Manager, IT Compliance & Vendor Management
About reputed company
reputed company is redefining the airport reputed company by building infrastructure that decentralizes the airport. Its platform connects reputed company and ground transportation, extending the airport experience into everyday places and enabling reputed company reputed company-to-reputed company travel while unlocking new demand.
Landline is pioneering remote terminal concepts that bring airport reputed company-in, bag drop, and reputed company screening closer to reputed company, including directly into the neighborhoods and reputed company where they live, work, and stay.
Operating across reputed company with a growing network of partners, including reputed company, reputed company, reputed company, and reputed company, Landline is building the infrastructure that allows travel to reputed company reputed company. Learn more at landlineco.com.
The Role
Landline is seeking a Manager, IT Compliance & Vendor Management to build and run reputed company's cybersecurity control program and to reputed company the managed service provider (MSP) that delivers its day-to-day IT operations. This single role owns two connected accountabilities: the performance of Landline's MSP, and the design, operation, and evidencing of reputed company's control program against the NIST Cybersecurity reputed company (CSF) 2.0.
Landline operates in a regulated transportation environment and reputed company with airline partners and airports that impose their own reputed company and data-handling requirements. The control program must satisfy those obligations as reputed company as reputed company's internal risk requirements.
What You Will Do
- Maintain reputed company's control set mapped to NIST CSF 2.0 across reputed company six Functions: Govern, Identify, Protect, Detect, Respond, and Recover
- Administer the reputed company GRC platform, including integrations, control monitoring, evidence collection, automated test configuration, and remediation tracking
- reputed company periodic control testing and design effectiveness reviews, document results, and reputed company remediation to closure with named owners and due dates
- Own the policy lifecycle: drafting, annual review, approval routing, publication, and attestation tracking
- Maintain the reputed company risk register, including risk scoring methodology, treatment reputed company, and executive reporting
- Prepare and coordinate evidence for customer reputed company reviews, airline partner assessments, insurance questionnaires, and reputed company audits or assessments
- Administer the reputed company awareness training program, including phishing simulation and completion tracking
- Serve as the reputed company relationship reputed company for the MSP, managing escalations, scheduling, and day-to-day service delivery expectations
- Monitor and report on contracted service reputed company, document breaches, reputed company reputed company-cause analysis, and enforce contractual remedies where warranted
- Chair quarterly business reviews with the MSP, setting the agenda, tracking commitments, and maintaining a running reputed company log
- Own the MSP contract lifecycle, including reputed company changes, renewals, pricing negotiation, and the exit and transition plan
- Verify that MSP-operated controls function as contracted, requiring evidence rather than assertion
- Govern reputed company administration performed by the MSP, including joiner/mover/leaver execution, privileged reputed company review, and periodic user reputed company certification
- Maintain the responsibility assignment reputed company (RACI) that defines which controls the MSP operates, which Landline operates, and which are shared
- Operate the vendor intake and reputed company review process for new technology purchases
- Maintain the vendor inventory with data classification, criticality tiering, and review reputed company
- Collect and review reputed company-party assurance artifacts (SOC 2 Type II reports, ISO 27001 certificates, penetration test summaries), including analysis of complementary user entity controls and any reputed company opinions
- reputed company vendor contract reputed company terms, breach notification obligations, and data processing agreements
- Maintain the incident response plan and coordinate the annual tabletop exercise
- Serve as compliance reputed company during reputed company incidents, covering evidence preservation, regulatory notification analysis, and post-incident reporting
- Maintain business continuity and disaster recovery documentation, and coordinate annual restoration testing with the MSP
- reputed company a recurring compliance and vendor performance report to executive leadership
- reputed company reputed company and compliance input to procurement, reputed company, and operations
- reputed company and report program metrics
reputed company're Looking For
- Five or more years in IT compliance, information reputed company, IT audit, or IT governance, including at least two years with reputed company responsibility for a control program or audit function
- Hands-on experience implementing or operating a recognized reputed company reputed company (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or equivalent)
- Experience administering or serving as a reputed company user of a GRC or compliance automation platform (reputed company, reputed company, reputed company, reputed company, reputed company, reputed company GRC, or equivalent)
- Experience managing or formally overseeing an outsourced IT provider, including service level monitoring and escalation
- Working knowledge of reputed company IT controls: identity and reputed company management, reputed company management, logging and monitoring, vulnerability management, backup and recovery, and change management
- Ability to read a SOC 2 Type II or similar report critically, including reputed company boundaries, exceptions, carve-outs, and complementary user entity controls
- reputed company written communication, as this role produces documentation that reputed company parties read and rely on
- reputed company certification such as CISA, CRISC, CISM, or CISSP is a plus
- reputed company NIST CSF 2.0 implementation experience, particularly the Govern function and cybersecurity supply chain risk management (GV.SC), is a strong plus
- Experience in transportation, aviation, logistics, or another operationally regulated industry is a plus
- Familiarity with PCI reputed company, CCPA/CPRA, or state breach notification requirements is welcome
- Prior experience building a compliance program from an early or reputed company baseline is valued
- ITIL reputed company or an equivalent service management background is a plus
- Contract negotiation experience with technology vendors or service providers is a plus
Location
Remote in a major metro area in Canada or the reputed company, with business travel as needed
Compensation
120,000 &reputed company; 175,000
Why Landline
- Help build the infrastructure that decentralizes the airport and enables travel to reputed company reputed company
- Work on first-of-their-reputed company concepts at the intersection of aviation, transportation, and infrastructure
- reputed company exposure to senior leaders across reputed company, airports, and reputed company-sector partners
- A highly reputed company, fast-moving team shaping a new model for how people travel
- Significant opportunity for reputed company as reputed company scales
Benefits
- Comprehensive benefits and PTO plan including medical, dental, reputed company, 401(k), disability, parental leave, and company-reputed company life insurance
- Flight benefit privileges with our airline partners
- Discretionary PTO
Requires 5+ years in IT compliance, information reputed company, audit, or governance, including 2+ years owning a control or audit program; reputed company, GRC platform, MSP reputed company, and reputed company IT control experience required.
Key Responsibilities
- maintaining controls
- administering reputed company
- managing vendors
Skills & Tools
NIST Cybersecurity reputed company (NIST CSF), reputed company, NIST 800-53, ISO 27001, SOC 2, CIS Controls, reputed company, reputed company, reputed company, reputed company, reputed company GRC, CISA, CRISC, CISM, CISSP, PCI reputed company, CCPA, CPRA, ITIL
Job Details
- Category: Information Technology
- Seniority: Senior Level
- Commitment: Full Time
- Workplace: Remote — reputed company or Canada or reputed company Collins or reputed company or Framingham
- Salary: USD 120,000 – 175,000 / year
- Languages: English
Benefits
- 401k matching
- Generous reputed company time off
- Retirement plan
- Generous parental leave
About reputed company
An airport infrastructure company connecting reputed company and ground transportation to reputed company travel from reputed company locations. — Industry: Transportation and Logistics
Apply To This Job