privacy, trust, or related roles within Saa S, cloud, or high‑trust technology environments.
  • Direct ownership of Fed RAMP Moderate, Fed RAMP High, Fed RAMP 20x, or a comparable federal cloud authorization program.
  • Proven experience translating regulatory, security, and privacy requirements into technical implementation plans with engineering teams.
  • Experience leading complex, cross‑functional initiatives with executive visibility, ambiguous requirements, and multi‑quarter delivery timelines.
  • Experience partnering with security engineering, infrastructure, product, legal, audit, and customer‑facing teams.

Skills

  • Deep knowledge of Fed RAMP, NIST 800‑53, Fed RAMP 20x automation concepts, continuous monitoring, POA&M governance, 3PAO engagement, and federal cloud authorization workflows.
  • Strong working knowledge of security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, PCI‑DSS, and customer security review processes.
  • Strong working knowledge of privacy operations, consent management, data governance, DSR workflows, subprocessors, DPAs, retention, and privacy‑by‑design practices.
  • Ability to translate regulatory and security requirements into actionable, value‑driven product and engineering work.
  • Strong product and program management expertise, including roadmap development, prioritization, milestone definition, and executive reporting.
  • Pragmatic, analytical approach to risk management and decision‑making in fast‑paced environments.
  • Excellent stakeholder management, written communication, and executive presence.
  • Comfort operating with dedicated engineering resources while remaining accountable for prioritization, clarity, outcomes, and risk‑based tradeoffs.
  • Preferred
  • Experience with Fed RAMP 20x, evidence automation, GRC engineering, compliance‑as‑code, or continuous control monitoring.
  • Experience supporting federal, state, healthcare, insurance, legal, or other regulated enterprise customers.
  • Certifications such as CISSP, CISM, CISA, CRISC, PMP, or similar are a plus.

Filevine is an Equal Opportunity Employer.

Qualifications for employment, promotion and other terms and conditions of employment are based upon the ability to perform the job.

Equal-employment opportunities are provided to all applicants and employees without regard to race, creed, religion, color, age, national origin, sex, disability, veteran status, or other legally protected class.

Filevine is committed to providing reasonable accommodations for qualified individuals with disabilities.

If you need assistance or accommodation due to disability, or if you have concerns related to Filevine’s equal employment opportunities, you may contact us at legal@filevine. com

Cool Company Benefits

  • A dynamic, rapidly growing company, focused on helping organizations thrive
  • Medical, Dental, & Vision Insurance (for full‑time employees)
  • Competitive & Fair Pay
  • Maternity & paternity leave (for full‑time employees)
  • Short & long‑term disability
  • Opportunity to learn from a dedicated leadership team
  • Top‑of‑the‑line company swag
  • Privacy Policy Notice

Filevine will handle your personal information according to what’s outlined in our Privacy Policy.

Communication about this opportunity, or any open role at Filevine, will only come from representatives with email addresses using “filevine. com”.

Other addresses reaching out are not affiliated with Filevine and should not be responded to.

#J-18808-Ljbffr

Head of Trust and Secirty Arbeitgeber: Filevine

Filevine ist ein hervorragender Arbeitgeber, der in einem dynamischen und schnell wachsenden Umfeld der Legal-Tech-Branche tätig ist. Mit einem starken Fokus auf Innovation und Teamarbeit bietet das Unternehmen nicht nur wettbewerbsfähige Vergütungen und umfassende Sozialleistungen, sondern auch zahlreiche Möglichkeiten zur beruflichen Weiterentwicklung und zum Lernen von einer engagierten Führungsebene. Die Unternehmenskultur fördert Zusammenarbeit und Kreativität, was es zu einem attraktiven Arbeitsplatz für Fachkräfte macht, die einen bedeutenden Einfluss auf die Zukunft der Rechtsbranche haben möchten.

F

Kontaktdaten:

Filevine Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Head of Trust and Secirty erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Filevine kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Filevine zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Filevine.

Wir glauben, dass du diese Fähigkeiten brauchst, um Head of Trust and Secirty mit Bravour zu bestehen

FedRAMP
Compliance Engineering
Security Compliance
Privacy Operations
Data Governance
Risk Management
Stakeholder Management

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Filevine vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Filevine könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Filevine sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Filevine auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!