Product Security Assurance & Compliance; PSAC Manager
Listed on 2026-06-09
-
IT/Tech
Cybersecurity, Information Security
Secure Logix Product Security Assurance & Compliance Manager will own and drive the company's Product Security Assurance & Compliance (PSAC) Program. Organizationally embedded within Product and reporting to the SVP of Product, this role directly supports revenue growth, security posture improvement, and organizational resilience. While the primary workflow of this role is driven by the sales cycle and customer-facing security requirements, the PSAC Manager operates with cross‑functional accountability to Engineering, IT, Legal, and executive leadership — and maintains independence in the accuracy and integrity of all security assessments and responses, regardless of deal context.
This is a compliance, documentation, and program management role — not a hands‑on IT operations position. However, it demands deep product fluency. The PSAC Manager is expected to develop a thorough, systems‑level understanding of Secure Logix products and platform architecture, including how they handle data, authenticate users, integrate with customer environments, and expose potential security considerations.
Essential Duties and Responsibilities- Inventory all existing security policies, procedures, standards, and evidence artifacts across the organization.
- Identify duplicate, conflicting, or outdated documentation and consolidate into a single authoritative source of truth.
- Establish a version‑controlled, centralized documentation repository accessible to authorized personnel.
- Define and enforce documentation governance standards to prevent re‑fragmentation over time.
- Conduct a structured gap analysis mapped to relevant frameworks (NIST CSF, ISO 27001, CIS Controls, etc.) and customer requirements.
- Maintain a prioritized remediation roadmap with clear ownership, timelines, and measurable outcomes.
- Track remediation progress and provide regular status reporting to executive leadership.
- Use recurring questionnaire themes to proactively identify systemic gaps before they surface in customer engagements.
- Manage the full lifecycle of all inbound questionnaires (SPSRD, SIG, CAIQ, HECVAT, custom).
- Build and maintain a centralized repository of pre‑approved responses and supporting evidence artifacts to enable rapid, consistent turnaround.
- Collaborate with Engineering, IT, Legal, and executive leadership to gather accurate technical and policy information.
- Track all assessment timelines and ensure on‑time delivery to support active sales cycles.
- Leverage assessment responses to inform gap analysis and product‑level risk identification.
- Design and deploy an internal, self‑service security Q&A tool enabling any authorized Secure Logix employee to quickly retrieve accurate, pre‑approved answers to common security questions.
- Establish an escalation workflow: questions that do not return a sufficient answer are automatically flagged and routed to the PSAC Manager for resolution and knowledge‑base enrichment.
- Invest time to achieve a thorough understanding of Secure Logix product architecture, data handling, authentication mechanisms, and customer‑facing integrations.
- Maintain fluency sufficient to accurately map product behavior to security controls and framework requirements when responding to customer assessments.
- Identify product‑level security risks or deficiencies surfaced through customer questionnaires, assessments, or gap analysis.
- Submit product security improvement ideas through the formal Product Management process for prioritization and review.
- Collaborate with Product Management and Engineering to ensure new features and enhancements are evaluated against documented security policies prior to release.
- Sign‑off on feature releases to ensure compliance with documented security policies and practices.
- Lead planning, execution, and maintenance of security certifications including ISO 27001 and other frameworks as required.
- Manage certification project plans, timelines,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).