Security Compliance Manager - Moodle US
United States - Remote
Moodle with us!
We're the world's most popular learning platform and we’re on a mission to empower educators to improve our world.
Find out about your new workplace...
Moodle is the world’s most trusted online learning solution. The engine of our ecosystem is Moodle LMS, the secure and customizable open source learning management platform used by over 250 million learners worldwide. Developed in conjunction with our community, Moodle LMS is complemented by an ecosystem of products including Moodle Workplace and a network of partners and services providing hosting, customizations and support. We also teach and support educators to create effective online learning experiences and share open education resources. Collectively, we empower educators to improve our world.
Moodle US, a newly formed US-based services division of Moodle Pty, provides services in learning design, implementation support, training, hosting, custom development, and support for Moodle LMS, Moodle Workplace, as well as other Moodle products.
We’ve built a passionate team of hard-working and driven people from all over the world, united by a shared belief in the ability of our platform to make a positive difference to our world. We respect our colleagues and value an open and innovative workplace, filled with integrity and of course a strong focus on education (yes, these are our company values!)
Find out more about us on our website.
What your new role can look like…
The Security Compliance Manager monitors activities obligated by the organization's framework requirements and governance practices. The individual supports the development and implementation of the security compliance programs, policies, auditing, and reporting practices for framework certification. They will ensure that the organization is in alignment with the relevant industry frameworks and standards, and proactively identifies and mitigates any compliance risks or gaps. The Compliance Manager also oversees the compliance audits, assessments, and remediation plans, and communicates effectively with internal and external stakeholders on the compliance status and issues.
Please note, as this role will be deeply involved in our Fed RAMP certification process, the individual hired must be a US person (citizen or legal permanent resident). They may be residing outside of the United States. Additional responsibilities involving global projects will require availability to meet with global stakeholders during alternative time zone working hours. Therefore, residence in UK or Europe may be preferred.
With the pace of Moodle, no two days will ever be the same! You will...
- Develop, implement and maintain security compliance programs for the global organization, including SOC 2, FedRAMP, and ISO 27001. This involves policy, process and technologies, and ensuring continuous compliance of active certifications.
- Help inform and improve the company’s global Governance Risk and Compliance Program where applicable.
- Create and oversee security policies and procedures as necessary for compliance success. Support adjacent teams where necessary.
- Perform routine analysis to proactively identify and mitigate compliance risk to the organization within the established Risk Tolerance and Risk Appetite Statements.
- Continuously monitor the security industry to remain current in approved regulations / statutory / frameworks and solutions for the Information Security Department.
- Upon request, conduct a comprehensive assessment of select regulations / statutory / frameworks; providing a summary report and associated analysis material to inform business strategy requirements.
- Continuously monitor, audit, evaluate and improve the technical controls under administration by this position.
- Establish performance indexes (KPI, OKR, KRI, etc) and other risk metrics for quantitative measurement.
- Conduct training sessions and workshops to educate employees about the latest information security and compliance policy updates and/or recommendations.
- Routinely interface with stakeholders and leaders for successful delivery of all services and programs under administration by this position.
- Be solutions oriented, highly organized and self motivated, with the ability to prioritize and achieve tight deadlines.
Requirements
This position embodies and promotes the department’s mission, goals and values:
- Mission:
- To reduce the probability of material impact due to a cyber event
- Goals:
- Support: Support the company strategy and objectives
- Protect: Protect the critical assets including reputation
- Comply: Comply with laws, regulations and industry standards
- Enable: Enhance company competitive position by securely supporting and enabling new products / services
- Educate: Effectively promote information security education
- Values
- Honesty
- Integrity
- Accountability
- Collaboration
- Continuous Improvement
We’d love to hear from you, especially if you can talk to us about your:
- Bachelor's Degree in a related field of study
- Certifications (CISM or equivalent)
- Security Frameworks (SOC 2, ISO 27001, CIS CSC, NIST 800-53)
- Regulations (FedRAMP, PCI-DSS)
- Process & Project Management (CompTIA Project+ or equivalent)
You’ll sweep us off our feet if you have:
- FAIR Fundamentals
- CISSP
- CIPP/E
- CRISC
Benefits
What's in it for you?
We’ve already talked about the importance we place on achieving our mission to empower educators to improve our world, our passion for our values and some of the cool things we are doing as a company.
So what about this?!
- Fully remote opportunity, working from home or wherever suits you
- Flexible work schedule
- Supportive, passionate, and fun team
- Culture that fosters personal growth and development
- Salary range of $120,000 - $135,000 per year, depending on experience and education
- Plus, we’ll provide you with a benefits package, including health insurance coverage, employer 401(k) contribution, paid time off, group term life, and much more
Moodle US is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind: Moodle US is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at Moodle US are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. Moodle will not tolerate discrimination or harassment based on any of these characteristics. Moodle encourages applicants of all ages.
Tags: Audits CIPP CISM CISSP Compliance CompTIA CRISC FedRAMP Governance ISO 27001 NIST NIST 800-53 OKR Open Source SOC SOC 2 Strategy
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.