SlipstreamJobsFresh Startup & VC-Backed Jobs

Director, Security Compliance and Trust

Motive - Remote - Remote - posted 2026-09-21

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 225,000 - 305,000 / annual

Motive empowers physical operations teams with AI-driven software for fleet, safety, and finance management. The company serves nearly 100,000 customers across transportation, logistics, construction, energy, field service, manufacturing, and public sector. As Director of Security Compliance and Trust, you will build and lead the compliance, privacy, and trust function reporting to the CISO. This is a hands-on leadership role where you will lead a small, senior, globally distributed team while personally contributing to policy writing, control design, audit fieldwork, and customer escalations. Key responsibilities include: - Own the compliance and privacy function end-to-end: org design, hiring, team development, and serving as senior authority on the control environment - Build an integrated control framework mapping ISO 27001/27701, SOC 1/2, PCI DSS, FedRAMP, GDPR, and CCPA/CPRA to avoid duplicate evidence collection - Manage the annual audit calendar, auditor relationships, and lead Motive's FedRAMP authorization from the ground up - Own privacy compliance operations including data subject rights, DPIAs, ROPA, and cross-border transfer mechanics for sensitive driver data (location, video, telematics, biometric-adjacent processing) - Drive regulatory readiness for new markets (Canada, EU, Mexico, South America) ahead of go-to-market, partnering on data residency and regional architecture - Serve as the face of Motive's security and privacy posture to customers, owning trust.gomotive.com, security questionnaire responses, and enterprise deal escalations - Architect an AI-first operating model for the function, personally building evidence automation, continuous control monitoring, and AI-assisted questionnaire response - Own the security policy and standards library, exceptions process, company-wide security training, and phishing simulation - Establish Motive's AI governance program across product and internal AI use, building against ISO/IEC 42001, NIST AI Risk Management Framework, and EU AI Act This role is central to enabling Motive's global expansion and making compliance a business enabler rather than a constraint. REQUIREMENTS: - 8+ years in security compliance, GRC, privacy, audit, or risk management, including 5+ years in leadership roles managing both people managers and senior individual contributors - Demonstrably hands-on: must have personally written policies, designed controls, built control mappings, sat through fieldwork, and answered customer questions recently (not a decade ago) - Proven ownership of multi-framework compliance programs at scale in cloud-native SaaS environments (ISO 27001, SOC 1/2, PCI DSS as core) - Deep, operational privacy experience across GDPR and CCPA/CPRA with hands-on ownership of DSAR operations, DPIAs, ROPA, and cross-border transfer mechanics (CIPP/E, CIPP/US, or CIPM certifications are a plus but demonstrated operational ownership is more important) - Experience standing up compliance and privacy in new international markets, ideally Canada, EU, Mexico, or Latin America (familiarity with PIPEDA, Law 25, LGPD, or Mexican LFPDPPP is a strong advantage) - FedRAMP experience, ideally having led an organization through authorization or Moderate/High readiness - Concrete, demonstrated use of AI to run compliance work (evidence collection, questionnaire response, control monitoring, policy drafting, audit preparation, regulatory gap analysis) — must be able to articulate what you built, what it replaced, and what it measurably changed - Demonstrated ownership of customer-facing trust functions (security reviews, questionnaires, trust portals, enterprise escalation) and experience leading globally distributed teams across multiple timezones - Working fluency in AI governance frameworks and a clear point of view on governing AI without blocking adoption - Experience supporting IPO readiness, SOX, or equivalent regulated-environment scrutiny is strongly preferred - Experience with sensitive personal data at scale is strongly preferred

Similar roles