Compliance and Privacy Officer
About Toku:
Toku is a prominent provider of compliance infrastructure tailored for crypto companies, facilitating token and stablecoin-based salary payments to employees while ensuring adherence to state, federal, and international tax regulations. The company boasts a client portfolio that encompasses nearly a third of the crypto firms listed on Robinhood.
Supported by significant funding of $26 million from well-known investors such as Blockchain Capital and Naval Ravikant, Toku is rapidly expanding to address the escalating demand for compliance solutions within the ever-evolving regulatory landscape.
As the Compliance and Privacy Officer at Toku, you will take charge of privacy and security programs, guaranteeing compliance with regulatory standards like GDPR, SOC2, and ISO 27001. This pivotal role demands a blend of technical proficiency and strategic project management skills to ensure adherence to regulations, data protection, and shape the compliance landscape in the dynamic crypto sector.
Responsibilities:
Oversee GDPR compliance practices and spearhead certification initiatives with TrustArc/eTrust.
Develop and execute privacy and security programs and risk assessments in alignment with regulatory norms like SOC2, GDPR, and ISO 27001.
Lead security and privacy program endeavors collaboratively across various teams.
Serve as a primary contact for privacy-related inquiries and audits.
Establish and implement security protocols to ensure data integrity and safeguarding.
Conduct system security audits and propel penetration testing.
Define access control measures, encryption standards, and secure data transfer protocols.
Spearhead vulnerability assessments and devise remediation strategies.
Collaborate with engineering teams to incorporate privacy-by-design and security-by-design principles.
Create company-wide privacy and security training programs.
Stay updated on evolving regulations and security threats to adjust strategies accordingly.
Desired Qualifications:
- Bachelor’s or Master’s degree.
- 4-8 years of experience in driving security/privacy engineering initiatives, business practices, and programs within fintech SaaS or HRIS/payroll platforms.
- Demonstrated expertise in managing GDPR, SOC2, or ISO 27001 implementations.
- Profound knowledge of encryption, authentication, and network security.
- Familiarity with compliance management platforms like TrustArc or Drata.
- Outstanding written and verbal communication skills to convey complex ideas clearly to diverse audiences.
Preferred Certifications:
- Certified Information Systems Security Professional (CISSP).
- Certified Information Privacy Professional (CIPP/E, CIPP/US).
- ISO 27001 Lead Implementercertification.
Benefits of Joining Toku:
- Play a pivotal role in shaping the future of compliance in the crypto space amid significant regulatory changes.
- Collaborate with forward-thinking clients and highly involved industry-leading investors.
- Join a swiftly expanding startup addressing market demands with a strong product-market fit.
- Competitive salary, equity opportunities, and a work culture supportive of remote arrangements.
As an equal opportunity employer, Toku is committed to fostering a diverse team encompassing a wide range of backgrounds, thoughts, and experiences. The recruitment process is unbiased, devoid of discrimination based on race, color, religion, gender identity, sexual orientation, age, national origin, disability status, protected veteran status, or any other legally safeguarded characteristics. Female applicants, minorities, LGBTQ+ individuals, and candidates from underrepresented backgrounds are strongly encouraged to apply.
We recommend the use of Rezi.ai to vet resume quality before submitting an application.
