Risk and Compliance Lead
Core
Lead the end-to-end security GRC function, owning certification and audit programs (SOC 2, ISO 27001, ISO 42001) and the master security risk register for an AI-native software platform.
Role type
Senior IC Risk and Compliance Lead
Builds
Security certifications, audit artifacts, and continuous compliance monitoring for an agentic software creation platform.
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC) for AI-native developer tools.
Deliverable
Production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOC 2 and ISO 27001 certification ownership, security risk register management, ISMS/SSP documentation authoring, GRC automation platform usage, external auditor management, technical control evidence review, GDPR/privacy fundamentals.
Preferred skills
ISO 42001 scoping, FedRAMP experience, developer tools/AI/ML product background, CISA/CISSP/ISO 27001 Lead Auditor certifications, early-stage program setup.
Technologies
Anecdotes, Vanta, Drata, NIST CSF, SOC 2, ISO 27001, ISO 42001, FedRAMP.
Responsibilities
Own the end-to-end certification roadmap including scoping, gap assessments, remediation, and audit execution; manage relationships with external auditors and drive the annual audit calendar; own and maintain the company's master security risk register including risk identification, scoring, and reporting; build and maintain continuous compliance monitoring; own core audit artifacts including ISMS documentation and Statements of Applicability; run regular audits and readiness assessments and track remediation of findings.
Seniority
Senior, hands-on IC