← Все вакансии/Senior/jobgether
SeniorRemoteUS

Security Compliance Manager

J
jobgether
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Compliance Manager based in the United States.

This is a senior, hands-on leadership role responsible for owning and strengthening the organization’s security compliance and GRC function end-to-end. You’ll shape the compliance strategy across major security, privacy, regulatory, and industry frameworks while keeping the business continuously audit- and customer-ready. The role combines strategic program ownership with close collaboration across engineering, IT, product, security, and legal teams. You’ll serve as a trusted point of contact for auditors, regulators, customers, and senior leadership, translating complex risks into clear business implications. You’ll also drive a major FedRAMP initiative, improve control efficiency, and build scalable processes that support a rapidly growing technology environment. As the function develops, you’ll lead and mentor team members while expanding the organization’s compliance capabilities. This remote-first opportunity is ideal for an experienced GRC professional who thrives on ownership, technical fluency, and meaningful business impact.

Responsibilities
  • Own the strategy, planning, design, and ongoing operation of the security compliance and GRC program across SOC 2 Type II, PCI DSS Level 1 Service Provider, ISO 27001, GDPR, CCPA, and DORA.
  • Lead the organization’s FedRAMP authorization efforts, coordinating NIST SP 800-53 control implementation, third-party assessment activities, and continuous monitoring across engineering and IT.
  • Serve as the primary point of contact for auditors, regulators, industry stakeholders, and other external reviewers, ensuring assessments and compliance engagements are well planned and successfully executed.
  • Partner closely with engineering, IT, product, security, and legal teams to implement effective controls and resolve compliance and risk issues.
  • Present compliance objectives, program scope, findings, risks, and outcomes to senior leadership and board-level stakeholders in a clear, concise, and business-focused manner.
  • Own the control framework by rationalizing overlapping requirements across standards and maintaining an efficient, coherent, and evidence-focused control environment.
  • Manage the security policy and standards library, ensuring documentation remains accurate, relevant, and aligned with regulatory and business requirements.
  • Own the organizational risk picture, including the risk register, risk quantification, reporting cadence, remediation tracking, and validation of risk treatment decisions.
  • Lead the customer assurance and trust program, including security questionnaires, attestations, and trust documentation, helping ensure security reviews support rather than delay commercial opportunities.
  • Coordinate evidence collection, security scans, artifacts, and documentation while identifying opportunities to automate and streamline compliance processes.
  • Lead continuous improvement initiatives based on findings from regulators, internal and external reviews, quality assessments, and maturity evaluations.
  • Develop sufficient technical and product fluency to understand platform architecture, evaluate control effectiveness, and collaborate with engineering and product teams as a trusted peer.
  • Identify creative and scalable approaches to compliance that improve consistency, efficiency, and automation.
  • Produce executive-ready documentation, presentations, meeting materials, and reporting for internal and external stakeholders.
  • Lead, mentor, and develop the compliance team, including a Security Compliance Analyst, while establishing priorities and scaling the function as regulatory and business requirements evolve.
Requirements
  • 7+ years of experience in security compliance, GRC, audit, or a closely related field, including end-to-end ownership of audit or certification programs.
  • Demonstrated experience managing programs such as SOC 2, PCI DSS, and/or ISO 27001 from planning through assessment and ongoing compliance.
  • Deep knowledge of security and privacy frameworks, including PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, and DORA.
  • Familiarity with broader control frameworks such as NIST Cybersecurity Framework and CIS Controls.
  • Strong technical and product aptitude, with the ability to understand complex technology environments and confidently collaborate with engineering and product teams.
  • Ability to connect technical controls, security risks, and compliance requirements to real-world business outcomes.
  • Exceptional written and verbal communication skills, including the ability to create executive-ready documentation and communicate credibly with auditors, regulators, leadership, and customers.
  • Experience working in a fast-paced, high-growth environment; fintech, payments, or similarly regulated technology environments are strongly preferred.
  • Strong program management, organizational, analytical, and problem-solving capabilities with a focus on continuous improvement.
  • Ability to operate effectively as a strategic leader, cross-functional partner, and hands-on individual contributor depending on the situation.
  • Demonstrated experience leading, mentoring, or managing team members, or clear readiness to take ownership of people leadership responsibilities.
  • Willingness and ability to travel when required.
  • Bonus: Direct experience operating a PCI DSS Level 1 Service Provider compliance program.
  • Bonus: Hands-on experience with DORA and operational resilience requirements.
  • Bonus: Familiarity with GRC and security tooling, including compliance automation platforms such as Vanta, HRIS platforms such as Rippling, and macOS environments.
Conditions
  • Competitive Compensation: Generous compensation package combining cash and equity.
  • Equity Flexibility: Early exercise available for all optio
Стек и навыки

С чем работаем