Compliance & Trust Lead
Core
Lead end-to-end compliance and trust programs for a B2B SaaS platform, ensuring security certifications and managing enterprise procurement trust reviews.
Role type
Senior GRC practitioner (Compliance & Trust Lead)
Builds
Matured compliance frameworks (SOC 2, ISO 27001, ISO 42001) and automated risk management processes.
Domain
B2B SaaS / Developer Tools / Cybersecurity Compliance
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
GRC framework expertise, SOC 2 and ISO 27001 implementation, risk management, third-party risk assessment, compliance automation, policy drafting, stakeholder management
Preferred skills
Experience with Vanta or Drata, knowledge of GDPR and CCPA, ability to design scalable processes
Technologies
Vanta, Drata, Google Cloud, k8s, Postgres, Node
Responsibilities
Maintain and mature SOC 2 Type II, ISO 27001, and other certifications; serve as primary contact for security questionnaires and enterprise procurement; run risk management and third-party risk programs; partner with engineering to embed compliance controls; scale GRC function with automation.
Seniority
Senior, high-autonomy IC