Compliance Manager
Core
Own end-to-end security and compliance programs, managing audits, risk registers, and customer security diligence for a distributed computing platform.
Role type
Senior IC Compliance Manager (Security & Risk)
Builds
SOC 2 Type II and ISO 27001 programs, compliance automation platform evidence base, enterprise security diligence responses
Domain
Cybersecurity, Cloud Infrastructure, SaaS
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOC 2 Type II program ownership, ISO 27001 program ownership, end-to-end audit management, security diligence for enterprise customers, risk register management, compliance automation platform proficiency, cloud security controls understanding
Preferred skills
Regulated-customer contractual security obligations experience, FedRAMP or higher-bar frameworks experience, building a compliance function from scratch, cloud infrastructure or AI/ML platform familiarity
Technologies
Vanta, compliance automation platforms
Responsibilities
Own SOC 2 Type II and ISO 27001 programs including scope, evidence, and external auditor relationships; Complete and maintain control evidence in compliance automation platforms; Lead security questionnaires, audit responses, and right-to-audit requests for enterprise customers; Own and mature the enterprise risk register; Coordinate contract compliance obligations including data protection and breach notification; Assess and stand up new certifications as required
Seniority
Senior, hands-on IC