Summary
Join Fastly as a Technology Compliance Lead and help scale our technology compliance program to meet the evolving needs of our customers. This role will focus on maintaining a deep understanding of our platform and compliance obligations, responding to customer inquiries, managing audits, and refining our internal control framework. You will collaborate with internal and external stakeholders, including engineers, auditors, and customers. This individual contributor role reports to the Director, Technology Compliance and requires 5-7 years of relevant experience in security or compliance. Fastly offers a competitive salary, comprehensive benefits, and a flexible hybrid work model.
Requirements
- Have 5-7 years of security or compliance analysis, or assurance/advisory experience, including a focus on customer security communications and leading programs as an individual contributor
- Have a thorough understanding of technical environments, and the ability to communicate with subject matter experts about technical and operational security controls
- Have experience mapping and rationalizing controls to meet requirements across multiple information security/technology compliance standards (e.g., PCI DSS, HIPAA, ISO 27001, SOC 1/ SOC 2, FedRAMP, SOX IT General Controls)
- Hold a BS degree (in Management Information Systems, Computer Science, or a related field preferred)
- Have excellent written and verbal communication skills to communicate details of a security program to a wide spectrum of audiences, including customers
- Have strong analytical skills and attention to detail
- Have the ability to be self-directed and take initiative on projects and tasks, and in identifying gaps related to security controls, with minimal day-to-day oversight/direction
Responsibilities
- Maintain a deep understanding of our platform and its supporting infrastructure and processes, as well as how our compliance obligations apply to that environment
- Provide responses to and maintain reference material for customer inquiries and due diligence procedures that involve technology compliance and participate in discussions for security and compliance assessments
- Collaborate with Law on customer agreements and security addenda
- Manage customer audits
- Continuously confirm and refine Fastly’s internal control framework and related documentation (e.g., policies, procedures, narratives, training material), and contribute to ongoing controls development and improvement
- Actively identify and communicate control gaps; help the company develop and confirm remediation efforts
- Liaise with external auditors and internal partners to facilitate audit procedures and evidence gathering
- Support third party oversight processes, including security and compliance assessments of Fastly’s vendors and service providers
- Enhance internal reference and training material about our technology compliance program
Preferred Qualifications
- Have experience in ANY of these: CISA, CISM, CISSP, or related certification
- Have experience using governance, risk management, and compliance (GRC) tools
Benefits
- We offer a comprehensive benefits package including medical, dental, and vision insurance
- Family planning, mental health support along with Employee Assistance Program, Insurance (Life, Disability, and Accident), a Flexible Vacation policy and up to 18 days of accrued paid sick leave are there to help support our employees
- We also offer 401(k) (including company match) and an Employee Stock Purchase Program
- For 2025, we offer 11 paid local holidays, 11 paid company wellness days
- This role may be eligible to participate in Fastly’s equity and discretionary bonus programs
- Fastly currently embraces a largely hybrid model for most roles which allows employees flexibility to split their time between the office and home
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.