Back to jobs

Director, Data Security & Compliance (Remote)

Fully Remote - can be based anywhere in the U.S.

DataKind is looking for a Director, Data Security & Compliance!

DataKind is seeking a Director, Data Security and Compliance! This is a unique opportunity to expand a critical function that directly protects vulnerable populations and enables our mission-driven educational products to scale responsibly. The data security and compliance frameworks you implement will be foundational to our organization's ability to deliver life-changing educational tools while maintaining the highest standards of data protection. 

About the Opportunity

Reporting to the Vice President, Technology, this role will develop and implement a comprehensive data security strategy for DataKind, focusing on our enterprise education and communities platforms and products. In this critical role, you'll establish and oversee DataKind’s implementation of IS27001 to protect sensitive student data while ensuring compliance with regulations including FERPA, GDPR, SOC2, and other relevant standards. As our organization grows, you'll build our Data Security and Compliance from the ground up, creating and laying the groundwork for future expansion as our products scale.

For a data security professional seeking meaningful impact, this role offers the chance to apply specialized expertise in a mission-focused environment where your work directly safeguards student data and enables educational access. You will help lead data security strategy while working with a passionate team committed to making a difference through technology.

Location

Remote position available anywhere in the U.S. with working hours primarily between 8am-6pm Eastern Time.

Salary Range

The salary range is $150,000 - $170,000.

Actual salary within this range will be based on the candidate’s experience and an internal salary equity scan of active employee(s) with similar roles and experience. 

Core Responsibilities:

Data Security Implementation

  • Finalize and execute a comprehensive data security strategy aligned with organizational goals, grant deliverables, and product roadmaps
  • Design, implement and maintain data security infrastructure, policies, controls, and procedures across all product environments
  • Create and manage security protocols including data access control, encryption, and data loss prevention
  • Conduct regular data security assessments, vulnerability testing, and risk evaluations
  • Implement data breach response procedures and lead incident investigations when necessary

Compliance Management

  • Set up organization’s implementation of ISO27001 in preparation for a SOC2 audit 
  • Ensure organizational adherence to education data privacy regulations including FERPA and GDPR
  • Establish data governance policies that protect student information while enabling product functionality
  • Monitor regulatory changes and update data security practices accordingly
  • Maintain documentation needed for compliance verification and audits
  • Build external partnerships with data security vendors and compliance consultants to extend capabilities

Cross-Functional Leadership

  • Partner with engineering and product teams to integrate data security considerations into the development lifecycle
  • Work closely with the Senior Director, Engineering to align data privacy requirements with technical initiatives
  • Collaborate with Education Partnerships and Customer Success team members to address data security concerns from educational institutions and users
  • Advise executive leadership on data risk management and resource allocation
  • Educate staff across the organization on data protection best practices and compliance requirements
  • Create a scalable data security and compliance function that can grow with organizational needs

Education-Specific Data Protection

  • Develop specialized protocols for protecting student data in educational contexts
  • Enable secure data sharing in compliance with educational privacy requirements
  • Implement age-appropriate data security measures for student-facing applications
  • Build security systems that accommodate the unique data handling needs of educational environments

Grant Management & Milestone Achievement

  • Align data security planning and resource allocation with grant commitments and milestone requirements
  • Make strategic decisions to prioritize security initiatives that fulfill grant obligations while advancing protection goals
  • Establish KPIs and reporting frameworks for data security and compliance functions
  • Establish tracking systems to monitor compliance progress against grant milestones and deliverables
  • Work with leadership to prepare data security components of grant reports and future funding proposals
  • Balance innovation with the disciplined execution required to meet grant-specified security outcomes

Qualifications 

Required

  • Alignment and enthusiasm for DataKind’s mission and values
  • 8+ years of experience in data security and privacy, with at least 3 years focused on compliance and regulatory requirements
  • Demonstrated experience with education-specific privacy regulations, particularly FERPA
  • Experience directly implementing ISO27001 or a similar data security frameworks in cloud-based software environments
  • Experience with SOC2 audit processes
  • Understanding of security requirements for products handling sensitive student information
  • Networking engineering skills to set up, maintain and document technical security infrastructure 
  • Knowledge of secure data handling practices and ability to guide engineering teams
  • Strong project management skills to handle multiple data security initiatives simultaneously
  • Bachelor's degree in Computer Science, Information Security, Data Management, or related field

Preferred

  • Demonstrated experience guiding staff through the implementation of new security requirements, including developing training materials, providing hands-on support, and ensuring consistent adoption of updated policies and procedures.
  • Background in educational technology or working with educational institutions
  • Knowledge of COPPA, PPRA, TX-RAMP, state-specific student privacy laws, and other education regulations
  • Certifications such as CIPM, CIPP/E, CISSP, CISM, or equivalent
  • Experience building data security and compliance functions from scratch in growing organizations
  • Familiarity with data security automation tools and processes
  • Working knowledge of GDPR and other international data protection standards
  • Master's degree in Cybersecurity, Data Privacy, Information Assurance, or related field

About DataKind

At DataKind, we believe in the transformative power of data science and AI to create a more promising future. Since our founding in 2012, we’ve been at the forefront of designing scalable, data-driven tools that address some of the world’s toughest challenges—ranging from frontline health, humanitarian action, climate and environment, economic opportunity, education, and more. As both a product innovator and a movement catalyst, we set new standards in the social sector, empowering organizations to harness the full potential of data science and AI while putting communities first.

Why Work with DataKind

At DataKind, we believe that people are the most important asset to delivering on our mission. As a people-first remote organization, we offer the following for all our employees:

  • Flexibility and time off. Enjoy genuine flexibility that goes beyond adjustable hours. We build in shared time off, organization-wide recharge days, bi-weekly meeting-free days, and flexible PTO (with a minimum of 20 vacation days encouraged annually).
  • Comprehensive Wellness Support. We care for your total wellbeing with 100% employer-paid medical, vision, and dental benefits for employees (72% for dependents), a wellness reimbursement program for the activities and purchases that matter to you, and 12 weeks paid parental leave when you need it most.
  • A Culture of Growth. Every team member receives professional development funding each year, alongside mentorship and advancement opportunities. We invest in your future with a 401(k) plan with 5% employer matching. 
  • Meaningful Connection. Despite being distributed across time zones, we value being able to come together in person for conferences, strategic planning, and at our annual staff retreat.
  • Living our Values. DataKind is committed to a diverse, equitable and inclusive work environment in our day-to-day work and via special initiatives driven by our DEI Steering Committee.

 

Encouraging Applicants of All Backgrounds

We encourage people from all backgrounds to apply, especially people of color, people with disabilities, veterans, and members of the LGBTQ+ community. 

DataKind is an equal opportunity employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status, genetic information, pregnancy, or any other category/characteristics protected by law. No matter one’s background, all role must value and advocate for inclusion and equity.

Applicants must have a U.S.-based permanent address and be currently authorized to work in the United States on a full-time basis  indefinitely without employer visa sponsorship.

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

This information helps inform our recruitment efforts and will have no bearing on your application. 

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in DataKind’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.