Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Murphy-Hoffman Company (MHC Kenworth)

Director, Security & Compliance

Murphy-Hoffman Company (MHC Kenworth)

. Own renewal and continuous operation of the SOC 2 Type II report and serve as primary liaison to the audit firm .

Posted 10/9/2026full-timeRemote • Minnesota • United StatesLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing SOC 2 Type II programs, ensuring compliance with security standards such as HIPAA, PCI, and GDPR/CCPA. Proficient in developing security policies, risk management frameworks, and vendor assessments while effectively communicating with stakeholders.

Highest-signal resume keywords
SOC 2 Type II Program ManagementCompliance Automation ToolsVendor Risk ManagementData Governance PracticesAI Governance Frameworks

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Policy DevelopmentControl MonitoringEvidence CollectionRisk AssessmentData ClassificationIncident Response PlanningSecure Software Development LifecycleCompliance DocumentationAuditor ManagementAccess Control Standards
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationCredibility Building
Tools & Technologies
VantaDrataSecureframeCompliance Automation Platforms
Certifications & Qualifications
CISSPCISMCIPPCISA
Industry Keywords
SOC 2HIPAAPCIGDPRCCPAAI GovernanceNIST AI RMFOWASP LLM Top 10ISO 27001ISO 42001

About the role

Key responsibilities & impact
  • Own renewal and continuous operation of the SOC 2 Type II report and serve as primary liaison to the audit firm
  • Mature the control environment and reduce manual evidence collection
  • Develop, document, and operate controls aligned with SOC 2 Type II, HIPAA, PCI, and GDPR/CCPA
  • Work directly with auditors to ensure ongoing compliance
  • Expand the company's attestation footprint as needed
  • Serve as primary contact for customer security reviews, questionnaires, and due-diligence requests
  • Maintain the security policy suite, risk register, and incident response plan
  • Run tabletop exercises
  • Establish data classification, retention, and access-control standards
  • Partner with engineering on least-privilege access, encryption, and data lifecycle management
  • Develop and implement secure software development lifecycle policies and environmental and physical security standards
  • Own vendor and third-party risk management, including reviews of SaaS and AI tools
  • Assist Legal with security and data privacy contract negotiations
  • Build the company's AI governance framework, including acceptable use policies, model/vendor risk assessment, and oversight of AI data handling
  • Track emerging AI standards and translate them into practical controls
  • Partner with product and engineering on responsible AI practices
  • Provide security and compliance input on shadow AI risk
  • Advise the executive team and board on security and compliance posture
  • Partner with Sales and Customer Success during enterprise deals
  • Build out the security/compliance function

Requirements

What you’ll need
  • Bachelor’s degree in Computer Science, Information Security, or a related field
  • 6+ years of experience across security, compliance, IT/GRC, or risk management
  • At least 2+ years running a SOC 2 program day-to-day, including evidence collection, control monitoring, and auditor management
  • Direct, hands-on experience operating and renewing an existing SOC 2 Type II program
  • Working knowledge of data governance practices, including classification, retention, access review, and CCPA/GDPR
  • Familiarity with AI governance concepts and frameworks including NIST AI RMF, OWASP LLM Top 10, and ISO 42001
  • Experience writing policies and configuring compliance automation tools
  • Strong written and verbal communication skills
  • Experience with compliance automation platforms such as Vanta, Drata, Secureframe, or similar
  • Vendor/third-party risk assessment and management skills
  • Ability to build credibility with enterprise customers and prospects on security and trust topics
  • Candidates must be based in the United States
  • This role is not eligible for visa sponsorship
  • Preferred: CISSP, CISM, CIPP, or CISA
  • Preferred: Experience achieving or maintaining ISO 27001 or ISO 42001

Benefits

Comp & perks
  • Flexible, work-where-you-live model
  • 401(k) plan with deferred and Roth options
  • Employer match of 50% up to a maximum of 4.5% of gross pay
  • Comprehensive medical plans with co-pay or HSA coverage options
  • Dental and vision plans
  • Daycare and Medical FSA/HSA
  • $50,000 group term life insurance coverage
  • Generous paid time off (PTO) policies
  • Employee Assistance Program (EAP)
  • Additional life insurance
  • Critical illness insurance
  • Accident, cancer and hospital indemnity insurance
  • Legal/ID Shield
  • Pet insurance
  • Paid family or medical leave where provided by state programs
  • Four weeks of paid paternity leave after one year of employment, with partial eligibility beginning at six months, in states without a state program
  • Twelve weeks of paid leave for the birth parent, subject to eligibility rules