The opportunity
At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.
What you'll do
Program & Audit Ownership
Own and lead our ISO 27001 compliance program end-to-end, from certification: planning and internal audit through surveillance cycles and Statement of Applicability updates
Drive execution across our multi-program compliance portfolio spanning SOC 2,: PCI DSS, HIPAA, and NIST CSF, alongside global and international frameworks including UK Cyber Essentials, Spain ENS, and emerging EU regulations such as the Cyber Resilience Act (CRA), Radio Equipment Directive (RED), and NIS2
Serve as the primary liaison to external auditors, QSAs, and certification: bodies, managing the full audit lifecycle across concurrent engagements and keeping internal stakeholders aligned on timelines and deliverables
Risk, Policy & Stakeholder Advisory
Own the Security Risk Management Framework, ensuring risk identification,: treatment, and reporting activities are consistently managed, tracked, and communicated across the business
What they're looking for
- Lead the development, review, and maintenance of internal information: security and data protection policies, standards, and procedures, and drive policy awareness across the organization
- Build and maintain strong cross-functional relationships with Engineering,: Legal, Privacy, and Sales, advising on complex compliance requirements and translating technical risk into clear, actionable guidance for both technical and non-technical audiences
- Support review of security provisions in customer contracts, MSAs, and: security exhibits, partnering with Legal and Sales to provide clear, actionable security positions during negotiations
- Evidence, Automation & Tooling