About the Role
Jeppesen ForeFlight is seeking a Security Assurance & Operations leader to own two critical functions within our Governance, Risk, and Compliance organization. This role serves as the single point of contact for all customer-facing security inquiries (including HECVAT, SIG, CAIQ, customer audits, and agency-specific questionnaires) while also supporting the operational governance of our compliance program to ensure documentation remains current and audit-ready between cycles.
As Jeppesen ForeFlight continues to grow its enterprise and public-sector customer base, the volume and complexity of security-related requests from customers, procurement teams, and government agencies has grown with it. This role is purpose-built to ensure those requests are handled with speed, consistency, and accuracy to protect both our customer relationships and our ability to compete in security-sensitive markets. This role reports directly to the Director of GRC with dotted-line working relationships across the Proposals Team, Sales, Engineering, Legal, and Product Security. This position is 100% remote, US-based. Limited travel may be required; not estimated to exceed 10% of the employee's time.
Position Responsibilities
- Serve as the single named point of contact for all inbound customer security questionnaires, assessment requests, customer audits, and agency-specific security inquiries routed to the Security Team
- Establish and own a structured intake, tracking, and response process for all customer-facing security requests to ensure consistent turnaround timeframes, clear ownership, and a single escalation path to support Sales.
- Lead completion of standard and custom security questionnaires including HECVAT, SIG, CAIQ, and customer-specific DDQs with appropriate SME input, owning each request through to delivery
- Own the security Q&A content within the organization's enterprise questionnaire management platform to ensure responses remain accurate and aligned with current security posture
- Manage Trust Center operational updates to reflect current certifications, policies, and security posture; handle customer requests for security documentation through appropriate NDA-gated channels
- Partner with the Proposals Team to embed security intake steps within existing proposal workflows, ensuring a seamless and consistent experience for Sales and customers
- Produce quarterly metrics on inquiry volume, response time, content reuse rates, and document review completion status for GRC leadership review
- Communicate effectively across Sales, Proposals, Engineering, Legal, and Product Security; represent GRC in cross-functional meetings and serve as an informal mentor to colleagues navigating customer security requests
- Coordinate with control owners and GRC team members to ensure policy documentation, procedures, and framework evidence remain current between audit cycles
Basic Qualifications (Required Skills / Experience)
- Bachelor's degree or equivalent experience in a technical, business, or compliance-adjacent field
- 4+ years in a proposal management, GRC, security compliance, or combined assurance function with hands-on operational ownership of both process and content
- Direct, hands-on experience completing SIG, CAIQ, HECVAT or comparable vendor security questionnaires at volume in a B2B SaaS or enterprise technology environment
- Advanced working experience with an enterprise RFP or questionnaire management platform
- Strong system thinking with the ability to establish and run security intake and tracking cross-functionally without formal authority
- Experience with AI-assisted workflows or platform integrations that accelerate response cycles and reduce manual effort
- Strong written and verbal communication skills along with the ability to translate technical security concepts into clear, accurate, customer language
- Strong organizational discipline is required to manage a high volume of concurrent requests, review cycles, and deadlines with precision
- Comfortable producing metrics and status reporting for leadership on inquiry performance and program health
Preferred Qualifications
- Experience in a high-growth B2B SaaS or technology company where security questionnaires are high-volume, time-sensitive, and directly tied to revenue and renewal outcomes
- Experience building or scaling a centralized security Q&A knowledge base across cross-functional subject matter experts
- Background supporting government or public-sector customers with procurement, renewal, or compliance documentation requirements
- Security, compliance, or industry certification relevant to the role (e.g., Responsive platform certification, Fortinet NES, cloud networking, or similar)
- Responsive or equivalent RFP platform certification or advanced administration experience
- Familiarity with security and compliance frameworks (ISO 27001, SOC2, NIST, etc.) to interpret control questions and coordinate accurate responses
- Familiarity to aviation, aerospace, or defense-adjacent compliance frameworks including EASA, CASA, or CMMC.
Why Join Us
At Jeppesen ForeFlight, we know you want a rewarding career. To do that, you need challenging projects, a good work environment, and awesome coworkers. We believe in our employees, and we empower them to make a direct impact on our products and services. We strive to provide our employees with a world-class benefits experience, focused on supporting their physical, financial, and emotional wellbeing. Our benefits package includes but is not limited to the following:
- Medical, dental, vision insurance with Employer paid health premiums
- Open PTO Policy
- 401(k) with up to 10% company matching and immediate vesting
- 12 Weeks Paid Paternal Leave
- Flight Training Rewards
Pay is based upon candidate experience and qualifications, as well market and business considerations: Summary Pay Range:
Jeppesen ForeFlight - EOE including Disability/Vets | Pay Transparency | E-Verify Participant | Equal Opportunity Employer