•
Build and own Pivotal’s security program
Establish the strategy, policies, processes, and roadmap that define Pivotal’s security posture. Identify the company’s most critical assets, prioritize risk accordingly, and build a program that scales alongside a fast-growing platform and team.
•
Partner with engineering to embed security into the platform
Work closely with engineering and infrastructure teams to ensure security is built into how we design, develop, and deploy — from cloud architecture and CI/CD pipelines to data access controls and third-party integrations. You’ll advocate for secure-by-design practices without slowing the team down.
•
Lead compliance and regulatory readiness
Own Pivotal’s approach to relevant compliance frameworks, including SOC 2 and HIPAA. Translate regulatory requirements into actionable engineering and operational controls, lead audit preparation, and serve as the primary point of contact during security reviews.
•
Stay ahead of the threat landscape
Keep a close eye on the evolving security environment — emerging threats, new attack vectors, regulatory changes, and industry best practices. Bring that awareness into how Pivotal prioritizes and evolves its defenses over time.
•
Interface with customers and external stakeholders
Represent Pivotal’s security program directly to customers, partners, and prospects. Answer security questionnaires, lead trust reviews, and give customers confidence that their data — and their providers’ data — is in safe hands.
•
Drive security awareness across the organization
Champion a security-conscious culture companywide. Work with teams outside of engineering — including finance, operations, and people — to ensure security practices extend beyond the codebase and into how the whole organization operates.
•
Develop guidelines for emerging technologies
As an AI-native company, Pivotal is actively building with and around LLMs and AI tooling. Help define the guardrails for responsible, secure use of these technologies — both in our product and in our internal workflows.